Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Request-Id
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Adblock-Key
X-Drupal-Cache
Alt-Svc
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
P3p
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Template
Status
X-Language
Timing-Allow-Origin
Content-Encoding
X-Content-Security-Policy
X-Iinfo
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-Turbo-Charged-By
X-CDN
Keep-Alive
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Cache-Group
X-Pass-Why
X-Age
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Amz-Id-2
X-Amz-Request-Id
X-Pingback
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
X-Server-Powered-By
EagleId
X-UA-Device
X-Varnish-Cache
X-Nginx-Cache-Status
Request-Context
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
Feature-Policy
X-Device
Server-Timing
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Host
Report-To
X-Ac
X-Rq
X-Server-Id
Content-Location
X-OneAgent-JS-Injection
X-Node
X-Backend-Server
X-Response-Time
X-Cnection
X-Origin-Cache
X-Cloud-Trace-Context
X-Application-Context
EagleEye-TraceId
Allow
Request-Id
X-Readtime
Surrogate-Control
X-Cdn
X-Cache-Lookup
X-Country
X-ORACLE-DMS-ECID
X-TTL
X-Url
X-DynaTrace
X-Vhost
X-Rack-Cache
Pinterest-Generated-By
X-Clacks-Overhead
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
NEL
X-Ua-Compatible
X-CST
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-ORACLE-DMS-RID
X-FTR-Request-ID
X-Country-Code
X-HW
X-Goog-Hash
X-Dispatcher
X-Instart-Request-ID
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-DataStream-Cache-Status
Edge-Control
X-Px
X-Vname
X-TtlSet
X-PC
X-VARITI-CCR
Service-Worker-Allowed
X-MS-InvokeApp
X-Mod-Pagespeed
SPRequestGuid
Verso
X-Recruiting
X-Request-ID
X-Dns-Prefetch-Control
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Cdn-Fetch
X-Exp-Id
X-Varnish-TTL
X-DataDome
X-D2id
X-Vcap-Request-Id
X-SharePointHealthScore
X-B3-TraceId
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
RTSS
X-ESI
TCN
DynaTrace
X-RateLimit-Remaining
X-Powered-By-Plesk
X-GitHub-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Navigation-Version
Display
Response
X-Middleton-Response
X-Middleton-Display
X-Sol
X-Akam-SW-Version
Content-MD5
Charset
X-Server-Name
MS-Author-Via
AR-PoweredBy
AR-CACHE
ServerID
AR-ATIME
Ar-Sid
X-Amz-Rid
X-Trace
Accept-Ch-Lifetime
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Shield-Request-Id
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Powered-CMS
X-Dw-Request-Base-Id
AR-Request-ID
Realpath
X-Cached
Nginx-Cache
X-DynaTrace-JS-Agent
X-Version
X-Forwarded-Proto
X-Upstream
X-Shard
X-Server-ID
X-Mrf-Section-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Fastly-Restarts
Mrf-Cache-Status
X-Mrf-Item-Lastmod
Public-Key-Pins
SPRequestDuration
SPIisLatency
X-Goog-Storage-Class
Accept-Ch
X-Upstream-Proxy
Pinterest-Version
X-Pinterest-Rid
X-MSEdge-Ref
X-Client-IP
Access-Control-Request-Method
Pagespeed
Paypal-Debug-Id
S
X-Amz-Meta-S3cmd-Attrs
X-DataStream-Origin-MEX-Latency
X-Debug
X-DataStream-MidMile-RTT
X-Id
X-FTR-Backend
Accept-CH
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Expires
