Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
P3p
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Server
X-Via
X-Age
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Ws-Request-Id
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
X-DataDome
X-ORACLE-DMS-RID
X-Cache-Lookup
X-Mod-Pagespeed
NEL
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Aspnet-Version
X-DynaTrace
Allow
X-Country-Code
X-Instart-Request-ID
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
Accept-Ch
X-FTR-Request-ID
X-Varnish-TTL
X-TTL
X-ESI
Verso
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
Accept-Ch-Lifetime
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
Edge-Cache-Tag
AR-CACHE
AR-PoweredBy
Ar-Sid
RTSS
AR-Request-ID
AR-ATIME
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
X-Vcache
SPRequestGuid
Charset
X-NF-Request-ID
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-MSEdge-Ref
X-Cached
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Middleton-Response
Display
X-Sol
X-Amz-Rid
Pagespeed
Response
X-Fastcgi-Cache
X-Middleton-Display
X-Powered-CMS
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
TCN
X-SharePointHealthScore
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Cdn
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
MS-Author-Via
S
X-DynaTrace-JS-Agent
X-Upstream
X-Shard
Nel
X-Id
Nginx-Cache
SPIisLatency
SPRequestDuration
X-Ezoic-Cdn
X-Hp-Webp
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Content-Type
X-Forwarded-For
X-T
X-Amzn-Trace-Id
X-Grace
X-Amz-Meta-S3cmd-Attrs
DynaTrace
X-Recruiting
Front-End-Https
X-Hits
Fastcgi-Cache
X-Varnish-Age
X-Edge-O15-RID
ServerID
X-DIS-Request-ID
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Node-Name
X-Element-Page-Cache
X-Server-ID
NR-ENABLED
X-Content-Digest
X-Cache-TTL
X-FTR-Expires
X-HS-Cache-Config
X-Country-Code-Real
X-HS-Hub-Id
X-HS-Content-Id
X-FTR-Cache-Status
X-HS-Combine-CSS
Powered
X-Frontend
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
Server-Name
Alternate-Protocol
TP-Cache
TP-L2-Cache
X-Logged-In
Server-Node
X-Jurisdiction
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
Backend-Timing
X-ATS-Timestamp
X-Webkit-Csp
Upgrade-Insecure-Requests
X-Page-Id
X-Content-Options
Refresh
X-Amz-Apigw-Id
X-Content-Security-Policy-Report-Only
X-Cache-Hit
X-Amzn-RequestId
AMP-Access-Control-Allow-Source-Origin
X-F-Cache
X-Origin-Server
X-Revision
X-Akamai-Edgescape
X-Rid
X-Varnish-Grace
X-User-Agent
X-Type
X-Shield-Request-Id
Fastly-Restarts
X-XRDS-Location
X-Zen-Fury
X-Content-Powered-By
X-Webapp-Samesite-None-Activated-N
X-LB-Cache
X-Geo-Country
X-B
X-Activity-Id
X-CST
X-AppVersion
X-Az
X-N
X-B3-Sampled
X-FTR-Cache-Host
X-URL
X-Pad
PB-PID
PB-RID
X-Kinsta-Cache
X-Mobile-Rewrite
Arc-Version
X-Analytics
Cache-Status
X-TT
X-Time
X-WebKit-CSP-Report-Only
X-Debug-Info
X-AOL-HN
X-Cache-Age
X-Instance
