Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
CF-Cache-Status
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
Alt-Svc
X-Adblock-Key
X-Drupal-Cache
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
P3p
X-Template
X-Language
Status
Timing-Allow-Origin
X-Iinfo
Content-Encoding
X-Content-Security-Policy
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Pingback
X-Amz-Request-Id
X-Amz-Id-2
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
EagleId
Grace
X-Server-Powered-By
X-UA-Device
X-Varnish-Cache
Request-Context
X-Nginx-Cache-Status
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Server-Id
X-WebKit-CSP
Server-Timing
Feature-Policy
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Host
Report-To
X-Rq
X-Ac
X-Node
Content-Location
X-OneAgent-JS-Injection
X-Request-ID
X-Cnection
X-Response-Time
X-Backend-Server
X-Cloud-Trace-Context
X-Origin-Cache
X-Application-Context
X-Readtime
Request-Id
Allow
Surrogate-Control
EagleEye-TraceId
X-ORACLE-DMS-ECID
X-Vhost
X-Country
X-DynaTrace
X-TTL
X-Cdn
X-Cache-Lookup
X-Rack-Cache
Pinterest-Generated-By
X-Origin-Upstream-Status
X-Url
X-Clacks-Overhead
NEL
X-Ua-Compatible
X-FTR-Request-ID
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-Ruxit-JS-Agent
X-Dispatcher
X-Dns-Prefetch-Control
X-CST
X-HW
X-ORACLE-DMS-RID
X-Instart-Request-ID
X-Goog-Hash
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
X-DataStream-Cache-Status
X-TtlSet
X-DataDome
X-Vname
X-PC
Edge-Control
X-Px
X-VARITI-CCR
Service-Worker-Allowed
Verso
X-Mod-Pagespeed
X-MS-InvokeApp
X-Recruiting
RTSS
X-Exp-Variant
X-Use-Magma
X-Exp-Id
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Cdn-Fetch
X-Varnish-TTL
X-D2id
SPRequestGuid
X-Vcap-Request-Id
X-Abt-Application-Version
X-Amz-Server-Side-Encryption
TCN
X-GitHub-Request-Id
X-SharePointHealthScore
X-Navigation-Version
Display
X-Sol
X-Middleton-Response
X-Middleton-Display
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Response
X-Akam-SW-Version
X-Powered-By-Plesk
MS-Author-Via
X-RateLimit-Remaining
X-ESI
Charset
X-Forwarded-Proto
Realpath
DynaTrace
X-Shield-Request-Id
X-Powered-CMS
X-Amz-Rid
X-Upstream
ServerID
X-B3-TraceId
Public-Key-Pins
X-Trace
X-Version
X-TEC-API-VERSION
X-TEC-API-ROOT
Fastly-Restarts
X-TEC-API-ORIGIN
Nginx-Cache
AR-ATIME
X-Cached
AR-CACHE
Ar-Sid
AR-PoweredBy
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
Content-MD5
X-Shard
X-Server-Name
X-Dw-Request-Base-Id
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
Accept-CH
Pagespeed
AR-Request-ID
X-Grace
Access-Control-Request-Method
Paypal-Debug-Id
X-MSEdge-Ref
