Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
X-XSS-Protection
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-XSS-PROTECTION
Keep-Alive
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Nginx-Cache-Status
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Ws-Request-Id
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
Content-Location
X-Origin-Cache
X-OneAgent-JS-Injection
X-Response-Time
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-DataDome
X-Application-Context
NEL
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Mod-Pagespeed
X-Cache-Lookup
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Varnish-TTL
X-Country-Code
X-DynaTrace
Accept-Ch
Allow
X-Instart-Request-ID
X-Goog-Hash
X-Vname
X-PC
X-TtlSet
X-TTL
X-FTR-Request-ID
Verso
X-ESI
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-GitHub-Request-Id
Edge-Cache-Tag
X-Kinja-Revision
X-Kinja-Build
X-Use-Magma
X-Kinja
X-Kinja-Server
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
RTSS
X-Px
AR-PoweredBy
AR-Request-ID
Ar-Sid
AR-ATIME
AR-CACHE
X-D2id
X-Debug
X-Abt-Application-Version
Charset
X-NF-Request-ID
SPRequestGuid
X-Server-Name
X-Amz-Server-Side-Encryption
X-Vcache
X-Powered-CMS
X-Accel-Expires
X-MSEdge-Ref
X-Cached
X-Amz-Rid
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
X-Vcap-Request-Id
Display
X-Navigation-Version
X-Sol
Pagespeed
X-Middleton-Display
X-Middleton-Response
Response
X-SRCache-Fetch-Status
X-Trace
X-SRCache-Store-Status
X-SharePointHealthScore
TCN
X-Pinterest-Rid
Pinterest-Version
X-Cdn
X-VARITI-CCR
Public-Key-Pins
Realpath
Cache-Tag
X-Fastcgi-Cache
Access-Control-Request-Method
X-Client-IP
S
X-Upstream
X-Fastly-Request-ID
X-DynaTrace-JS-Agent
X-Ser
MS-Author-Via
SPIisLatency
X-Shard
SPRequestDuration
X-Id
X-Hp-Webp
DynaTrace
X-Ezoic-Cdn
X-Forwarded-For
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Content-Type
Nginx-Cache
X-Amz-Meta-S3cmd-Attrs
X-Amzn-Trace-Id
X-T
X-Recruiting
Front-End-Https
X-Grace
Fastcgi-Cache
X-Hits
X-Varnish-Age
X-DIS-Request-ID
ServerID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
NR-ENABLED
X-Element-Page-Cache
X-Node-Name
X-Content-Digest
X-Frontend
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Goog-Storage-Class
Powered
Server-Name
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-Edge-O15-RID
Alternate-Protocol
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-Logged-In
X-FTR-Backend-Server
X-FTR-Backend
TP-Cache
TP-L2-Cache
X-Correlation-Id
Server-Node
X-Cache-TTL
X-Webkit-Csp
X-Webapp-Samesite-None-Activated-N
X-Shield-Request-Id
X-XRDS-Location
X-Request-Received
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
X-Request-Handler-Origin-Region
X-Microsite
Nel
X-Server-ID
Upgrade-Insecure-Requests
X-Jurisdiction
X-Content-Security-Policy-Report-Only
X-Page-Id
X-Content-Options
X-User-Agent
X-Akamai-Edgescape
Refresh
X-Rid
X-Origin-Server
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Varnish-Grace
