Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
X-Ua-Compatible
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Cache-Group
X-Backend
CF-Ray
X-Via
X-Age
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-LiteSpeed-Cache
Report-To
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Host
X-Device
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Ac
Content-Location
X-Node
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
X-Cache-Lookup
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
Rating
Edge-Control
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-DynaTrace
X-Country-Code
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-FTR-Request-ID
X-TTL
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Server
X-Use-Magma
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
Edge-Cache-Tag
RTSS
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
Ar-Sid
X-D2id
X-Px
X-Debug
X-Abt-Application-Version
X-Server-Name
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Vcache
X-Accel-Expires
X-MSEdge-Ref
X-Middleton-Display
X-Middleton-Response
X-Sol
Pagespeed
Response
Display
X-Amz-Rid
X-Vcap-Request-Id
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Powered-CMS
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
TCN
X-Fastcgi-Cache
X-Trace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
X-Cdn
Cache-Tag
X-Ser
X-Fastly-Request-ID
Access-Control-Request-Method
MS-Author-Via
S
X-DynaTrace-JS-Agent
X-Upstream
X-Shard
Nginx-Cache
SPIisLatency
SPRequestDuration
X-Id
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Ezoic-Cdn
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Hp-Webp
X-Content-Type
X-Forwarded-For
X-Grace
X-T
X-Amzn-Trace-Id
X-Amz-Meta-S3cmd-Attrs
DynaTrace
Front-End-Https
X-Recruiting
X-Hits
X-Edge-O15-RID
Fastcgi-Cache
Nel
X-Varnish-Age
X-Aspnet-Version
ServerID
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-DIS-Request-ID
X-Element-Page-Cache
X-Mobile-URL
X-Node-Name
NR-ENABLED
X-Cache-TTL
X-Server-ID
X-Content-Digest
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
Powered
X-Frontend
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Goog-Generation
X-Goog-Metageneration
X-HS-Hub-Id
X-Jurisdiction
X-FTR-DC
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
Server-Node
Alternate-Protocol
Server-Name
TP-Cache
TP-L2-Cache
X-Logged-In
X-Correlation-Id
X-XRDS-LOCATION
AMP-Access-Control-Allow-Source-Origin
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
Upgrade-Insecure-Requests
Backend-Timing
X-ATS-Timestamp
X-Amz-Apigw-Id
X-Webkit-Csp
X-Cache-Hit
X-Amzn-RequestId
X-Content-Options
X-Origin-Server
X-Content-Security-Policy-Report-Only
X-Page-Id
X-Rid
X-User-Agent
Refresh
X-Revision
X-Akamai-Edgescape
X-F-Cache
X-Varnish-Grace
X-Type
X-CST
Fastly-Restarts
X-Zen-Fury
X-XRDS-Location
X-Shield-Request-Id
X-Content-Powered-By
X-B3-Sampled
X-Geo-Country
X-LB-Cache
X-B
X-AppVersion
X-Az
X-Activity-Id
X-N
X-FTR-Cache-Host