X-Ezoic-Cdn
X-N
X-Grace
X-T
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Fastly-Request-ID
Arr-Disable-Session-Affinity
X-XRDS-Location
X-NF-Request-ID
X-Amzn-Trace-Id
Front-End-Https
X-Content-Type
X-Hits
X-Ser
X-Varnish-Age
X-Mobile-Rewrite
Arc-Version
PB-RID
PB-PID
X-B3-Sampled
Alternate-Protocol
X-Acc-Meta-Resource-Type
Fastcgi-Cache
X-Frontend
X-Vcache
X-FTR-Cache-Host
X-VCache
Server-Name
X-Logged-In
X-Content-Digest
X-Srv
X-Correlation-Id
X-Pad
X-Forwarded-For
Host
X-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-FastCGI-Cache
Nel
Powered-By-ChinaCache
X-Node-Name
X-Microsite
X-Request-Handler-Origin-Region
FilterID
X-Rid
Healthy
TP-Cache
TP-L2-Cache
X-Kinsta-Cache
X-LB-Cache
Edge-Cache-Tag
X-Debug-Info
X-IPLB-Instance
X-Type
X-Request-Received
X-User-Agent
X-Request-Processing-Time
X-GUploader-UploadID
X-AOL-HN
X-Cached-By
X-Cache-2
X-Revision
X-B3-Traceid
X-F-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-Hostname
X-Cache-Rule
X-Cache-Key
X-Amz-Apigw-Id
X-Amzn-RequestId
Powered
X-Zen-Fury
X-XRDS-LOCATION
Surrogate-Key
X-Cache-Age
Backend-Timing
X-Analytics
X-Accel-Expires
X-RateLimit-Limit
X-Page-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Content-Security-Policy-Report-Only
X-Instance
X-Varnish-Grace
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Content-Options
X-BCube-Filmed-By
Source
X-Jobs
X-Cluster
X-FB-Debug
X-App-Environment
Cache-Status
X-Request-Guid
X-Via-JSL
X-Az
X-TT
X-AppVersion
X-Akamai-Edgescape
X-Activity-Id
X-PHP-Backend
X-Content-Powered-By
X-Framework
X-Amz-Replication-Status
Cleartype
Tracecode
WPE-Backend
X-Varnish-Hostname
Server-Node
X-Forwarded-Host
Refresh
Host-Header
X-B-Cache
X-Signature
X-FW-Type
X-ATG-Version
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Hash
X-Cache-Operation
X-Time
X-NWS-LOG-UUID
X-Cache-Control
Liferay-Portal
Accept-Charset
X-Mobile
X-Drupal-Cache-Tags
Actual-Object-TTL
X-Edge-Location
DC
X-Cache-Action
Access-Control-Allow-Method
X-Cache-TTL
Fastcgi-Useragent
Cache
X-Cache-Hit
Upgrade-Insecure-Requests
X-App-Server
X-Response-Served-From
X-Mobile-URL
X-Accel-Buffering
X-Hp-Webp
X-Storage
X-TX-ID
Payment
X-Esi
X-Whom
X-UA-Device-Type
X-Content-Age
X-B
X-Handled-By
X-TT-TIMESTAMP
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Xserver
X-RequestSource
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-SS-Set-Cookie
X-Adobe-Content
X-VG-WebCache
X-Adobe-Loc
X-GeoIP
X-Cacheable-TTL
X-Git-Hash
X-Ratelimit-Reset
X-WA-Info
Eomportal-Instance
Filters
X-Geo-Country
Cache-Tv-Group
X-TA-CDN-Provider
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Viewport
Accept-CH-Lifetime
Server-Info
X-Status
X-ProcessESI
X-RemovedCookies
Cache-Tag
X-FB-TRIP-ID
Webserver
Datacenter
X-Cache-TTL-Remaining
NGB
Retry-After
X-Cache-Enabled
X-APP-VERSION
X-FW-Dynamic
X-Contextid
X-Seen-By
S-Cnection
X-Presslabs-Stats
X-Ratelimit-Limit
X-Host-Name
X-Origin-Server
X-PressLabs-Stats
X-Mode
MS-CV
From-Origin
Country
Frame-Options
X-Tumblr-Pixel-3
Meta-Geo
X-Cache-Config
X-Path-Route
X-Hyper-Cache
X-Cache-Var-Map
X-Magnolia-Registration
Load-Balancing
X-LJ-Flow-ID
X-ES-SERVER