Accept-Ch-Lifetime
SPIisLatency
X-Client-IP
SPRequestDuration
X-Goog-Storage-Class
X-DynaTrace-JS-Agent
S
X-Debug
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Expires
X-FTR-Realm
X-Id
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
Accept-Ch
X-Ezoic-Cdn
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-FastCGI-Cache
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Fastly-Request-ID
X-B3-Traceid
X-N
X-T
X-Amzn-Trace-Id
X-NF-Request-ID
X-Vcache
Arr-Disable-Session-Affinity
X-DIS-Request-ID
X-Pinterest-Rid
MicrosoftSharePointTeamServices
Pinterest-Version
X-Upstream-Proxy
X-Content-Type
X-XRDS-Location
X-Hits
X-B3-Sampled
X-FTR-Cache-Host
X-Acc-Meta-Resource-Type
X-Frontend
PB-PID
X-Mobile-Rewrite
Arc-Version
PB-RID
X-Ser
X-Varnish-Age
X-Logged-In
Fastcgi-Cache
X-Content-Digest
Server-Name
X-Correlation-Id
Alternate-Protocol
X-VCache
X-Srv
X-Cache-Key
X-Node-Name
Nel
AMP-Access-Control-Allow-Source-Origin
X-Request-Handler-Origin-Region
X-Microsite
X-Pad
FilterID
X-User-Agent
X-Rid
X-Forwarded-For
TP-Cache
X-Type
TP-L2-Cache
Powered
Healthy
X-LB-Cache
X-F-Cache
Host
X-IPLB-Instance
X-Kinsta-Cache
X-Request-Processing-Time
X-Request-Received
X-Zen-Fury
X-Amz-Apigw-Id
X-Cache-2
X-Amzn-RequestId
X-Revision
Edge-Cache-Tag
Powered-By-ChinaCache
X-Debug-Info
Accept-CH-Lifetime
X-AOL-HN
X-GUploader-UploadID
X-Via-JSL
X-Cached-By
X-Kong-Upstream-Latency
X-Analytics
X-Kong-Proxy-Latency
Backend-Timing
X-Cache-Age
X-HS-Content-Id
X-Az
X-Activity-Id
X-HS-Hub-Id
X-AppVersion
X-Hostname
X-XRDS-LOCATION
X-Accel-Expires
X-Cache-Rule
X-Esi
Surrogate-Key
X-Varnish-Backend
VIX-Pulpo-Node
X-Content-Security-Policy-Report-Only
VIX-Pulpo-Upstream-Status
X-Content-Options
X-Instance
X-PHP-Backend
X-BCube-Filmed-By
X-RateLimit-Limit
X-Page-Id
X-Tumblr-Pixel
Server-Node
X-Varnish-Grace
X-Tumblr-User
X-Amz-Replication-Status
X-Tumblr-Pixel-0
X-Akamai-Edgescape
X-App-Environment
X-Jobs
X-Content-Powered-By
X-B-Cache
X-Signature
X-Request-Guid
X-Forwarded-Host
Cleartype
Refresh
Source
X-TT
X-Cluster
X-FB-Debug
Cache-Status
X-Framework
Liferay-Portal
X-FW-Type
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Server
DC
X-Fastcgi-Cache
Tracecode
X-ATG-Version
Accept-Charset
X-Varnish-Hostname
Access-Control-Allow-Method
Fastcgi-Useragent
X-Time
Host-Header
X-Mobile
X-APP-VERSION
X-Cache-Action
X-Cache-Operation
WPE-Backend
X-Drupal-Cache-Tags
X-Whom
X-Cache-Control
X-Edge-Location
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-B
X-Hp-Webp
Payment
X-Mobile-URL
X-Accel-Buffering
X-WA-Info
X-Response-Served-From
X-App-Server
NGB
Actual-Object-TTL