X-Webapp-Samesite-None-Activated-N
X-URL
PB-PID
PB-RID
X-Mobile-Rewrite
Arc-Version
X-Kinsta-Cache
X-Pad
Cache-Status
X-WebKit-CSP-Report-Only
X-Cache-Age
X-TT
X-Time
X-Debug-Info
X-Instance
X-AOL-HN
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-B-Cache
Actual-Object-TTL
Paypal-Debug-Id
X-App-Environment
X-Tumblr-User
X-Request-Guid
X-Signature
X-Framework
X-Jobs
Access-Control-Allow-Method
X-Cache-Action
DC
X-FB-Debug
X-PHP-Backend
X-Analytics
X-RateLimit-Remaining
X-Load-Cache
X-Git-Hash
X-Cached-By
X-Varnish-Backend
Surrogate-Key
Fastcgi-Useragent
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Tt-Trace-Tag
Host-Header
X-Amz-Replication-Status
X-Tt-Trace-Host
X-IPLB-Instance
X-Contextid
MS-CV
X-Ttl
X-SS-Set-Cookie
FilterID
X-ATG-Version
X-Ruxit-Js-Agent
X-Cache-Key
X-Cluster
Tracecode
X-WA-Info
Host
NGB
X-Response-Served-From
X-Accel-Buffering
X-FastCGI-Cache
X-Mobile
X-Srv
WPE-Backend
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Source
Payment
X-Cache-NE
X-Varnish-Server
X-Host-Name
X-VCache
X-Cache-Operation
X-Cache-2
Eomportal-Instance
X-Cache-Rule
X-FW-Hash
X-Region
X-FW-Static
X-FW-Server
X-FW-Serve
Frame-Options
X-FW-Type
X-Cacheable-TTL
X-ORACLE-APMCS-TAG
X-Via-JSL
X-Cache-Enabled
Filters
Cache-Tv-Group
X-ORACLE-APMCS-REQUEST-ID
X-Tumblr-Pixel-2
X-Varnish-Hostname
X-GeoIP
X-Tumblr-Pixel-1
X-IPS-LoggedIn
X-Adobe-Content
X-Adobe-Loc
X-Is-Bot
X-Rendered-As
X-Presslabs-Stats
X-RequestSource
X-NewRelic-App-Data
X-TX-ID
Xserver
X-Hostname
X-Origin-Response-Time
X-EdgeConnect-Cache-Status
X-Seen-By
X-NWS-LOG-UUID
Cleartype
Retry-After
X-Cache-TTL-Remaining
Server-Info
Cache
X-RemovedCookies
X-ProcessESI
X-UA
Liferay-Portal
X-Dc
Accept-CH
Datacenter
X-HTML-Minification-Powered-By
X-RTag
X-Cache-Control
X-B3-Traceid
Ms-Operation-Id
Healthy
X-Source
X-L-Path
X-Environment-Context
X-FireWall-Port
X-Upgrade-Enabled
X-App-Server
X-Endurance-Cache-Level
From-Origin
X-Cache-Server
X-Handled-By
X-RateLimit-Limit
X-Rule
Version
X-CACHE-KEY
X-Status
X-PressLabs-Stats
Accept-CH-Lifetime
X-Wix-Request-Id
X-APP-VERSION
X-Backend-Name
Meta-Geo
X-ES-SERVER
X-Path-Route
X-Cache-Var-Map
X-RN-RSRV
X-Cache-Var
X-Proxy-Build
X-Tb
X-Access
X-Timing-Wait
OT-Force-Account-Verify
Selected-Fe
X-Section
X-Format
X-Request-Time
X-Origin
X-Storage
Azure-SiteName
X-Sorting-Hat-ShopId
X-EIG-Tracking-Id
Azure-Version
Cache-Tags
X-Human
X-Sorting-Hat-PodId
X-Shopify-Generated-Cart-Token
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Shopify-Stage
X-Proto
Mn-Server-Ip
X-Akamai-Request-ID
Akamai-GRN
X-ShopId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Content-Age
X-Alternate-Cache-Key
X-ShardId
X-Soup
X-Cache-Host
GEO-INFO
X-PCL
X-Proxy
X-Akamai-Request-ID2
X-Generated-By
X-Vgn-Hpd-Reason
X-FC-Vary-Parameters
X-Cache-Config
X-FW-Dynamic
X-BYPASS-REASON
Decoy-Debug-Status
X-Hl-Ver
X-OCL
X-ServerID
X-ProxyCache-Status
X-Time-Microsecs
X-Qloud-Router
Ec-Rule-Version
X-Web-Node