Machine
X-AWS-Id
X-Varnish-Hits
X-RN-RSRV
X-VWS-Id
X-Daa-Tunnel
X-Cache-Var
X-Rendered-As
X-Zipkin-Id
Cache-Key
X-Cache-Host
DSUID
X-Hit
Release
We-Hiring
X-CF-Powered-By
X-Proxied
X-Backend-Name
Mail-Subject
X-Generated-By
X-Labrador-Cache-Channel
X-Human
Vix-Hermes-Req-Id
X-Routing-Service
GEO-INFO
X-Varnish-Cache-Hits
X-Varnish-Server
X-Upstream-HT
X-Loop
X-PCL
Now
X-Debug-Cache
X-RCS-CacheZone
X-Device-Type
Uber-Trace-Id
X-EIG-Tracking-Id
Mn-Server-Ip
X-Cache-Grace
X-From
X-Upstream-CT
X-Web-Node
X-TNCMS
X-OCL
X-Viewer-Country
ServedBy
X-Cluster-Node
X-Environment-Context
X-L-Path
X-MP-GENERATED-AT
X-CCM
X-BYPASS-REASON
OT-Force-Account-Verify
X-Access
X-Akamai-Request-ID
X-Alternate-Cache-Key
X-Origin-Response-Time
X-Proto
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-VG-TLSProxy
X-ShopId
X-ShardId
X-ProxyCache-Key
X-ProxyCache-Status
X-Rule
Akamai-GRN
X-Section
Ms-Operation-Id
X-RTag
X-JoinUs
Decoy-Debug-TTL
X-Generated
X-FC-Vary-Parameters
X-Upgrade-Enabled
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Proxy-Build
X-Xfnlog-Site
Decoy-Debug-Key
Decoy-Debug-Status
X-Timing-Wait
X-S
X-Endurance-Cache-Level
X-R9-Blue-Green-Version
Rt-Fastcgi-Cache
X-Hosted-By
Cache-Name
DB-Nickname
X-Region
X-Guploader-Uploadid
X-NCache
X-Via-Fastly
X-Cache-NE
X-NewRelic-App-Data
X-Drupal-Cache-Contexts
NGX
X-Redis-Cache
X-UUID
X-Platform-Server
X-Nginx-Cache
X-Load-Cache
X-Real-IP
X-MServer
X-Datadome
X-Trace-Id
X-VCT
X-Hl-Ver
ProcessTime
X-Site-Version
X-EdgeConnect-Cache-Status
X-Www-Served-By
Cteonnt-Length
X-Locale
X-Vgn-Hpd-Reason
X-Cache-Remote
X-ServerID
X-Request-Time
SRV
X-IP
X-ECACHE
X-Oracle-Dms-Rid
X-Rocket-Nginx-Bypass
X-Time-Microsecs
X-GEO
Time
X-B3-Spanid
Azure-Version
Azure-InstanceId
X-Origin
S-Rt
Version
Azure-SlotName
Azure-SiteName
X-FW-Version
Azure-RegionName
X-IPS-LoggedIn
X-Origin-Hint
Webcakes-App-Name
Webcakes-App-Version
X-Via-CDN
Property-Id
Webcakes-Region
TWC-Privacy
TWC-Device-Class
TWC-GeoIP-Country
X-Wix-Request-Id
NtCoent-Length
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
Origin
L5d-Success-Class
Served-By
X-FireWall-Port
X-Cache-Backend
X-Proxy
X-Dc
X-Distributor
X-Oneagent-Js-Injection
X-Pubstack
X-Unique-ID
Fastly-SSL
X-No-Session
Origin-Cache-Control
CACHE
Origin-Edge-Control
X-Microcachable
X-ApacheServer
X-RateLimit-Reset
X-PERF
Fastcgi-X-Cache-Version
X-CS
X-UA
Odigeo-Trace-Id
X-Cache-Category-Id
X-Format
X-Grey
IBM-Web2-Location
X-Akamai-Transformed
X-Cache-Server
Hostname
X-Akamai-Request-ID2
X-Is-Bot
Cache-Tags
X-Webkit-Csp
X-NC
Ec-Rule-Version
X-Detected-As
X-HTML-Minification-Powered-By
X-UnsetCookies
Access-Control-Request-Headers
X-Edge
X-Powered-By-Defense
X-Via-NSCOPI
Proxy-Connection
X-Compress-Hint
Backend-Name
X-Ua
X-Varnish-Cacheable
Request-EU
Meta-Geo-Continent
Cdn-Request-Time
Cdn-Host
Content-Script-Type
Content-Style-Type
Cross-Origin-Window-Policy
Cache-Prefix
Cache-Cookie-Set-Lfrom
AsisCache
BehaviorPad-Version
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Fastly-SIE
Fastly-SWR
Mobile-Detection-Method
Request-Time
Node
Proxy-Firewall
Rendered-Blocks
MD5-Digest
HA-Ipaddr
Fly-Cache
Fly-Request-Id