Actual-Object-TTL
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Signature
X-Framework
X-App-Environment
X-B-Cache
DC
Paypal-Debug-Id
X-Ruxit-Js-Agent
X-Request-Guid
X-Jobs
Access-Control-Allow-Method
X-RateLimit-Remaining
X-FB-Debug
X-PHP-Backend
X-Cache-Action
X-Load-Cache
X-Git-Hash
Surrogate-Key
X-Cached-By
X-Varnish-Backend
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
X-Tt-Trace-Tag
Host-Header
X-Ttl
X-Amz-Replication-Status
FilterID
X-Contextid
X-Tt-Trace-Host
X-IPLB-Instance
MS-CV
X-SS-Set-Cookie
X-ATG-Version
X-Cache-Key
X-Cluster
X-WA-Info
NGB
Accept-CH
X-Response-Served-From
X-Accel-Buffering
Tracecode
X-Srv
WPE-Backend
Frame-Options
Payment
Xserver
X-Varnish-Server
X-Mobile
X-Cache-NE
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Host-Name
Eomportal-Instance
X-Region
X-Varnish-Hostname
X-FW-Server
X-Tumblr-Pixel-2
X-FW-Hash
Filters
X-Tumblr-Pixel-1
X-Cache-Enabled
X-FW-Serve
Host
X-Adobe-Loc
X-GeoIP
X-Rendered-As
X-Cache-2
Source
X-FW-Static
Cache-Tv-Group
X-Is-Bot
X-FW-Type
X-IPS-LoggedIn
X-Cache-Rule
X-Cacheable-TTL
X-Adobe-Content
X-Cache-Operation
X-Presslabs-Stats
X-TX-ID
X-EdgeConnect-Cache-Status
X-ORACLE-APMCS-TAG
X-Via-JSL
X-Hostname
X-NewRelic-App-Data
X-ORACLE-APMCS-REQUEST-ID
X-RequestSource
X-Seen-By
X-Origin-Response-Time
X-Oneagent-Js-Injection
Cleartype
Cache
X-Cache-TTL-Remaining
Retry-After
X-FastCGI-Cache
Accept-CH-Lifetime
Server-Info
X-VCache
X-RemovedCookies
X-NWS-LOG-UUID
X-UA
X-ProcessESI
X-HTML-Minification-Powered-By
Healthy
X-Cache-Control
Datacenter
X-Dc
X-B3-Traceid
Ms-Operation-Id
X-RTag
Liferay-Portal
X-Source
X-FireWall-Port
X-Upgrade-Enabled
X-Environment-Context
X-Cache-Server
X-Endurance-Cache-Level
From-Origin
X-L-Path
X-Trafficlayer-App-Name
X-Rule
X-RateLimit-Limit
X-Trafficlayer-App-Scope
X-Wix-Request-Id
X-App-Server
Version
X-Status
X-Handled-By
X-CACHE-KEY
X-PressLabs-Stats
X-APP-VERSION
X-Cache-Var
X-RN-RSRV
X-Cache-Var-Map
Meta-Geo
X-ES-SERVER
X-Path-Route
X-Backend-Name
Selected-Fe
OT-Force-Account-Verify
X-Section
X-Request-Time
X-Tb
X-Format
X-Access
X-Proxy-Build
X-Timing-Wait
Cache-Tags
Azure-SlotName
Azure-Version
Azure-RegionName
X-Akamai-Request-ID
Akamai-GRN
Azure-SiteName
Azure-InstanceId
X-Storage
X-Human
X-Origin
X-OCL
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Generated-Cart-Token
X-ProxyCache-Key
X-ProxyCache-Status
X-Proto
X-PCL
X-ShardId
X-Sorting-Hat-ShopId
X-BYPASS-REASON
X-EIG-Tracking-Id
X-Alternate-Cache-Key
X-Goog-Meta-Goog-Reserved-File-Mtime
Decoy-Debug-Key
DB-Nickname
X-Web-Node
Ec-Rule-Version
X-Redis-Cache
Decoy-Debug-Status
X-Viewer-Country
X-UUID
X-Proxy-Cache-Status
X-Soup
X-ServerID
X-Pubstack
X-Time-Microsecs
X-Vgn-Hpd-Reason
X-SaId
Now
X-FC-Vary-Parameters
X-Generated-By
X-Hl-Ver
X-Hosted-By
X-Debug-Cache
X-Content-Age
X-Cache-Config
X-Cache-Host
X-Cluster-Node
X-Hyper-Cache
X-JoinUs
