Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
Alt-Svc
X-Adblock-Key
X-Drupal-Cache
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
P3p
X-Template
X-Language
Status
Timing-Allow-Origin
X-Iinfo
Content-Encoding
X-Content-Security-Policy
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Age
X-Drupal-Dynamic-Cache
X-Backend
X-Server
X-Pingback
X-Amz-Request-Id
X-Amz-Id-2
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
EagleId
X-Server-Powered-By
X-UA-Device
X-Varnish-Cache
Request-Context
X-Nginx-Cache-Status
X-Request-ID
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Server-Id
Feature-Policy
Server-Timing
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Host
X-Rq
Report-To
X-Ac
X-Node
Content-Location
X-OneAgent-JS-Injection
X-Cnection
X-Response-Time
X-Backend-Server
X-Cloud-Trace-Context
X-Origin-Cache
X-Application-Context
Request-Id
X-Readtime
Allow
Surrogate-Control
EagleEye-TraceId
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Country
X-DynaTrace
X-Vhost
X-Cache-Lookup
X-TTL
X-Cdn
Pinterest-Generated-By
X-Rack-Cache
X-Clacks-Overhead
X-Origin-Upstream-Status
X-Url
X-Ua-Compatible
NEL
X-FTR-Request-ID
X-Ruxit-JS-Agent
Rating
X-Country-Code
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-CST
X-Dispatcher
X-HW
X-Goog-Hash
X-ORACLE-DMS-RID
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
X-DataStream-Cache-Status
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Px
X-VARITI-CCR
X-DataDome
Service-Worker-Allowed
Verso
X-Mod-Pagespeed
X-MS-InvokeApp
X-Recruiting
X-Varnish-TTL
X-D2id
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
SPRequestGuid
RTSS
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
TCN
X-SharePointHealthScore
X-Navigation-Version
X-GitHub-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
DynaTrace
X-Middleton-Display
Display
Response
X-Middleton-Response
X-Sol
X-Akam-SW-Version
X-Powered-By-Plesk
X-RateLimit-Remaining
MS-Author-Via
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Charset
X-Shield-Request-Id
ServerID
X-Forwarded-Proto
X-Amz-Rid
Content-MD5
AR-PoweredBy
AR-CACHE
AR-ATIME
Ar-Sid
X-B3-TraceId
X-Trace
X-Powered-CMS
Accept-Ch-Lifetime
X-Upstream
Nginx-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Version
Realpath
Fastly-Restarts
X-Cached
Public-Key-Pins
X-Dw-Request-Base-Id
Accept-Ch
X-Shard
AR-Request-ID
X-DynaTrace-JS-Agent
X-Mrf-Item-Lastmod
X-ESI
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
Mrf-Cache-Status
Pagespeed
X-Server-Name
Access-Control-Request-Method
X-MSEdge-Ref
Paypal-Debug-Id