GEO-REGION-INFO
Ha-Gx-Prefs
Request-Country
X-CGP
X-HS-Combine-CSS
X-HS-Cache-Config
X-G
X-Transaction
X-IN-APIGATEWAY
X-SRCache-Key
X-Instart-Info
X-External-Request-Id
X-Eu-Site
X-Debug-Log
X-Trv-Group
X-Destination
X-Developer
X-Edge-Server
X-DPWN-IS-SECURE
X-Internal-Host
X-NU-AKA-ACS-Version
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Rojux
X-Region-Sid
X-Rewrite-Enabled
X-Request-UUID
X-S-Cookie
X-Processor
X-Org
X-NX-Host
X-Server-Time
X-ScT
X-PAYTM-SRV-ID
X-S-Maxage
X-Debug-Cookies
X-Twitter-Response-Tags
X-Accel-Expires-Debug
X-A-Wwc
X-Aed
X-AIR-PT
X-Application
X-App-Name
X-A-Dgt
X-A-Dcw
Viewtype
Server-ID
VivaBuild
X-A
X-A-Dam
X-A-Ccd
X-ARC
X-B-Cookie
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Arc-Country
X-D
X-VG-WebServer
X-Date
X-Worker
X-Connection-Hash
X-Cache-Bucket
Xc-Version
X-Cdn-Srv
X-CF-Lambda-Fn
X-Cluster-Name
X-CF-Lambda-Version
Rt-Proxy-Cache
ServerName
X-BACKEND-TTL
A
X-Tb
X-CDN-Forward
Mime-Version
X-ElasticPress-Search
True-Client-Country-4JS
X-TH-Server
Memcached
X-Cache-Info
On-Server
X-Cache-Id
Is-Eu
X-PHP-Host
X-Dispatch
PageSpeed
X-Clientip
X-Variation
Platform
Gh-Request-Id
X-Qloud-Router
Section-Io-Cache
RNT-Time
X-Server-IP
Server-Int
SS
RNT-Machine
Resin-Trace
X-Reqid
X-Key
X-Dispatcher-Server
X-Request-URI
X-Skip-Cache
X-Backend-State
X-Core-Mission
X-Irp-Debug
Country-Code
Countrycode
Adler-Geo
X-Level-Front-Cache
X-Generated-On
X-Hash
X-GeoIP-Country-Code
X-We-Are-Hiring
X-Geo-Header
Esi-Enabled
X-Location
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Nginx-Cache-Key
Apple-News-Services-Host
X-Epic-Correlation-Id
Apple-News-Services-Request-Url
X-Fastly-Cache
X-Response-By
X-Li-Pop
V-Age
X-Li-Fabric
X-SD-PageType
X-LI-Proto
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Secret
Web-Mar-Node
X-Auto-Login
AKAMAI
X-FPC
X-Cdn-Origin
X-ND-Cache
User-Cache-Control
X-Distil-CS
X-Device-Os
X-Crawler
X-CDN-Cache
X-Gannett-Site-Version
X-Amz-Meta-Cache-Control
X-Request-Start
X-Hnp-Log
X-BBXSRF
X-Gen-Mode
X-Cache-FS-Status
X-Block-Status
X-LI-UUID
Who
X-B3-Parentspanid
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Swa-Ws
X-SVT-ORM-VERSION
X-Wikidot-Static-Cache
Powered-By
IsBot
X-C
Pramga
CDCHOST
REQUESTUUID
X-Webstats-RespID
X-ServiceProvider
X-Servername
X-WebServer
SD-X-WS
Server-Host
LB
X-SIPLIST1
X-Wikidot-Backend
Accept-Language
UCS
X-Fetched-On
X-Nc
X-Method
X-Origin-Expires
X-Developers
X-GRACE
X-Origin-Date
X-VServer
X-CUA
X-Generation-Time
Content-Disposition
X-Azure-Ref
X-Release
X-Reboot
X-Protected-By
W
X-Azure-Ref-OriginShield
X-Served-From
PFcat
CF-IPCountry
X-Via-Edge
X-Matched-Rule
X-GeoIP-City
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Varnish-Url
GW-Server
X-Via-SSL
X-B3-SpanId
Thinkindot-CacheControl
X-OVcl
X-Fstrz
X-Thanos
X-Parent-Response-Time
X-Clara-WADP
Fastly-Soc-X-Request-Id
X-WADP-Cache
X-Thinkindot-L3
Heartbleed
X-Cms-Context
X-Bip
X-Cdn-Forward
X-OVcl-Cache
Pragrma
X-Owner
X-Varnish-Ttl
X-VC-Cache
X-CLOUD-TRACE-CONTEXT
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
L
X-Planisys-CDN-Cache
X-Proxy-Cache-Status
X-Ratelimit-Remaining
X-LAGOON
X-Proxy-Upstream