NGX
X-Redis-Cache
S-Rt
X-JoinUs
Node
X-Pubstack
X-NYM-Debug-Backend
Decoy-Debug-Key
Srv
Origin-Cache-Control
X-Hosted-By
X-SaId
X-Hyper-Cache
Decoy-Debug-TTL
X-ProxyCache-Key
X-UUID
X-MP-GENERATED-AT
Origin-Edge-Control
TWC-GeoIP-LatLong
TWC-Locale-Group
Now
Property-Id
DB-Nickname
TWC-Connection-Speed
Webcakes-Region
TWC-GeoIP-Country
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
X-Say-TTL
X-Www-Served-By
X-LJ-Flow-ID
X-RCS-CacheZone
X-IP
X-Say-Cacheable
X-Viewer-Country
X-Site-Version
X-Locale
X-Proxy-Cache-Status
X-Varnish-Hits
X-Origin-Hint
X-Trafficlayer-App-Name
X-VWS-Id
X-Trafficlayer-App-Scope
TWC-Device-Class
X-SayCDN-TTL
X-Debug-Cache
X-Yottaa-Optimizations
X-Cluster-Node
X-BCube-Filmed-By
X-AWS-Id
X-Yottaa-Metrics
X-Detected-As
X-Generated
X-Amzn-Remapped-Content-Length
X-Akamai-Transformed
X-FB-TRIP-ID
X-TNCMS
Accept-Charset
X-Loop
Cross-Origin-Window-Policy
X-R9-Blue-Green-Version
L5d-Success-Class
X-CCM
X-CS
X-Xfnlog-Site
X-Oneagent-Js-Injection
X-NCache
Cache-Name
Uber-Trace-Id
Viewport
X-Unique-Id
Webserver
X-Drupal-Cache-Tags
Time
Cache-Key
X-Esi
X-UA-Device-Type
X-Cache-Remote
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-From
Accept-Language
X-Backend-TTL
X-Mode
Mime-Version
X-Origin-CC
X-Drupal-Cache-Contexts
X-Cluster-Name
X-CDN-Forward
X-Origin-TTL
X-UnsetCookies
X-Forwarded-Host
X-TT-TIMESTAMP
Country
Rt-Fastcgi-Cache
X-Whom
X-Info
Odigeo-Trace-Id
X-Edge-Location
X-Microcachable
X-Newrelic-Synthetics
X-B3-Spanid
X-Daa-Tunnel
X-ApacheServer
X-Varnish-Cache-Hits
X-PERF
X-Geo
X-Magnolia-Registration
X-NGENIX-Cache
X-CLOUD-TRACE-CONTEXT
ServedBy
Content-Disposition
X-EC-Lua
X-UPSTREAM-Address
Ohc-File-Size
Proxy-Connection
Ohc-Cache-HIT
X-Zipkin-Id
X-Proxied
X-Device-Type
X-Routing-Service
X-Uri
X-Via-Fastly
X-No-Session
X-TA-CDN-Provider
BehaviorPad-Version
W
VivaBuild
X-Rocket-Build-Number
AsisCache
Viewtype
X-VG-WebServer
X-D
Apple-News-Services-Request-Url
Meta-Geo-Continent
X-Request-UUID
X-Destination
Mobile-Detection-Method
X-GeoIP-Country-Code
X-Region-Sid
Apple-News-Services-Handled
X-G
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Application
X-ARC
Xc-Version
Rendered-Blocks
T-Server
X-External-Request-Id
X-DPWN-IS-SECURE
Apple-News-Services-Host
X-Vtex-Processado-Em
X-Rojux
X-Vtex-Remote-Cache
X-Geo-Header
Apple-News-Services-Parsed-Url
X-Rewrite-Enabled
X-S
X-Date
X-Connection-Hash
Fastcgi-X-Cache-Version
X-Aed
X-VG-WebCache
X-Accel-Expires-Debug
X-VG-TLSProxy
X-Transaction
GEO-REGION-INFO
X-B-Cookie
X-Labrador-Cache-Channel
X-Vdms-Version
X-Twitter-Response-Tags
X-Trv-Group
Machine
X-A-Wwc
X-PHP-Host
X-Sigma
X-S-Cookie
X-Sigma-Backend
X-ScT
X-Session-Fingerprint
X-A
X-A-Dgt
Content-Style-Type
Content-Script-Type
X-A-Ccd
X-A-Dcw
X-SRCache-Key
X-A-Dam
MD5-Digest
X-C
X-Real-IP
HitType
Cf-Ipcountry
Ha-Gx-Prefs
IsBot
HA-Ipaddr
X-CUA
Gh-Request-Id
Environment
Fastly-Soc-X-Request-Id
X-Hit
Powered-By
X-Auto-Login
X-Backend-State
X-Logging-Id