X-Vcache
X-Goog-Storage-Class
SPIisLatency
X-Client-IP
SPRequestDuration
X-Grace
S
X-Debug
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Realm
X-Country-Code-Real
X-FTR-DC
X-FTR-Expires
X-FTR-Balancer
X-Id
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Ezoic-Cdn
X-Amz-Meta-S3cmd-Attrs
X-FastCGI-Cache
Pinterest-Version
X-Pinterest-Rid
Accept-CH
X-N
X-Upstream-Proxy
X-Fastly-Request-ID
X-T
Front-End-Https
X-Amzn-Trace-Id
X-DIS-Request-ID
Arr-Disable-Session-Affinity
X-NF-Request-ID
X-Content-Type
X-B3-Traceid
MicrosoftSharePointTeamServices
X-Hits
X-XRDS-Location
X-B3-Sampled
X-FTR-Cache-Host
X-Varnish-Age
X-Ser
Arc-Version
PB-RID
X-Frontend
X-Mobile-Rewrite
PB-PID
Fastcgi-Cache
X-Acc-Meta-Resource-Type
Server-Name
X-Content-Digest
X-Logged-In
Alternate-Protocol
X-Correlation-Id
X-Srv
X-Cache-Key
X-Node-Name
X-Pad
X-Esi
Nel
AMP-Access-Control-Allow-Source-Origin
X-Request-Handler-Origin-Region
X-Microsite
FilterID
X-Forwarded-For
TP-Cache
TP-L2-Cache
Host
X-Type
X-Rid
Healthy
X-Kinsta-Cache
X-User-Agent
X-LB-Cache
Powered-By-ChinaCache
X-Request-Processing-Time
X-Request-Received
X-IPLB-Instance
X-F-Cache
X-Zen-Fury
Edge-Cache-Tag
X-Debug-Info
X-AOL-HN
X-Cache-2
X-Amz-Apigw-Id
X-Amzn-RequestId
Powered
X-GUploader-UploadID
X-Cached-By
X-Revision
X-VCache
X-Hostname
X-HS-Content-Id
X-HS-Hub-Id
Backend-Timing
X-Analytics
X-Cache-Age
X-Kong-Upstream-Latency
X-Cache-Rule
X-Kong-Proxy-Latency
X-Via-JSL
X-Accel-Expires
X-XRDS-LOCATION
X-AppVersion
X-Activity-Id
X-Az
Surrogate-Key
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Varnish-Backend
X-Content-Security-Policy-Report-Only
X-BCube-Filmed-By
X-Content-Options
X-Page-Id
X-Instance
X-RateLimit-Limit
X-Cluster
X-FB-Debug
X-Varnish-Grace
X-Amz-Replication-Status
X-Tumblr-Pixel-0
X-Tumblr-User
X-Akamai-Edgescape
X-Tumblr-Pixel
X-Jobs
X-Request-Guid
X-PHP-Backend
Source
X-Content-Powered-By
Cache-Status
Server-Node
X-App-Environment
X-TT
X-Forwarded-Host
X-Signature
Refresh
X-B-Cache
Cleartype
X-Framework
X-Fastcgi-Cache
Liferay-Portal
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Hash
X-FW-Static
Accept-CH-Lifetime
X-Server-ID
X-Varnish-Hostname
DC
X-ATG-Version
Tracecode
Host-Header
Accept-Charset
WPE-Backend
Access-Control-Allow-Method
X-APP-VERSION
Fastcgi-Useragent
X-Cache-Operation
X-Cache-Control
X-Edge-Location
X-Cache-Action
X-Drupal-Cache-Tags
X-Mobile
X-Time
X-B
X-Cache-Hit
Actual-Object-TTL
X-Erf-Bev-Bev-Is-Generated
X-Hp-Webp
X-Mobile-URL
X-Response-Served-From
X-Erf-Bev-Bev
Payment
X-Accel-Buffering
X-Whom
X-Storage
X-TX-ID