Memory
X-Origin-CC
X-Origin-TTL
X-DC
X-FE
X-TrackingId
X-Core-Value
Kp-EeAlive
X-IN-WAF
X-Phone
N-Cache
X-Amzn-Remapped-Content-Length
X-Varnish-Beresp-Ttl
Selected-Fe
X-Be
X-Birta-Cache-Post
X-Page-Type
X-Birta-Served
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-SERVER-NAME
X-Varnish-IP
User-Agent
Magicmarker
X-Pf-Uncompressing
Selected-FE
X-Info
X-URL
HitType
X-Ttl
X-Geo
X-App-Version
X-Dynatrace-Js-Agent
Pagetype
X-Varnish-Beresp-Grace
X-Backend-TTL
X-Varnish-Beresp-Status
Cdn
X-Zone
X-Flog
X-Hello
X-User
X-Newrelic-Synthetics
X-ABtesting
X-Generated-In
X-Backend-Host
X-Source
X-CACHE-KEY
X-Servedbyhost
X-TT-LOGID
X-Backend-Url
X-Litespeed-Cache
X-MSEdge-Flight
Geoip-City
GeoIp-Country-Code
X-GoCache-CacheStatus
X-Debug-Cache-Store
Geoip-Latitude
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Tt-Trace-Tag
X-MSEdge-Features
X-Web-Server
X-Agile-Age
X-Agile
X-Cache-Debug
X-Agile-Id
X-Up
X-Refresh
CF-Cached-On
X-Soup
X-Check-Cacheable
X-ZONE
X-Mid
X-MID
X-VCL-Version
SN
X-HS-Status
X-Real-Ip
X-Tb-Optimization-Total-Bytes-Saved
X-Aicache-OS
X-Ruxit-Js-Agent
Amp-Access-Control-Allow-Source-Origin
FSS-Cache
X-Vcl-Version
X-Oss-Hash-Crc64ecma
GeoIP-Country-Code
FSS-Proxy
X-UPSTREAM-Address
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
X-Cache-Ttl
X-Say-TTL
X-SayCDN-TTL
GeoIP-City
X-Say-Cacheable
X-Old-Content-Length
X-Amzn-Remapped-Connection
X-NWS-UUID-VERIFY
X-Amzn-Remapped-Date
X-ServedByHost
X-APP
GeoIP-Latitude
Ohc-Cache-HIT
Ohc-File-Size
X-Varnish-Authentication
X-Contensis-Viewer-Groups
Server-Cache-Control
Server-Surrogate-Control
X-Cache-ASPX
X-BC
HostName
WZWS-RAY
Group
X-EC-Lua
X-COUNTRY
HTTPS
Cache-Hits
X-Bc
RequestId
X-Via-Ucdn
X-CSRF-Token
Srv
Backend
X-Node-Id
Inserted-Into-Cache-At
Fastly-Backend-Name
Www
X-Akamai-SSL-Client-Sid
X-SN
X-Varnish-Beresp-TTL
X-Nananana
X-Instart-Isnd
X-Proxy-Cacherz
X-ECache
URI
X-Logtrace-Id
X-IN-APIGATEWAYSSL
X-CSRF-TOKEN
Ajk
Xkeyrz
WebServer
X-Dynatrace
XServer
Lb
X-WR-MODIFICATION
X-Cache-Expires
X-Request-Url
Host-ID
Requestid
Cf-Ipcountry
X-Cache-Tag
X-LiteSpeed-Cache-Control
X-RateLimit-Limit-Second
Get-Access-Time
X-Wa
X-Fastly-Country-Code
X-NGENIX-Cache
X-Cache-Time
X-FORWARDED-FOR
Is-Session-Tracking
Xkeynj
X-Unique-Id
X-RateLimit-Remaining-Second
X-PAGE-TYPE
X-TIME
X-MCACHE
X-Edge-IP
X-Requestid
Epwk-Cache
X-Varnish-Action
X-BE
X-Cache-Miss-From
X-PF-Uncompressing
X-Fastly-Backend-Reqs
X-Sedo-Request-Id
X-Vct
Dynatrace
X-Apw-Access-Token
X-Apw-Access-Object
T-Server
X-Apw-Hits
X-Cf-Powered-By
Fastcgi-X-Cache
X-Apw-Access-Action
Cneonction
Xet-Cookie
X-SRV
DataCenter
PICS-Label
X-Pjax-Url
X-Ecache
X-Render-Time
X-PJAX-URL
X-LB-ID
X-Swift-Error
Pics-Label
X-GDPR
X-Micro-Cache
CDN
X-Svr
X-AssetVersion
Correlation-Id
X-Dw-Trace-Id
X-NGINX-Cache
X-Sf
X-WA
X-Var-Ttl
X-Lb-Id
FNAC-ModuleRouting
X-ServerName
RequestUuid
X-Akamai-ERPolicy
X-Serial
X-Akamai-ERRuleID
X-Fastly-Cache-Hits
X-Page-Impression-Id
X-Flow-Id
X-Bug-Bounty
X-Fpc
X-DI
X-DSS
X-DB
Ohc-Response-Time
X-WPE-Loopback-Upstream-Addr
Cache-Provider
X-DW
X-RPM
X-Html-Edge-Cache
X-LiteSpeed-Tag
X-Zalando-Child-Request-Id
Lfy
X-RPS
X-RSL
Warning