Backend-Timing
X-Revision
X-ATS-Timestamp
X-F-Cache
X-Cache-Hit
X-Type
X-XRDS-LOCATION
Fastly-Restarts
X-Pad
X-Analytics
X-Geo-Country
X-URL
X-Content-Powered-By
X-AppVersion
X-Activity-Id
X-N
X-Az
X-LB-Cache
X-Zen-Fury
X-B3-Sampled
X-B
X-RateLimit-Remaining
X-Kinsta-Cache
X-Ruxit-Js-Agent
X-FTR-Cache-Host
X-Cache-Age
X-TT
PB-RID
PB-PID
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-0
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel
X-Jobs
X-Request-Guid
Arc-Version
X-Mobile-Rewrite
X-Instance
Access-Control-Allow-Method
X-Debug-Info
Actual-Object-TTL
X-Framework
X-B-Cache
X-Signature
X-FB-Debug
Paypal-Debug-Id
DC
Cache-Status
X-PHP-Backend
X-CST
X-Load-Cache
X-Cache-Action
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Surrogate-Key
Fastcgi-Useragent
X-Varnish-Backend
X-Ttl
X-Git-Hash
X-FastCGI-Cache
FilterID
Host-Header
X-Time
X-Cached-By
X-Tt-Trace-Tag
X-IPLB-Instance
MS-CV
X-Contextid
X-SS-Set-Cookie
X-Amz-Replication-Status
X-Cluster
X-Tt-Trace-Host
Tracecode
X-Cache-Key
Frame-Options
X-Srv
X-ATG-Version
X-Response-Served-From
X-Accel-Buffering
WPE-Backend
NGB
X-B3-Traceid
Source
Eomportal-Instance
Payment
X-Varnish-Server
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-FW-Static
X-Cache-NE
Host
X-GeoIP
X-FW-Server
X-FW-Hash
Filters
Cache-Tv-Group
X-Adobe-Content
X-Adobe-Loc
X-WA-Info
X-FW-Serve
X-Cache-Enabled
Xserver
X-FW-Type
X-RequestSource
X-Region
X-IPS-LoggedIn
X-Oneagent-Js-Injection
X-TX-ID
X-Cache-2
X-Cacheable-TTL
X-Host-Name
X-Is-Bot
X-Rendered-As
Cleartype
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Mobile
X-Seen-By
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Cache-Rule
X-Cache-Operation
Cache
X-Origin-Response-Time
X-Via-JSL
X-Hostname
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
X-VCache
Healthy
X-Cache-Control
X-Cache-TTL-Remaining
Datacenter
X-PressLabs-Stats
X-HTML-Minification-Powered-By
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
Accept-CH
Retry-After
X-RemovedCookies
X-RTag
X-ProcessESI
Ms-Operation-Id
Server-Info
X-RateLimit-Limit
X-Rule
X-Dc
X-Presslabs-Stats
X-Cache-Server
From-Origin
X-CACHE-KEY
Version
X-Wix-Request-Id
X-Status
X-UA
Liferay-Portal
X-Esi
X-L-Path
X-Environment-Context
X-Source
X-NWS-LOG-UUID
X-Upgrade-Enabled
X-Endurance-Cache-Level
X-FireWall-Port
Accept-CH-Lifetime
X-ES-SERVER
X-Cache-Var
Meta-Geo
X-RN-RSRV
X-Cache-Var-Map
X-Path-Route
OT-Force-Account-Verify
X-Timing-Wait
X-Proxy-Build
Selected-Fe
X-UUID
X-Alternate-Cache-Key
X-Backend-Name
X-Tb
X-Handled-By
X-ShopId
X-Content-Age
X-EIG-Tracking-Id
X-Proto
X-Storage
X-Shopify-Generated-Cart-Token
X-Shopify-Stage
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Hyper-Cache
X-ShardId
X-Generated-By
X-Debug-Cache
L5d-Success-Class
NGX
Ec-Rule-Version
X-Section
Decoy-Debug-Key
Decoy-Debug-Status
Node
Now
X-Cache-Config
X-Cache-Host
X-BYPASS-REASON
X-Akamai-Request-ID2
S-Rt
X-FC-Vary-Parameters
X-ProxyCache-Key