X-App-Server
X-Oracle-Dms-Rid
X-Content-Age
X-NWS-LOG-UUID
X-WA-Info
X-WebKit-CSP-Report-Only
X-TT-TIMESTAMP
X-Yottaa-Optimizations
Cache-Tv-Group
Upgrade-Insecure-Requests
X-Yottaa-Metrics
NGB
X-Handled-By
Filters
X-UA-Device-Type
X-Git-Hash
X-SS-Set-Cookie
X-Status
X-Tumblr-Pixel-2
X-GeoIP
Eomportal-Instance
X-Adobe-Loc
X-Adobe-Content
X-Tumblr-Pixel-1
X-Cacheable-TTL
X-ProcessESI
X-RemovedCookies
X-RequestSource
Cache-Tag
Viewport
X-Geo-Country
X-VG-WebCache
Retry-After
Xserver
Cache
Datacenter
Webserver
X-Cache-TTL-Remaining
X-FW-Dynamic
X-Cache-TTL
X-Presslabs-Stats
X-Seen-By
MS-CV
Server-Info
X-Ratelimit-Reset
X-FB-TRIP-ID
X-Cache-Enabled
X-TA-CDN-Provider
X-Host-Name
X-B3-Spanid
X-Contextid
X-Ratelimit-Limit
Frame-Options
X-Generated-By
From-Origin
X-RTag
X-Origin-Server
Ms-Operation-Id
X-Hyper-Cache
S-Cnection
X-Mode
Country
X-CF-Powered-By
X-Tumblr-Pixel-3
X-Cache-Var-Map
X-Cache-Config
X-Cache-Var
Machine
X-Path-Route
Meta-Geo
X-ES-SERVER
Load-Balancing
X-RN-RSRV
X-PressLabs-Stats
X-Upstream-HT
X-MP-GENERATED-AT
X-Zipkin-Id
X-Labrador-Cache-Channel
X-Proxied
Cache-Key
X-Upstream-CT
X-Hit
Vix-Hermes-Req-Id
X-Access
X-Cache-Grace
X-Routing-Service
X-Section
X-Cache-Host
X-PCL
X-Backend-Name
GEO-INFO
X-Human
SRV
Decoy-Debug-Key
X-Varnish-Cache-Hits
X-OCL
X-TNCMS
Decoy-Debug-TTL
X-Varnish-Server
X-Loop
Decoy-Debug-Status
X-Web-Node
X-From
Now
X-Viewer-Country
X-Upgrade-Enabled
ServedBy
Mn-Server-Ip
X-Via-Fastly
X-LJ-Flow-ID
X-Origin-Response-Time
X-L-Path
X-Region
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Magnolia-Registration
X-ShopId
X-ShardId
X-Shopify-Stage
X-Environment-Context
X-Endurance-Cache-Level
X-VWS-Id
X-R9-Blue-Green-Version
X-AWS-Id
X-Alternate-Cache-Key
X-CCM
X-Debug-Cache
X-VG-TLSProxy
X-EIG-Tracking-Id
X-Rule
X-Akamai-Request-ID
Rt-Fastcgi-Cache
X-Drupal-Cache-Contexts
We-Hiring
X-Cluster-Node
DSUID
X-RCS-CacheZone
X-S
X-Timing-Wait
OT-Force-Account-Verify
X-Xfnlog-Site
Mail-Subject
DB-Nickname
X-Varnish-Hits
X-Rendered-As
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated
Cache-Name
X-NCache
X-JoinUs
X-Proto
X-Hosted-By
Akamai-GRN
X-FC-Vary-Parameters
X-Proxy-Build
X-Device-Type
X-Guploader-Uploadid
Release
Version
Uber-Trace-Id
X-Site-Version
X-Locale
X-Nginx-Cache
X-NewRelic-App-Data
Cteonnt-Length
X-Www-Served-By
X-BYPASS-REASON
X-VCT
X-ProxyCache-Status
X-ProxyCache-Key
X-Trace-Id
ProcessTime
X-Request-Time
X-Time-Microsecs
NGX
X-IP
X-Load-Cache
Time
X-UUID
X-Redis-Cache
X-Platform-Server
S-Rt
X-Origin
CACHE
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Wix-Request-Id