X-Cache-Hit
X-Storage
X-Oracle-Dms-Rid
X-WebKit-CSP-Report-Only
X-Git-Hash
X-Presslabs-Stats
X-TX-ID
X-Content-Age
Filters
Cache-Tag
X-Handled-By
X-TT-TIMESTAMP
Cache-Tv-Group
X-RequestSource
X-Cacheable-TTL
Retry-After
Viewport
Upgrade-Insecure-Requests
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-Pixel-2
Eomportal-Instance
X-Tumblr-Pixel-1
X-UA-Device-Type
X-GeoIP
X-NWS-LOG-UUID
X-Status
X-Adobe-Loc
X-RemovedCookies
X-ProcessESI
X-Adobe-Content
X-SS-Set-Cookie
X-Cache-TTL
MS-CV
X-Geo-Country
X-FW-Dynamic
X-TA-CDN-Provider
X-VG-WebCache
Webserver
X-Seen-By
X-Cache-TTL-Remaining
Xserver
X-Server-ID
X-Host-Name
X-FB-TRIP-ID
Ms-Operation-Id
X-RTag
Datacenter
X-B3-Spanid
X-Cache-Enabled
Frame-Options
Cache
Server-Info
X-Ratelimit-Limit
X-Hyper-Cache
From-Origin
X-Contextid
X-Origin-Server
X-Generated-By
X-Mode
Country
X-CF-Powered-By
S-Cnection
SRV
GEO-INFO
X-Path-Route
X-ES-SERVER
X-RN-RSRV
X-Cache-Var-Map
X-Cache-Var
X-Ratelimit-Reset
Load-Balancing
Meta-Geo
X-Cache-Config
X-Tumblr-Pixel-3
Machine
X-Cache-Grace
X-MP-GENERATED-AT
X-Upstream-HT
X-Zipkin-Id
Cache-Key
X-Proxied
X-Upstream-CT
X-Drupal-Cache-Contexts
X-Routing-Service
X-Section
X-Access
Vix-Hermes-Req-Id
ServedBy
X-Backend-Name
X-From
Rt-Fastcgi-Cache
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-Hit
X-Human
X-Varnish-Cache-Hits
X-Varnish-Server
X-TNCMS
X-R9-Blue-Green-Version
X-Labrador-Cache-Channel
X-Loop
CACHE
X-Web-Node
X-PCL
X-OCL
Akamai-GRN
X-Proxy-Build
X-Region
X-Timing-Wait
X-Rule
Cache-Name
X-Magnolia-Registration
X-Cache-Host
X-AWS-Id
X-Akamai-Request-ID
X-Cluster-Node
X-EIG-Tracking-Id
X-LJ-Flow-ID
Now
X-Trace-Id
X-Origin-Response-Time
X-VWS-Id
X-Upgrade-Enabled
Mn-Server-Ip
X-VG-TLSProxy
X-Viewer-Country
X-Locale
DSUID
X-Www-Served-By
X-Site-Version
X-Device-Type
Release
X-L-Path
X-Endurance-Cache-Level
X-Environment-Context
X-FC-Vary-Parameters
X-Generated
X-Via-Fastly
X-NCache
X-Proto
X-Debug-Cache
X-JoinUs
X-Sorting-Hat-ShopId
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
Mail-Subject
X-Rendered-As
X-NewRelic-App-Data
X-ShardId
X-ShopId
X-Shopify-Stage
DB-Nickname
X-Alternate-Cache-Key
We-Hiring
X-Sorting-Hat-PodId
X-Guploader-Uploadid
X-RateLimit-Reset
X-CCM
OT-Force-Account-Verify
ProcessTime
Version
X-Dc
X-Xfnlog-Site
X-S
X-IP
X-Time-Microsecs
X-Request-Time
Uber-Trace-Id
X-Load-Cache
X-RCS-CacheZone
X-VCT
X-Varnish-Hits
Time
NtCoent-Length
X-Akamai-Request-ID2
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-Region
X-FW-Version
Cteonnt-Length
Azure-SlotName
X-Wix-Request-Id
X-Origin-Hint
TWC-GeoIP-Country