X-Bip
Server-Surrogate-Control
X-TrackingId
X-CGP
X-Render-Time
X-Developers
X-Cache-Time
X-VC-Cache
X-Agile-Id
X-Epic-Correlation-Id
X-Tumblr-Pixel-3
X-Eu-Site
X-Varnish-Authentication
Server-Cache-Control
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Contensis-Viewer-Groups
X-App-Name
X-SIPLIST1
X-Nc
X-Agile-Age
X-Agile
X-Cache-ASPX
X-Thanos
X-Distil-CS
Section-Io-Cache
Fastly-SSL
X-GoCache-CacheStatus
User-Cache-Control
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Locid
Locale
X-Debug-Cache-Expiry
X-AK-Request-ID
X-Hash
X-Debug-Cache-Fetch
X-Dispatcher-Server
X-Fetched-On
X-Fastly-Cache
Server-Int
X-FW-Version
X-Gamma-Serve
Request-Country
Request-EU
X-Generated-In
Kp-EeAlive
X-Generation-Time
X-Debug-Log
X-Debug-Cookies
X-Debug-Cache-Store
X-Azure-Ref
V-Age
X-GeoIP-City
X-Distributor
Memcached
X-LI-UUID
X-Cache-Debug
X-Rebelmouse-Surrogate-Control
X-VServer
X-Tec-Api-Origin
X-Core-Mission
X-Tec-Api-Root
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-OVcl-Cache
X-OVcl
X-Owner
X-Cache-Backend
X-RateLimit-Limit-Second
X-Cache-Bucket
X-Tec-Api-Version
X-Server-W
X-TT-LOGID
X-Trace-Id
X-Cdn-Srv
X-Urbn-Context-Path
X-User
X-Urbn-Site-Id
X-Cache-URL
Geo-Info
X-Sucuri-Cache
X-Cache-Info
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TH-Server
X-Swa-Ws
X-Origin-Expires
X-Origin-Date
Cdnsip
Country-Code
Cdncip
CDCHOST
AKAMAI
X-Key
Countrycode
X-BBXSRF
Heartbleed
IBM-Web2-Location
X-Irp-Debug
Fastly-SWR
Fastly-Backend-Name
Fastly-SIE
X-Li-Fabric
Access-Control-Request-Headers
X-WebServer
X-Webstats-RespID
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-We-Are-Hiring
X-Varnish-Beresp-Grace
X-NX-Host
X-NodeID
X-Micro-Cache
X-LI-Proto
X-Li-Pop
X-Clientip
X-Nginx-Cache-Key
X-Instart-Isnd
X-App-Version
X-Core-Value
X-Ms-Request-Id
X-Service
X-ServiceProvider
X-Request-URI
X-Reboot
X-Proxy-Upstream
X-Thinkindot-L3
X-Trafficlayer-App-Version
X-Servername
X-WADP-Cache
X-Variation
X-Up
X-Platform-Server
X-Old-Content-Length
X-Internal-Host
X-Hnp-Log
X-Has-Esi
X-Generated-On
X-Is-Gdpr
X-JWT-State
X-NU-AKA-ACS-Version
X-Ms-Version
X-Matched-Rule
X-Level-Front-Cache
X-Gen-Mode
X-Cms-Context
Server-ID
Server-Host
RNT-Time
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
True-Client-Country-4JS
Thinkindot-Control
RNT-Machine
Platform
Adler-Geo
ServerName
Cache-Host
Is-Eu
PFcat
Mail-Subject
We-Hiring
X-Clara-WADP
Wxu-Next-Region
Web-Mar-Node
Wxu-Next-Commit
Wxu-Next-Hostname
X-Cache-Tags
X-Block-Status
Cache-Hits
FNAC-ModuleRouting
X-Lb-Id
X-S-Maxage
X-CACHE-GROUP
X-Nginx-Cache
X-Response-By
X-Location
X-Req
Filterid
X-SERVER
X-B3-Parentspanid
X-Parent-Response-Time
X-Refresh
RequestId
X-Tb-Optimization-Total-Bytes-Saved
X-Var-Ttl
X-Air-Hostname
X-Cache-Expired-At
X-CF-Powered-By
X-Cdn-Forward
X-B3-SpanId
S-Cnection
X-NC
Pragrma
Memory
X-CSRF-Token
ProcessTime
Group
X-CSRF-TOKEN
X-BACKEND-TTL
X-Server-IP
X-Pjax-Url
Powered-By-ChinaCache
User-Agent
X-Wa
Origin