Azure-SlotName
X-FW-Version
X-Dc
X-Via-CDN
X-Origin-Hint
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
Property-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
X-EdgeConnect-Cache-Status
X-GEO
X-ECACHE
X-Cache-NE
X-Akamai-Request-ID2
X-MServer
NtCoent-Length
X-Daa-Tunnel
X-FireWall-Port
X-Hl-Ver
X-CDN-Forward
X-Proxy
X-Rocket-Nginx-Bypass
X-No-Session
X-SERVER-NAME
X-ServerID
X-Vgn-Hpd-Reason
X-IPS-LoggedIn
X-RateLimit-Reset
X-Cache-Remote
Origin
X-Akamai-Transformed
X-HTML-Minification-Powered-By
X-ApacheServer
X-PERF
X-Format
X-UA
X-Distributor
Odigeo-Trace-Id
X-CS
X-Cache-Server
X-Oneagent-Js-Injection
Fastly-SSL
Ec-Rule-Version
Cache-Tags
Access-Control-Request-Headers
X-UnsetCookies
X-Real-IP
L5d-Success-Class
Accept-Language
X-Microcachable
X-Pubstack
LB
Hostname
X-Tb
X-Unique-ID
Origin-Edge-Control
Origin-Cache-Control
X-Webkit-Csp
Served-By
X-NC
X-Cache-Backend
Fastcgi-X-Cache-Version
X-Compress-Hint
X-Varnish-Cacheable
X-Grey
X-Cache-Category-Id
IBM-Web2-Location
Request-EU
Content-Style-Type
Fastly-SWR
X-Developer
X-Org
Rendered-Blocks
Request-Country
Fastly-SIE
Request-Time
X-PAYTM-SRV-ID
X-Vtex-Remote-Cache
Fly-Cache
Rt-Proxy-Cache
Fly-Request-Id
GEO-REGION-INFO
Cross-Origin-Window-Policy
X-Vtex-Processado-Em
Server-ID
X-B3-Parentspanid
X-DPWN-IS-SECURE
MD5-Digest
X-G
A
X-IN-APIGATEWAY
X-Instart-Info
X-Transaction
Arc-Country
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
BehaviorPad-Version
AsisCache
X-Internal-Host
X-External-Request-Id
X-Edge-Server
Cdn-Request-Time
Content-Script-Type
Cache-Prefix
Proxy-Firewall
Cdn-Host
Viewtype
X-Is-Bot
Meta-Geo-Continent
Mobile-Detection-Method
Node
X-NU-AKA-ACS-Version
X-Detected-As
X-Rewrite-Enabled
X-ARC
X-Connection-Hash
X-Rojux
X-S-Cookie
X-Request-UUID
Xc-Version
X-Varnish-Url
X-D
X-AIR-PT
VivaBuild
X-Application
X-Twitter-Response-Tags
X-S-Maxage
X-Worker
X-SRCache-Key
X-CF-Lambda-Fn
X-Trv-Group
X-CF-Lambda-Version
X-Cdn-Srv
X-Server-Time
X-B-Cookie
X-ScT
X-Cluster-Name
X-Cache-Bucket
X-Aed
X-App-Name
X-Date
X-Rebelmouse-Cache-Control
X-A-Dam
X-A-Ccd
Proxy-Connection
X-Accel-Expires-Debug
X-BACKEND-TTL
X-A
X-Rebelmouse-Surrogate-Control
X-A-Dcw
X-VG-WebServer
Backend-Name
X-A-Wwc
X-A-Dgt
X-Destination
X-Region-Sid
X-URL
ServerName
X-ElasticPress-Search
X-Cache-Info
X-Clientip
Ha-Gx-Prefs
X-Cache-Id
Server-Int
W
True-Client-Country-4JS
X-Developers
X-Debug-Log
X-GeoIP-Country-Code
X-Cdn-Origin
Gh-Request-Id
X-Fastly-Cache
X-Eu-Site
Resin-Trace
X-Epic-Correlation-Id
On-Server
Platform
X-Core-Mission
Memcached