Webcakes-App-Version
Azure-RegionName
Azure-SiteName
TWC-Device-Class
Azure-InstanceId
Azure-Version
S-Rt
Property-Id
TWC-Connection-Speed
X-Origin
X-PressLabs-Stats
X-No-Session
NGX
X-Redis-Cache
X-EdgeConnect-Cache-Status
X-UUID
X-ProxyCache-Status
X-UA
X-Nginx-Cache
X-Via-CDN
X-BYPASS-REASON
X-ProxyCache-Key
X-CDN-Forward
X-GEO
X-Proxy
X-Platform-Server
X-FireWall-Port
X-ECACHE
X-Vgn-Hpd-Reason
X-MServer
X-Cache-NE
X-Hl-Ver
X-PERF
X-ApacheServer
X-Rocket-Nginx-Bypass
X-IPS-LoggedIn
X-HTML-Minification-Powered-By
X-CS
Odigeo-Trace-Id
X-Format
X-Daa-Tunnel
Origin
X-Cache-Server
X-Akamai-Transformed
Accept-Language
Ec-Rule-Version
Cache-Tags
Access-Control-Request-Headers
X-ServerID
X-Oneagent-Js-Injection
X-UnsetCookies
LB
X-Distributor
X-Cache-Remote
X-Tb
X-Dynatrace-Js-Agent
Fastly-SSL
X-Amzn-Remapped-Content-Length
X-Real-IP
Hostname
L5d-Success-Class
X-Webkit-Csp
Selected-Fe
Proxy-Connection
X-SERVER-NAME
X-Pubstack
X-B3-Parentspanid
X-Microcachable
X-Unique-ID
X-NC
Served-By
X-Compress-Hint
AKAMAI
Fly-Cache
Fastcgi-X-Cache-Version
X-Detected-As
Fastly-SWR
Fastly-SIE
A
X-DPWN-IS-SECURE
X-Destination
Fly-Request-Id
GEO-REGION-INFO
X-Developer
X-Cluster-Name
Cache-Cookie-Set-Idcheck
X-CF-Lambda-Fn
Cache-Cookie-Set-From
Meta-Geo-Continent
X-Cdn-Srv
MD5-Digest
BehaviorPad-Version
X-Cache-Bucket
X-Generated-On
X-G
Mobile-Detection-Method
AsisCache
X-Instart-Info
Arc-Country
X-External-Request-Id
X-Date
X-CF-Lambda-Version
X-IN-APIGATEWAY
X-Geo-Header
X-Edge-Server
X-BACKEND-TTL
X-A-Wwc
X-Rebelmouse-Surrogate-Control
X-A-Dgt
X-Region-Sid
X-A-Dam
X-A-Dcw
Server-ID
X-Accel-Expires-Debug
X-Internal-Host
X-AIR-PT
Rt-Proxy-Cache
X-Aed
X-Rebelmouse-Cache-Control
Cdn-Request-Time
X-Server-Time
Xc-Version
Content-Style-Type
X-Rojux
X-S-Cookie
X-S-Maxage
X-Worker
X-ScT
X-Rewrite-Enabled
X-Request-UUID
X-A
X-A-Ccd
Content-Script-Type
Viewtype
VivaBuild
X-SVT-ORM-RULES
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Varnish-Url
X-SVT-ORM-VERSION
Rendered-Blocks
X-Varnish-Cacheable
Cache-Prefix
Proxy-Firewall
X-ARC
X-Vtex-Remote-Cache
X-NU-AKA-ACS-Version
X-Connection-Hash
X-B-Cookie
X-D
X-Level-Front-Cache
X-Is-Bot
Request-Time
X-App-Name
REQUESTUUID
Node
Cdn-Host
Cross-Origin-Window-Policy
X-Transaction
X-Twitter-Response-Tags
X-Org
X-Trv-Group
Cache-Cookie-Set-Lfrom
X-PAYTM-SRV-ID
X-Application
X-ElasticPress-Search
X-URL
ServerName
IBM-Web2-Location
Origin-Cache-Control
Origin-Edge-Control
Countrycode
Esi-Enabled
X-Backend-State
Request-EU
Request-Country
X-Core-Mission
Resin-Trace
Section-Io-Cache
W
UCS
Server-Int
On-Server
X-BBXSRF
Ha-Gx-Prefs