X-Akamai-Request-ID2
Node
NGX
Mn-Server-Ip
Origin-Cache-Control
Origin-Edge-Control
X-MP-GENERATED-AT
X-NYM-Debug-Backend
S-Rt
X-Proxy
Decoy-Debug-TTL
GEO-INFO
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-IP
X-FW-Dynamic
X-CCM
X-AWS-Id
X-BCube-Filmed-By
X-LJ-Flow-ID
X-Detected-As
X-Locale
X-Varnish-Hits
X-VWS-Id
X-Www-Served-By
X-Site-Version
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Qloud-Router
X-Generated
Cross-Origin-Window-Policy
X-Origin-Hint
TWC-Locale-Group
X-Amzn-Remapped-Content-Length
Property-Id
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
Srv
Accept-Charset
X-Loop
TWC-GeoIP-LatLong
X-R9-Blue-Green-Version
TWC-GeoIP-Country
TWC-Device-Class
X-FB-TRIP-ID
TWC-Connection-Speed
X-TNCMS
TWC-Privacy
X-Xfnlog-Site
L5d-Success-Class
X-RCS-CacheZone
X-Akamai-Transformed
Cache-Name
X-CS
Uber-Trace-Id
Viewport
X-NCache
X-Drupal-Cache-Tags
Webserver
Time
X-Unique-Id
X-UA-Device-Type
X-Esi
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Remote
Cache-Key
Mime-Version
X-From
Accept-Language
X-Origin-TTL
X-Cluster-Name
X-Origin-CC
X-Drupal-Cache-Contexts
X-TT-TIMESTAMP
X-Edge-Location
Country
X-Forwarded-Host
Odigeo-Trace-Id
Rt-Fastcgi-Cache
X-Mode
X-Microcachable
X-Backend-TTL
X-EC-Lua
X-UnsetCookies
X-Info
X-Whom
X-CDN-Forward
X-Varnish-Cache-Hits
X-Geo
X-B3-Spanid
X-PERF
X-CLOUD-TRACE-CONTEXT
X-Magnolia-Registration
X-ApacheServer
X-TA-CDN-Provider
ServedBy
Content-Disposition
Proxy-Connection
Ohc-Cache-HIT
X-No-Session
X-Newrelic-Synthetics
Ohc-File-Size
X-UPSTREAM-Address
X-NGENIX-Cache
X-Device-Type
Cf-Ipcountry
X-PHP-Host
X-Nc
X-Via-Fastly
X-Labrador-Cache-Channel
X-G
X-Vtex-Processado-Em
X-Geo-Header
X-GeoIP-Country-Code
X-Region-Sid
X-Vtex-Remote-Cache
X-External-Request-Id
X-DPWN-IS-SECURE
Apple-News-Services-Parsed-Url
X-Date
Apple-News-Services-Host
Apple-News-Services-Handled
X-Destination
X-Uri
X-Request-UUID
X-Rewrite-Enabled
X-Sigma-Backend
X-Sigma
X-SRCache-Key
X-Transaction
X-Twitter-Response-Tags
X-Trv-Group
X-Session-Fingerprint
X-ScT
X-Vdms-Version
X-Rocket-Build-Number
X-Rojux
X-S
X-S-Cookie
Apple-News-Services-Request-Url
AsisCache
VivaBuild
W
X-B-Cookie
X-CF-Lambda-Fn
Viewtype
X-CF-Lambda-Version
X-A
X-A-Ccd
X-A-Wwc
X-Accel-Expires-Debug
X-Application
X-A-Dgt
X-A-Dam
X-A-Dcw
T-Server
Rendered-Blocks
GEO-REGION-INFO
Machine
Fastcgi-X-Cache-Version
Content-Style-Type
X-D
Content-Script-Type
X-Connection-Hash
X-VG-WebServer
Meta-Geo-Continent
Mobile-Detection-Method
MD5-Digest
X-VG-TLSProxy
X-VG-WebCache
X-Aed
X-ARC
X-Real-IP
X-Daa-Tunnel
X-Zipkin-Id
X-C
X-Cache-Time
User-Cache-Control
X-Routing-Service
X-Proxied
X-Agile
X-Bip
X-Backend-State
X-Auto-Login
X-Agile-Id
X-Agile-Age
Server-Surrogate-Control
Gh-Request-Id
Fastly-Soc-X-Request-Id
Environment
Ha-Gx-Prefs
HA-Ipaddr
Server-Cache-Control
Powered-By
Locid
X-Cache-ASPX
X-CGP
X-Tumblr-Pixel-3
X-TrackingId