RNT-Machine
X-Backend-State
Section-Io-Cache
HA-Ipaddr
Is-Eu
RNT-Time
X-Debug-Cookies
Apple-News-Services-Request-Url
X-Amzn-Remapped-Content-Length
X-We-Are-Hiring
REQUESTUUID
X-Geo-Header
X-HS-Combine-CSS
X-C
Adler-Geo
X-PHP-Host
AKAMAI
X-Request-URI
X-NX-Host
X-Nginx-Cache-Key
X-Edge
X-Location
X-Variation
Apple-News-Services-Host
Apple-News-Services-Handled
X-Skip-Cache
X-SVT-ORM-VERSION
X-CGP
Content-Disposition
X-Sn-Servicetimems
Esi-Enabled
Countrycode
X-SVT-ORM-RULES
X-ServiceProvider
Apple-News-Services-Parsed-Url
X-HS-Cache-Config
Selected-Fe
V-Age
X-Method
X-Reqid
X-WADP-Cache
X-Level-Front-Cache
X-Reboot
Web-Mar-Node
X-Generated-On
X-Wikidot-Backend
X-Auto-Login
X-Clara-WADP
X-Servername
X-Server-IP
X-Cache-FS-Status
X-SIPLIST1
X-TH-Server
X-CDN-Cache
X-Block-Status
X-Secret
User-Cache-Control
X-Response-By
X-Amz-Meta-Cache-Control
X-Cms-Context
X-Wikidot-Static-Cache
X-BBXSRF
X-SD-PageType
X-Request-Start
X-Device-Os
X-Distil-CS
X-Qloud-Router
IsBot
X-Fetched-On
CDCHOST
X-FPC
X-WebServer
X-Irp-Debug
N-Cache
X-Li-Fabric
X-Li-Pop
X-LI-Proto
PFcat
X-LI-UUID
X-Dispatcher-Server
X-Gannett-Site-Version
SS
X-GeoIP-City
Fastly-Soc-X-Request-Id
Country-Code
UCS
X-Hash
X-Key
X-Dispatch
X-Gen-Mode
X-Hnp-Log
SD-X-WS
X-Generation-Time
Server-Host
X-Powered-By-Defense
X-SERVER
X-Thinkindot-L3
X-Matched-Rule
X-Proxy-Cache-Status
X-Processor
X-Proxy-Upstream
X-TrackingId
X-Swa-Ws
X-VServer
X-Origin-Expires
X-Webstats-RespID
X-Crawler
X-Origin-Date
X-VC-Cache
X-Release
L
Who
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
Wxu-Next-Commit
Pramga
Powered-By
X-Via-NSCOPI
X-Nc
GW-Server
Wxu-Next-Hostname
Heartbleed
X-Azure-Ref
X-Azure-Ref-OriginShield
Wxu-Next-Region
CF-IPCountry
X-Pf-Uncompressing
X-OVcl-Cache
X-Served-From
X-Ua
X-OVcl
X-Via-Edge
X-Via-SSL
X-Bip
X-Owner
Kp-EeAlive
X-CUA
X-Thanos
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
Mime-Version
X-Parent-Response-Time
X-Varnish-Ttl
X-CLOUD-TRACE-CONTEXT
X-Varnish-Beresp-Ttl
X-FE
Magicmarker
User-Agent
X-LAGOON
X-Ratelimit-Remaining
X-Dynatrace-Js-Agent
PageSpeed
X-ND-Cache
Memory
X-Flog
X-Protected-By
X-Hello
X-ABtesting
X-Page-Type
X-Cache-Ttl
Pragrma
Pagetype
X-Fstrz
X-Be
X-Origin-CC
X-Origin-TTL
X-Datadome
X-Backend-Url
X-Planisys-CDN-TTL
X-Newrelic-Synthetics
X-Generated-In
X-Backend-Host
X-Planisys-CDN-Cache
X-User
X-Planisys-CDN-Rules
X-Ttl
X-GoCache-CacheStatus
X-COUNTRY
X-MSEdge-Flight
X-MSEdge-Features
X-Up
X-Tt-Trace-Tag
X-Geo
X-Zone
X-DC
X-Varnish-Beresp-Grace
X-Backend-TTL
X-Varnish-Beresp-Status
X-Core-Value
X-IN-WAF