X-Vgn-Hpd-Reason
X-Viewer-Country
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
DB-Nickname
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Web-Node
Akamai-GRN
Azure-SlotName
Azure-Version
Cache-Tags
Property-Id
Azure-SiteName
Azure-RegionName
TWC-Device-Class
TWC-Connection-Speed
Azure-InstanceId
Webcakes-Region
X-Akamai-Request-ID
X-Proxy
X-ProxyCache-Status
X-Redis-Cache
X-SaId
X-PCL
X-Origin
X-Hosted-By
X-JoinUs
X-OCL
X-ServerID
X-Request-Time
X-LJ-Flow-ID
X-FW-Dynamic
X-AWS-Id
X-Origin-Hint
X-Time-Microsecs
X-Format
X-Access
X-VWS-Id
X-Hl-Ver
Decoy-Debug-TTL
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Say-Cacheable
X-Pubstack
X-Say-TTL
Origin-Cache-Control
Origin-Edge-Control
X-BCube-Filmed-By
X-Human
X-Generated
X-CCM
X-IP
X-NYM-Debug-Backend
X-MP-GENERATED-AT
X-Soup
X-SayCDN-TTL
X-Qloud-Router
X-Cluster-Node
X-Xfnlog-Site
X-RCS-CacheZone
X-Proxy-Cache-Status
Mn-Server-Ip
X-Varnish-Hits
X-Amzn-Remapped-Content-Length
X-Loop
X-FB-TRIP-ID
Webserver
Cache-Name
X-TNCMS
X-Detected-As
X-App-Server
Cross-Origin-Window-Policy
Viewport
X-Locale
X-Www-Served-By
X-APP-VERSION
X-CS
Uber-Trace-Id
Srv
X-Site-Version
X-R9-Blue-Green-Version
Time
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Drupal-Cache-Tags
X-NCache
X-Akamai-Transformed
Accept-Charset
X-Unique-Id
X-Cache-Remote
X-From
X-UA-Device-Type
GEO-INFO
X-Cluster-Name
X-Edge-Location
X-TT-TIMESTAMP
X-Origin-TTL
X-Drupal-Cache-Contexts
X-Origin-CC
Cache-Key
Mime-Version
X-EC-Lua
Accept-Language
X-Backend-TTL
Country
X-Mode
Odigeo-Trace-Id
X-CDN-Forward
X-Newrelic-Synthetics
X-Microcachable
X-CLOUD-TRACE-CONTEXT
Rt-Fastcgi-Cache
X-B3-Spanid
Ohc-Cache-HIT
Ohc-File-Size
X-No-Session
X-Forwarded-Host
X-Info
X-Geo
Proxy-Connection
X-Labrador-Cache-Channel
X-Magnolia-Registration
X-UPSTREAM-Address
X-PHP-Host
X-Whom
Geo-Info
X-Proxied
X-App-Version
X-Zipkin-Id
X-Routing-Service
Content-Disposition
X-Varnish-Cache-Hits
X-UnsetCookies
X-Real-IP
X-Cache-Time
Cf-Ipcountry
ServedBy
Fastly-SSL
X-Date
X-ScT
AsisCache
X-SRCache-Key
BehaviorPad-Version
X-Session-Fingerprint
X-Request-UUID
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
X-PERF
X-Region-Sid
X-S
X-CF-Lambda-Version
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dam
X-A
X-A-Ccd
X-Aed
X-G
X-D
X-DPWN-IS-SECURE
X-B-Cookie
X-ARC
X-External-Request-Id
X-Application
VivaBuild
Viewtype
X-CF-Lambda-Fn
X-Connection-Hash
MD5-Digest
Machine
GEO-REGION-INFO
Content-Style-Type
Fastcgi-X-Cache-Version
X-Destination
Meta-Geo-Continent
X-GeoIP-Country-Code
X-Geo-Header
T-Server
Rendered-Blocks
Mobile-Detection-Method
Powered-By
Content-Script-Type
X-ApacheServer
X-VG-WebCache
X-Twitter-Response-Tags
X-Trv-Group
X-VG-WebServer
X-Vtex-Processado-Em
Xc-Version
X-Vtex-Remote-Cache
X-Transaction
X-Vdms-Version
Access-Control-Request-Headers
X-Device-Type
User-Cache-Control
X-Via-Fastly
X-CUA
X-Tumblr-Pixel-3
X-VG-TLSProxy
X-VC-Cache
X-Auto-Login
X-Cache-Debug