X-Pf-Uncompressing
Geoip-Latitude
GeoIp-Country-Code
Media-Length
TTL
X-Cdn-Request-ID
X-Ua
X-Correlation-ID
X-Sucuri-ID
SRV
X-NGINX-Cache
X-Unique-ID
PICS-Label
Geoip-City
X-NWS-UUID-VERIFY
X-Varnish-Cacheable
X-Sucuri-Id
X-Vcl-Version
X-COUNTRY
X-Via-CDN
X-Rocket-Nginx-Bypass
Dnion-Transfer-Encoding
X-Developer
XServer
X-Cache-Grace
X-Ocache
X-Sn-Servicetimems
X-Node-Id
X-LAGOON
X-Servedbyhost
X-AIR-PT
SN
Esi-Enabled
X-Device-Os
X-Cdn-Origin
X-Reqid
X-Webkit-CSP
X-Litespeed-Cache
On-Server
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Varnish-Ttl
X-Policy
X-Planisys-CDN-Cache
X-Via-Ucdn
X-TIME
X-MSEdge-Flight
X-HS-Status
X-MSEdge-Features
X-Request-Start
M-TraceId
X-Fastly-Country-Code
X-Request-Host
A
X-Azure-Ref-OriginShield
Tcn
X-Cache-Status-Check
X-FORWARDED-FOR
HostName
Rt-Proxy-Cache
Cloudfront-Viewer-Country
X-Oss-Request-Id
Hostname
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-ServedByHost
Cdn
X-Cache-Ttl
Who
Resin-Trace
X-Ftr-Cache-Host
X-VHOST
Magicmarker
NtCoent-Length
X-Beluga-Record
X-Beluga-Response-Time
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Node
X-Beluga-Cache-Status
X-Method
X-Zone
Pics-Label
X-Bc
Host-ID
CF-Cached-On
X-Varnish-URL
X-Ratelimit-Remaining
X-APP
MIME-Version
GeoIP-Country-Code
Load-Balancing
X-VCL-Version
X-LiteSpeed-Cache-Control
X-Oracle-Dms-Rid
Ttl
X-Be
X-Slack-Backend
Cteonnt-Length
X-Fastly-Backend-Reqs
X-Svr
GeoIP-Latitude
Ohc-Response-Time
X-Varnish-Url
DSUID
X-DC
X-VarnishDD-TTL
X-RPS
X-DB
X-DI
X-DSS
X-Action
X-PF-Uncompressing
X-RSL
X-DW
X-RPM
Release
GeoIP-City
X-VCT
X-Newrelic-App-Data
Vix-Hermes-Req-Id
X-MServer
X-Hp-Ccpa-Warning
X-PAYTM-SRV-ID
WebServer
X-Dispatch
X-HostName
Pramga
X-Cache-FS-Status
X-Processor
X-FPC
X-SRV
Amp-Access-Control-Allow-Source-Origin
X-Ratelimit-Limit
X-Tid
Processtime
X-PJAX-URL
X-Skip-Cache
Arc-Country
X-Ftr-Request-Id
X-Server-Time
CACHE
X-Swift-Error
X-Hello
X-Configured-By
X-ND-Cache
X-Flog
X-Dynatrace
X-DevSite-Last-Modified
Fastly-Drupal-HTML
X-BE
X-ABtesting
CF-IPCountry
X-WR-MODIFICATION
X-Dynatrace-Js-Agent
Servername
X-Edge-Server
X-Served-From
N-Cache
X-ID
Cdn-Host
X-SD-PageType
Cdn-Request-Time
Cache-Provider
X-Upstream-Ct
X-Upstream-Ht
SD-X-WS
X-Aicache-OS
X-Frame-Option
Lfy
X-Cache-Id
L
X-Ftr-Backend
X-WA
X-Snapshot-Date
CDN
X-Compress-Hint
X-Branch-Name
X-LB-ID
X-Amzn-Remapped-Connection
Pagetype
X-StackifyID
X-SN
X-Ftr-Realm
Requestid
X-Fastly-Cache-Hits
X-Bc-Bl
Dynatrace
X-Ftr-Balancer
X-Ftr-Dc
X-Amzn-Remapped-Date
X-Ftr-Backend-Server
X-CACHE-AGE
X-ZONE
X-Via-NSCOPI
X-Edge-IP
X-Varnish-Beresp-TTL
X-Apw-Access-Action
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Object
Proxy-Firewall
Warning
X-SB
X-ServerName
V-Cache
X-Backend-Host
X-VC
X-Request-Url
X-Cc-Via
X-Cc-Req-Id
D-Cc-Upstream
X-Release
Lb
LB
X-Request-URL
X-Check-Cacheable
X-Powered-Y
WP-Super-Cache
X-ElasticPress-Search
X-Scheme
X-Worker
Correlation-Id
X-App
X-Fastly-Cache-Status
X-BC
Backend-Name