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Soup
X-Phone
X-Check-Cacheable
X-Oss-Server-Time
X-Oss-Storage-Class
X-B3-SpanId
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
Geoip-Latitude
GeoIp-Country-Code
X-TT-LOGID
Geoip-City
X-Cdn-Forward
X-Servedbyhost
X-ZONE
X-Litespeed-Cache
X-SayCDN-TTL
X-Old-Content-Length
X-Say-TTL
X-Say-Cacheable
SN
Cdn
Cache-Hits
X-Birta-Cache-Post
X-Birta-Served
X-Real-Ip
X-Info
X-Varnish-IP
X-VCL-Version
X-Akamai-SSL-Client-Sid
HitType
X-Mid
X-MID
Selected-FE
X-CSRF-TOKEN
X-HS-Status
X-Cache-Time
X-GRACE
X-Ruxit-Js-Agent
Amp-Access-Control-Allow-Source-Origin
FSS-Proxy
X-Vcl-Version
Fastly-Backend-Name
X-Node-Id
X-Aicache-OS
FSS-Cache
X-FORWARDED-FOR
Inserted-Into-Cache-At
XServer
X-ServedByHost
X-Agile
X-BC
X-IN-APIGATEWAYSSL
X-Agile-Age
X-Agile-Id
X-Amzn-Remapped-Connection
X-Logtrace-Id
Ajk
WZWS-RAY
X-Amzn-Remapped-Date
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Debug
X-Refresh
CF-Cached-On
X-EC-Lua
X-Bc
X-Source
X-Cache-ASPX
Server-Cache-Control
GeoIP-Country-Code
X-UPSTREAM-Address
Server-Surrogate-Control
X-Contensis-Viewer-Groups
X-Varnish-Authentication
HostName
X-Via-Ucdn
GeoIP-Latitude
X-Wa
GeoIP-City
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Web-Server
Dynatrace
RequestId
X-CSRF-Token
X-Nananana
Srv
X-NWS-UUID-VERIFY
X-APP
X-App-Version
X-WR-MODIFICATION
X-TIME
X-ECache
Xkeyrz
X-Proxy-Cacherz
PICS-Label
T-Server
Ohc-File-Size
X-LiteSpeed-Cache-Control
WebServer
X-PJAX-URL
X-Render-Time
Cf-Ipcountry
X-LB-ID
Ohc-Cache-HIT
URI
X-Varnish-Beresp-TTL
Group
X-Micro-Cache
X-BE
X-GDPR
X-CACHE-KEY
X-Cache-Tag
Xkeynj
Is-Session-Tracking
X-SRV
X-PAGE-TYPE
MIME-Version
X-Fastly-Country-Code
X-Unique-Id
Get-Access-Time
HTTPS
X-Requestid
X-Cache-Miss-From
CDN
X-Policy
X-SN
SID
X-Uri
X-Edge-IP
X-Sedo-Request-Id
Www
Backend
X-MCACHE
X-Fastly-Backend-Reqs
X-Instart-Isnd
X-Request-Url
DataCenter
Xet-Cookie
Cache-Provider
X-Apw-Access-Token
Cneonction
Lb
Pics-Label
Host-ID
X-Apw-Access-Action
X-Pjax-Url
X-Swift-Error
Requestid
X-Cache-Expires
X-Vct
X-Apw-Hits
X-Apw-Access-Object
X-NGINX-Cache
X-Dw-Trace-Id
X-Lb-Id
X-Cf-Powered-By
X-WA
X-Cdn-Request-ID
X-Var-Ttl
FNAC-ModuleRouting
X-Ecache
X-Service
Correlation-Id
X-Newrelic-App-Data
Ohc-Response-Time
X-Serial
X-Fe
X-Zalando-Child-Request-Id
X-Akamai-ERRuleID
X-Fastly-Cache-Hits
Epwk-Cache
X-Flow-Id
X-Akamai-ERPolicy
X-Bug-Bounty
X-Varnish-Action
X-Html-Edge-Cache
Lfy
Warning
X-Page-Impression-Id
X-WPE-Loopback-Upstream-Addr
X-RPS
X-RSL
X-Fpc
X-ServerName
X-RPM
X-DW
X-DB
X-DI
X-DSS
X-PF-Uncompressing