X-Varnish-Authentication
X-Sigma
IsBot
Server-Cache-Control
Server-Surrogate-Control
X-SIPLIST1
X-WebServer
X-Contensis-Viewer-Groups
Gh-Request-Id
Environment
X-Sigma-Backend
W
X-Rocket-Build-Number
X-TrackingId
X-Cache-ASPX
X-Uri
X-C
X-Clientip
Fastly-Backend-Name
X-GeoIP-City
True-Client-Country-4JS
X-GoCache-CacheStatus
X-Debug-Cache-Store
X-Generation-Time
X-Debug-Cache-Fetch
Fastly-Soc-X-Request-Id
X-Generated-In
X-Clara-WADP
V-Age
X-Req
X-Debug-Cache-Expiry
X-CGP
X-Cms-Context
Request-EU
X-IN-APIGATEWAYSSL
Request-Country
X-Core-Mission
X-Nginx-Cache-Key
X-Webstats-RespID
X-IN-APIGATEWAY
X-Hnp-Log
X-Hash
Server-ID
X-Dispatcher-Server
Section-Io-Cache
X-Hit
We-Hiring
X-Cache-URL
Wxu-Next-Region
X-Cache-Bucket
X-Cache-Info
X-Irp-Debug
Server-Int
X-Distributor
Wxu-Next-Commit
Wxu-Next-Hostname
X-Epic-Correlation-Id
X-Bip
X-Eu-Site
X-BBXSRF
X-Backend-State
X-Developers
X-AK-Request-ID
X-Cdn-Srv
Locid
FNAC-ModuleRouting
X-Cache-Backend
Web-Mar-Node
X-Gen-Mode
RNT-Machine
X-Gamma-Serve
X-Fastly-Cache
X-Debug-Log
X-FW-Version
X-Distil-CS
RNT-Time
X-Block-Status
X-Li-Pop
X-Proxy-Upstream
X-OVcl-Cache
ServerName
X-RateLimit-Limit-Second
X-User
X-RateLimit-Remaining-Second
X-Wikidot-Static-Cache
X-Origin-Expires
Cdncip
Cdnsip
CDCHOST
X-NX-Host
X-Origin-Date
Apple-News-Services-Handled
Apple-News-Services-Host
X-Debug-Cookies
X-Varnish-Beresp-Grace
X-Thanos
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-TH-Server
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Render-Time
X-Request-URI
X-TT-LOGID
X-VServer
X-OVcl
Locale
X-LI-Proto
Country-Code
X-Location
X-Logging-Id
Kp-EeAlive
X-WADP-Cache
X-App-Name
X-Key
X-Wikidot-Backend
Memcached
X-Li-Fabric
Mail-Subject
X-We-Are-Hiring
IBM-Web2-Location
X-LI-UUID
Countrycode
HA-Ipaddr
Ha-Gx-Prefs
X-NGENIX-Cache
X-B3-Parentspanid
X-S-Maxage
X-Instart-Isnd
X-Trafficlayer-App-Version
Fastly-SWR
X-Thinkindot-L3
X-Trace-Id
X-ServiceProvider
X-Sucuri-Cache
X-JWT-State
X-SVT-ORM-RULES
X-Internal-Host
X-Rebelmouse-Surrogate-Control
X-SVT-ORM-VERSION
X-Swa-Ws
X-NU-AKA-ACS-Version
X-Owner
X-Ms-Request-Id
X-Platform-Server
X-Has-Esi
X-Rebelmouse-Cache-Control
X-Variation
X-Is-Gdpr
X-Reboot
Fastly-SIE
X-Matched-Rule
X-Old-Content-Length
X-NodeID
X-Up
X-Ms-Version
X-Azure-Ref
X-Cache-Tags
Thinkindot-CacheControl-Type
Is-Eu
Cache-Host
X-Agile
Thinkindot-CacheControl
Server-Host
Heartbleed
PFcat
Platform
AKAMAI
X-Agile-Age
Thinkindot-Control
X-Core-Value
X-Agile-Id
Adler-Geo
X-Nginx-Cache
HitType
X-TA-CDN-Provider
X-Generated-On
X-Refresh
X-Level-Front-Cache
X-Daa-Tunnel
X-Micro-Cache
X-Response-By
X-SERVER
X-Server-W
Cache-Hits
X-Service
X-NC
RequestId
X-Servername
X-Fetched-On
X-Server-IP
X-Lb-Id
X-B3-SpanId
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-TOKEN
X-Cdn-Forward
X-Nc
X-CF-Powered-By
X-Tec-Api-Root
Media-Length
X-Cdn-Request-ID
X-Tec-Api-Origin
X-Tec-Api-Version
ProcessTime
Memory
X-Ua
X-Pjax-Url
X-BACKEND-TTL
Origin
X-Air-Hostname
X-Wa