X-CGP
X-Clientip
HA-Ipaddr
X-Cdn-Origin
Memcached
X-Cache-Info
Gh-Request-Id
X-We-Are-Hiring
X-Method
X-Nginx-Cache-Key
Content-Disposition
X-HS-Combine-CSS
X-C
X-HS-Cache-Config
X-NX-Host
X-TrackingId
X-ServiceProvider
X-Server-IP
X-Skip-Cache
X-Sn-Servicetimems
X-Qloud-Router
X-Fastly-Cache
X-Location
X-Debug-Cookies
X-Debug-Log
X-Developers
X-Eu-Site
Apple-News-Services-Host
Backend-Name
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Distil-CS
Apple-News-Services-Handled
X-Grey
X-Cache-Category-Id
X-FPC
X-Wikidot-Backend
X-SIPLIST1
X-Reboot
X-Gen-Mode
X-Proxy-Upstream
X-Generation-Time
X-Gannett-Site-Version
X-Release
Wxu-Next-Commit
X-Crawler
X-Request-URI
Wxu-Next-Hostname
Wxu-Next-Region
Kp-EeAlive
X-Reqid
X-Wikidot-Static-Cache
X-Servername
X-Proxy-Cache-Status
X-Key
X-Device-Os
X-Webstats-RespID
X-Auto-Login
X-Irp-Debug
X-Secret
X-Hnp-Log
X-Bip
X-Dispatch
X-Epic-Correlation-Id
X-Hash
X-TH-Server
X-PHP-Host
X-Swa-Ws
X-Thanos
X-GeoIP-Country-Code
Who
X-Cache-Id
X-Variation
X-Block-Status
RNT-Machine
L
IsBot
N-Cache
Platform
Pramga
Powered-By
Is-Eu
Heartbleed
Web-Mar-Node
X-Cache-Backend
Adler-Geo
CDCHOST
GW-Server
Country-Code
RNT-Time
Fastly-Soc-X-Request-Id
Server-Host
User-Cache-Control
SS
True-Client-Country-4JS
Locale
X-Urbn-Context-Path
X-SERVER
X-Urbn-Site-Id
X-Nc
X-Edge
X-Fetched-On
X-VServer
X-Cms-Context
X-Clara-WADP
X-WADP-Cache
X-CUA
X-Owner
X-Request-Start
X-Thinkindot-L3
V-Age
X-Dispatcher-Server
X-Response-By
Thinkindot-Control
X-SD-PageType
X-GeoIP-City
X-VC-Cache
X-Pf-Uncompressing
X-WebServer
X-Azure-Ref
X-Azure-Ref-OriginShield
Thinkindot-CacheControl-Type
PFcat
X-Matched-Rule
X-LI-UUID
X-Li-Fabric
X-Amz-Meta-Cache-Control
X-Li-Pop
X-LI-Proto
X-Origin-Date
SD-X-WS
X-Origin-Expires
Thinkindot-CacheControl
X-Cache-FS-Status
X-CDN-Cache
CF-IPCountry
X-FE
X-OVcl-Cache
X-OVcl
X-Varnish-Ttl
X-Processor
X-Flog
X-Served-From
X-ABtesting
X-Via-NSCOPI
Magicmarker
X-CLOUD-TRACE-CONTEXT
X-Hello
User-Agent
X-Powered-By-Defense
X-Via-Edge
X-Via-SSL
X-LAGOON
X-Parent-Response-Time
PageSpeed
Pagetype
X-Ratelimit-Remaining
X-Be
Memory
X-Generated-In
X-User
X-Backend-Host
X-Backend-Url
X-GoCache-CacheStatus
X-MSEdge-Flight
X-MSEdge-Features
Mime-Version
X-Varnish-Beresp-Ttl
X-Up
X-Protected-By
X-Tt-Trace-Tag
X-ND-Cache
X-Newrelic-Synthetics
X-Ua
X-Debug-Cache-Expiry
X-Soup
X-Page-Type
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Planisys-CDN-TTL
X-COUNTRY
X-Geo
Pragrma
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Fstrz
X-Ttl
X-ZONE
X-Backend-TTL
X-Origin-TTL
X-Origin-CC
Cache-Hits
X-Cache-Ttl