X-Thanos
X-Sucuri-Cache
X-Varnish-Authentication
X-VC-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-WebServer
X-Render-Time
X-Hit
X-Contensis-Viewer-Groups
CDCHOST
Xc-Version
X-CUA
X-Developers
X-Eu-Site
X-Epic-Correlation-Id
X-Distil-CS
X-Cache-Debug
X-Logging-Id
BehaviorPad-Version
Access-Control-Request-Headers
X-GoCache-CacheStatus
HitType
X-SVT-ORM-RULES
X-Cache-Info
X-Cdn-Srv
X-Cache-Backend
X-Cache-Bucket
X-Swa-Ws
X-SVT-ORM-VERSION
X-Clara-WADP
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Block-Status
X-Clientip
X-Cms-Context
X-SIPLIST1
X-BBXSRF
X-VServer
X-User
X-Urbn-Site-Id
Web-Mar-Node
We-Hiring
X-We-Are-Hiring
X-WADP-Cache
X-AK-Request-ID
X-App-Name
X-Dispatcher-Server
X-Trace-Id
X-RateLimit-Remaining-Second
X-Azure-Ref
X-Urbn-Context-Path
X-TT-LOGID
X-TH-Server
X-Distributor
X-Ms-Version
X-NodeID
X-NX-Host
X-Ms-Request-Id
X-Micro-Cache
X-LI-UUID
X-Location
X-Varnish-Beresp-Ttl
X-Origin-Date
X-Origin-Expires
X-Rebelmouse-Cache-Control
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Rebelmouse-Surrogate-Control
X-Owner
X-OVcl
X-OVcl-Cache
X-LI-Proto
X-Li-Pop
X-Generated-In
X-Generation-Time
X-GeoIP-City
X-Gen-Mode
X-Gamma-Serve
X-Fastly-Cache
X-FW-Version
X-Hash
X-Request-URI
X-Irp-Debug
X-Key
X-Li-Fabric
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Hnp-Log
X-IN-APIGATEWAY
X-Webstats-RespID
Fastly-SSL
Mail-Subject
AKAMAI
Locale
Kp-EeAlive
V-Age
Memcached
Section-Io-Cache
Request-EU
Request-Country
X-Varnish-Beresp-Status
Server-ID
IsBot
Cdnsip
X-Varnish-Beresp-Grace
Cdncip
Cache-Host
IBM-Web2-Location
True-Client-Country-4JS
Fastly-SIE
Country-Code
Countrycode
Heartbleed
Fastly-SWR
X-Nginx-Cache
X-App-Version
Geo-Info
X-ServiceProvider
X-Service
Thinkindot-CacheControl-Type
Is-Eu
Thinkindot-Control
X-Old-Content-Length
Fastly-Backend-Name
PFcat
ServerName
X-Core-Mission
X-Variation
X-Generated-On
X-Up
X-NU-AKA-ACS-Version
X-Nginx-Cache-Key
X-Core-Value
X-Has-Esi
Thinkindot-CacheControl
Platform
X-Matched-Rule
RNT-Machine
Server-Int
X-JWT-State
X-Thinkindot-L3
RNT-Time
X-Trafficlayer-App-Version
X-Level-Front-Cache
X-Is-Gdpr
X-Platform-Server
X-Cache-Tags
X-Cache-URL
X-Fetched-On
Adler-Geo
Server-Host
X-Reboot
Wxu-Next-Hostname
X-Lb-Id
X-Req
Wxu-Next-Region
X-Internal-Host
X-Response-By
Wxu-Next-Commit
FNAC-ModuleRouting
X-Refresh
X-Servername
Cache-Hits
X-Server-W
X-B3-Parentspanid
X-SERVER
X-S-Maxage
RequestId
X-Cdn-Forward
X-Tb-Optimization-Total-Bytes-Saved
X-Parent-Response-Time
X-B3-SpanId
X-BACKEND-TTL
X-Air-Hostname
ProcessTime
X-CF-Powered-By
Filterid
X-Tec-Api-Version
X-Pjax-Url
X-CSRF-Token
X-Var-Ttl
X-Cache-Expired-At
Pragrma
Group
X-Tec-Api-Root
Memory
X-Tec-Api-Origin
X-Server-IP
X-CSRF-TOKEN
X-Varnish-Ttl
User-Agent
Powered-By-ChinaCache
TTL
X-Pf-Uncompressing
X-NC
S-Cnection
Media-Length
X-Cdn-Request-ID
Geoip-Latitude
Origin
X-Wa
X-Vcl-Version