User-Agent
X-Cache-Expired-At
X-Var-Ttl
Filterid
X-CSRF-Token
Pragrma
X-Pf-Uncompressing
X-TIME
X-Correlation-ID
X-Unique-ID
Geoip-Latitude
TTL
X-Reqid
Group
X-Sucuri-Id
Esi-Enabled
X-AIR-PT
GeoIp-Country-Code
X-Policy
Powered-By-ChinaCache
X-Planisys-CDN-Rules
S-Cnection
X-Planisys-CDN-Cache
X-Vcl-Version
X-Planisys-CDN-TTL
X-COUNTRY
SRV
X-NGINX-Cache
PICS-Label
X-Servedbyhost
SN
X-Rocket-Nginx-Bypass
X-Request-Start
X-Oracle-Dms-Rid
HostName
X-Sucuri-ID
X-Varnish-Cacheable
X-Azure-Ref-OriginShield
X-Litespeed-Cache
Rt-Proxy-Cache
X-Webkit-CSP
X-HS-Status
M-TraceId
X-Via-Ucdn
XServer
X-Method
Geoip-City
X-Via-CDN
Magicmarker
X-FORWARDED-FOR
Load-Balancing
X-NWS-UUID-VERIFY
Dnion-Transfer-Encoding
X-Developer
X-Fastly-Country-Code
Tcn
Who
DSUID
Ohc-Response-Time
X-Device-Os
X-Sn-Servicetimems
X-Cache-Ttl
X-Node-Id
X-Cdn-Origin
Resin-Trace
X-Cache-Grace
X-LAGOON
Release
X-VHOST
X-Ftr-Cache-Host
X-Be
On-Server
Cdn
X-Ocache
X-Dynatrace
X-ServedByHost
NtCoent-Length
CF-Cached-On
X-MServer
X-Svr
X-VCT
X-APP
X-Hp-Ccpa-Warning
X-MSEdge-Flight
X-Bc
X-MSEdge-Features
GeoIP-Country-Code
Vix-Hermes-Req-Id
X-VCL-Version
Pics-Label
X-Zone
X-Request-Host
A
X-Newrelic-App-Data
X-DC
X-VarnishDD-TTL
GeoIP-Latitude
Ttl
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Cteonnt-Length
X-Oss-Storage-Class
X-Oss-Server-Time
MIME-Version
GeoIP-City
X-Beluga-Node
X-Beluga-Cache-Status
X-Fastly-Backend-Reqs
X-Beluga-Record
X-Beluga-Status
X-Beluga-Response-Time
X-Varnish-URL
Cloudfront-Viewer-Country
X-Beluga-Trace
X-WR-MODIFICATION
X-Configured-By
X-LiteSpeed-Cache-Control
X-Cache-Status-Check
X-PF-Uncompressing
SD-X-WS
X-SD-PageType
Hostname
X-Varnish-Ttl
X-Varnish-Url
X-Ratelimit-Remaining
X-Upstream-Ht
X-Upstream-Ct
X-Cache-Id
X-Compress-Hint
X-SN
X-Ftr-Request-Id
Host-ID
X-Tid
X-PJAX-URL
X-SRV
X-HostName
X-BE
L
X-Release
X-Via-NSCOPI
X-Aicache-OS
Processtime
X-Dynatrace-Js-Agent
X-Fastly-Cache-Hits
X-Slack-Backend
X-ID
X-Swift-Error
LB
Cache-Provider
X-Scheme
CACHE
X-Frame-Option
Amp-Access-Control-Allow-Source-Origin
X-Ratelimit-Limit
Cache-Cookie-Set-Idcheck
X-DSS
Requestid
Cache-Cookie-Set-From
X-RSL
X-StackifyID
X-DW
X-DB
X-Action
X-DI
X-RPM
X-RPS
UCS
Cache-Cookie-Set-Lfrom
X-LB-ID
X-Ftr-Backend-Server
X-Ftr-Backend
Pagetype
X-Ftr-Balancer
X-Ftr-Dc
Dynatrace
X-Ftr-Realm
Lfy
X-ServerName
X-Branch-Name
Servername
CF-IPCountry
CDN
X-Snapshot-Date
X-CACHE-AGE
X-Cc-Req-Id
X-Apw-Hits
D-Cc-Upstream
X-Cc-Via
X-Node-ID
X-PAYTM-SRV-ID
X-Processor
X-Server-Time
X-Skip-Cache
X-FPC
X-Fastly-Cache-Status
Arc-Country
X-Cache-FS-Status
X-Dispatch
X-VC
Warning
Proxy-Firewall
V-Cache
X-Edge-IP
X-ZONE
X-Apw-Access-Token
X-Varnish-Beresp-TTL
X-Apw-Access-Action
X-Apw-Access-Object
WebServer
X-SB
NnCoection
WZWS-RAY
X-Hello
X-Flog
X-ABtesting
X-ElasticPress-Search
X-App
Backend-Name
X-Request-URL
X-BC
X-Worker
X-Check-Cacheable
X-Powered-Y
Lb
Correlation-Id
X-Litespeed-Cache-Control
X-Request-Url
WP-Super-Cache
Pramga