GeoIp-Country-Code
Geoip-City
Geoip-Latitude
X-Check-Cacheable
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Say-TTL
X-Say-Cacheable
X-SayCDN-TTL
X-B3-SpanId
Dynatrace
X-Akamai-SSL-Client-Sid
X-Zone
X-Old-Content-Length
X-Phone
X-Core-Value
X-IN-WAF
XServer
X-CSRF-TOKEN
X-Litespeed-Cache
X-Varnish-Beresp-Status
X-Cache-Time
X-TT-LOGID
X-DC
X-Servedbyhost
X-Varnish-Beresp-Grace
X-Cdn-Forward
WZWS-RAY
X-HS-Status
Fastly-Backend-Name
Cdn
X-IN-APIGATEWAYSSL
Inserted-Into-Cache-At
X-VCL-Version
SN
X-BC
X-Node-Id
X-Aicache-OS
Ajk
X-Datadome
X-Logtrace-Id
X-Ruxit-Js-Agent
Amp-Access-Control-Allow-Source-Origin
X-Mid
X-Birta-Cache-Post
X-Birta-Served
X-MID
FSS-Proxy
FSS-Cache
X-Vcl-Version
X-FORWARDED-FOR
X-EC-Lua
X-Amzn-Remapped-Connection
X-APP
X-Tb-Optimization-Total-Bytes-Saved
X-ServedByHost
X-Amzn-Remapped-Date
X-UPSTREAM-Address
X-Real-Ip
Selected-FE
X-Wa
X-RateLimit-Remaining-Second
X-Tec-Api-Root
X-Tec-Api-Origin
X-Varnish-IP
X-Info
X-RateLimit-Limit-Second
X-Tec-Api-Version
HostName
Server-Cache-Control
Server-Surrogate-Control
X-Proxy-Cacherz
X-Cache-ASPX
X-Contensis-Viewer-Groups
CF-Cached-On
X-Varnish-Authentication
Xkeyrz
HitType
X-Source
X-Refresh
X-PJAX-URL
MIME-Version
X-Cache-Debug
T-Server
PICS-Label
X-Agile-Id
RequestId
X-Agile-Age
X-Agile
X-CSRF-Token
Srv
X-Bc
GeoIP-Country-Code
Ohc-File-Size
X-Render-Time
X-GDPR
X-App-Version
X-Nananana
X-LiteSpeed-Cache-Control
GeoIP-City
X-Varnish-Beresp-TTL
X-TIME
X-WR-MODIFICATION
Ohc-Cache-HIT
X-LB-ID
X-ECache
GeoIP-Latitude
X-Via-Ucdn
X-NWS-UUID-VERIFY
WebServer
X-Web-Server
URI
SID
DataCenter
X-Policy
Cf-Ipcountry
X-Fastly-Country-Code
X-Uri
Xkeynj
Is-Session-Tracking
Get-Access-Time
X-BE
X-Micro-Cache
X-Cache-Tag
X-SRV
X-CACHE-KEY
X-Unique-Id
X-PAGE-TYPE
X-Cache-Miss-From
X-Sedo-Request-Id
X-Requestid
X-Fastly-Backend-Reqs
CDN
X-Request-Url
Group
X-NGINX-Cache
X-Service
Cache-Provider
X-MCACHE
X-GRACE
X-Lb-Id
X-Var-Ttl
HTTPS
Xet-Cookie
Lb
Ohc-Response-Time
X-NGENIX-Cache
X-Pjax-Url
Backend
X-Swift-Error
X-SN
X-Edge-IP
X-Has-Esi
X-Is-Gdpr
X-Vct
X-JWT-State
Pics-Label
X-Apw-Access-Object
X-Apw-Access-Action
Www
Cneonction
X-Apw-Access-Token
X-Apw-Hits
X-Dw-Trace-Id
FNAC-ModuleRouting
X-Cf-Powered-By
X-WA
X-Cdn-Request-ID
X-Instart-Isnd
Correlation-Id
X-Ecache
X-Cache-Expires
Warning
Host-ID
X-Newrelic-App-Data
X-Flow-Id
X-Akamai-ERRuleID
X-Litespeed-Cache-Control
X-Zalando-Child-Request-Id
X-RPS
X-RSL
X-Fe
X-Fastly-Cache-Hits
Requestid
X-Fpc
X-DB
Lfy
X-ServerName
X-DI
X-DSS
X-PF-Uncompressing
X-Bug-Bounty
X-Page-Impression-Id
X-Html-Edge-Cache
X-DW
X-RPM
X-Akamai-ERPolicy
X-Serial