X-Sucuri-ID
GeoIp-Country-Code
X-Unique-ID
X-Correlation-ID
X-Ua
SRV
X-Sucuri-Id
PICS-Label
X-NGINX-Cache
X-COUNTRY
Geoip-City
X-Rocket-Nginx-Bypass
X-NWS-UUID-VERIFY
Esi-Enabled
SN
X-Varnish-Cacheable
X-Via-CDN
X-Reqid
X-AIR-PT
X-Developer
Dnion-Transfer-Encoding
X-Servedbyhost
X-Policy
M-TraceId
X-Litespeed-Cache
X-HS-Status
X-Webkit-CSP
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Cdn-Origin
X-Ocache
X-Via-Ucdn
X-LAGOON
X-Sn-Servicetimems
X-Request-Start
X-Cache-Grace
X-Node-Id
X-Azure-Ref-OriginShield
X-Device-Os
HostName
X-TIME
XServer
On-Server
Rt-Proxy-Cache
X-FORWARDED-FOR
Cdn
X-Request-Host
X-Fastly-Country-Code
X-MSEdge-Features
X-ServedByHost
Resin-Trace
Tcn
X-MSEdge-Flight
Magicmarker
Who
X-Method
A
X-Cache-Ttl
X-Cache-Status-Check
Cloudfront-Viewer-Country
Hostname
X-Ftr-Cache-Host
X-VHOST
X-Beluga-Record
X-Beluga-Node
X-Beluga-Response-Time
X-Beluga-Status
X-Beluga-Cache-Status
X-APP
X-Beluga-Trace
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
CF-Cached-On
Load-Balancing
X-Ratelimit-Remaining
Pics-Label
X-Zone
X-Bc
DSUID
NtCoent-Length
X-Be
X-Svr
GeoIP-Country-Code
Host-ID
X-VarnishDD-TTL
Amp-Access-Control-Allow-Source-Origin
X-VCL-Version
Ohc-Response-Time
Release
X-Oracle-Dms-Rid
X-MServer
MIME-Version
X-VCT
X-Fastly-Backend-Reqs
X-Varnish-Url
Cteonnt-Length
Ttl
Vix-Hermes-Req-Id
X-Varnish-URL
GeoIP-Latitude
X-LiteSpeed-Cache-Control
X-Hp-Ccpa-Warning
X-DC
GeoIP-City
X-PF-Uncompressing
X-Slack-Backend
X-Newrelic-App-Data
X-DSS
X-PJAX-URL
X-Configured-By
X-DW
X-Ratelimit-Limit
X-Ftr-Request-Id
X-Action
X-DI
X-RSL
X-DB
X-RPS
X-Tid
X-Swift-Error
X-SRV
X-RPM
WebServer
X-HostName
X-PAYTM-SRV-ID
X-Upstream-Ht
X-BE
X-Processor
X-FPC
X-Upstream-Ct
Pramga
Processtime
X-Dispatch
X-Aicache-OS
X-Dynatrace
X-Server-Time
X-Cache-FS-Status
SD-X-WS
X-SD-PageType
Arc-Country
X-Skip-Cache
X-WR-MODIFICATION
X-Dynatrace-Js-Agent
Servername
X-SN
CACHE
L
X-Cache-Id
Cache-Provider
X-Compress-Hint
X-DevSite-Last-Modified
X-ABtesting
X-Flog
X-Hello
X-ID
Fastly-Drupal-HTML
X-Frame-Option
X-StackifyID
X-WA
X-Ftr-Balancer
X-Via-NSCOPI
X-Ftr-Backend-Server
X-Ftr-Backend
Requestid
X-Ftr-Dc
X-Ftr-Realm
X-Release
X-ServerName
CF-IPCountry
Dynatrace
X-Served-From
X-Edge-Server
CDN
X-ND-Cache
X-Branch-Name
X-LB-ID
X-Snapshot-Date
Cdn-Host
Cdn-Request-Time
N-Cache
Pagetype
X-Fastly-Cache-Hits
Lfy
X-CACHE-AGE
X-Bc-Bl
X-Cc-Via
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
Proxy-Firewall
X-Edge-IP
X-Apw-Access-Token
X-Varnish-Beresp-TTL
X-ZONE
X-Request-Url
LB
X-Apw-Hits
V-Cache
X-Apw-Access-Object
Warning
D-Cc-Upstream
X-Apw-Access-Action
X-VC
X-Scheme
X-SB
X-Cc-Req-Id
Lb
X-Node-ID
UCS
Correlation-Id
Cache-Cookie-Set-From
Backend-Name
X-BC
X-ElasticPress-Search
X-Powered-Y
X-Request-URL
X-Check-Cacheable
WP-Super-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Worker
X-Fastly-Cache-Status
X-App