Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
Alt-Svc
X-Adblock-Key
X-Drupal-Cache
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
P3p
X-Template
X-Language
Status
Timing-Allow-Origin
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Pingback
X-Amz-Request-Id
X-Amz-Id-2
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
EagleId
X-Server-Powered-By
X-UA-Device
X-Varnish-Cache
Request-Context
X-Nginx-Cache-Status
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Server-Id
Feature-Policy
Server-Timing
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Host
X-Rq
Report-To
X-Ac
X-Node
Content-Location
X-OneAgent-JS-Injection
X-Backend-Server
X-Cnection
X-Response-Time
X-Request-ID
X-Cloud-Trace-Context
X-Origin-Cache
X-Application-Context
X-Readtime
Allow
Request-Id
EagleEye-TraceId
Surrogate-Control
X-Country
X-ORACLE-DMS-ECID
X-Cache-Lookup
X-Vhost
X-TTL
X-DynaTrace
X-Url
X-Cdn
Pinterest-Generated-By
X-Rack-Cache
X-Clacks-Overhead
X-Origin-Upstream-Status
X-Ua-Compatible
NEL
X-Ruxit-JS-Agent
X-FTR-Request-ID
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-CST
X-Dns-Prefetch-Control
X-HW
X-Dispatcher
X-Goog-Hash
X-Instart-Request-ID
X-ORACLE-DMS-RID
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-DataStream-Cache-Status
Edge-Control
X-PC
X-TtlSet
X-Vname
X-DataDome
X-Px
X-VARITI-CCR
Service-Worker-Allowed
Verso
X-Mod-Pagespeed
X-MS-InvokeApp
X-Recruiting
X-Varnish-TTL
X-D2id
SPRequestGuid
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
RTSS
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
DynaTrace
TCN
X-Navigation-Version
X-SharePointHealthScore
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-GitHub-Request-Id
X-Middleton-Display
Display
Response
X-RateLimit-Remaining
X-Middleton-Response
X-Sol
X-Powered-By-Plesk
X-Akam-SW-Version
MS-Author-Via
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Accept-Ch-Lifetime
Charset
X-Shield-Request-Id
Accept-Ch
Content-MD5
ServerID
X-Amz-Rid
AR-ATIME
Ar-Sid
AR-PoweredBy
AR-CACHE
X-Forwarded-Proto
X-B3-TraceId
X-Trace
Realpath
X-Powered-CMS
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
Nginx-Cache
X-DynaTrace-JS-Agent
X-Version
X-Dw-Request-Base-Id
X-Upstream
AR-Request-ID
X-Cached
Fastly-Restarts
Public-Key-Pins
X-Shard
X-ESI
Pagespeed
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Server-Name
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Access-Control-Request-Method
Paypal-Debug-Id
X-MSEdge-Ref
X-Vcache
X-Goog-Storage-Class
X-Grace
SPRequestDuration
SPIisLatency
X-Client-IP
S
X-Debug
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Expires
X-DataStream-MidMile-RTT
X-Country-Code-Real
X-FTR-DC
X-DataStream-Origin-MEX-Latency
Pinterest-Version
X-Pinterest-Rid
X-Amz-Meta-S3cmd-Attrs
X-Ezoic-Cdn
X-Upstream-Proxy
X-FastCGI-Cache
X-N
X-Id
X-Fastly-Request-ID
X-DIS-Request-ID
X-T
X-Amzn-Trace-Id
Arr-Disable-Session-Affinity
Front-End-Https
X-NF-Request-ID
X-Content-Type
X-XRDS-Location
MicrosoftSharePointTeamServices
X-Hits
X-B3-Traceid
Accept-CH
X-B3-Sampled
X-FTR-Cache-Host
X-Varnish-Age
X-Ser
PB-RID
X-Mobile-Rewrite
Fastcgi-Cache
Arc-Version
PB-PID
X-Frontend
X-Acc-Meta-Resource-Type
Alternate-Protocol
X-Content-Digest
X-Logged-In
Server-Name
X-Correlation-Id
X-Srv
X-Pad
X-Cache-Key
X-Forwarded-For
X-Node-Name
X-Esi
Nel
AMP-Access-Control-Allow-Source-Origin
Host
X-Request-Handler-Origin-Region
X-Microsite
FilterID
TP-Cache
TP-L2-Cache
Powered-By-ChinaCache
X-Type
X-Rid
X-Kinsta-Cache
Healthy
X-LB-Cache
X-User-Agent
X-IPLB-Instance
X-Request-Processing-Time
X-Request-Received
Edge-Cache-Tag
X-Debug-Info
X-AOL-HN
X-F-Cache
X-Cached-By
X-Cache-2
X-GUploader-UploadID
X-Zen-Fury
Powered
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Revision
X-VCache
X-Hostname
X-HS-Content-Id
X-HS-Hub-Id
X-Cache-Rule
Backend-Timing
X-Cache-Age
X-Analytics
X-XRDS-LOCATION
X-Accel-Expires
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Via-JSL
Surrogate-Key
X-Az
X-AppVersion
X-Activity-Id
VIX-Pulpo-Node
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
X-BCube-Filmed-By
X-Instance
X-Page-Id
X-RateLimit-Limit
X-Cluster
X-Varnish-Grace
X-Amz-Replication-Status
X-FB-Debug
X-Content-Options
X-Akamai-Edgescape
X-PHP-Backend
X-Request-Guid
X-Tumblr-User
X-Jobs
X-Content-Powered-By
X-Tumblr-Pixel
X-Tumblr-Pixel-0
Source
X-App-Environment
Cache-Status
Server-Node
Cleartype
X-Framework
X-TT
Refresh
X-Forwarded-Host
X-B-Cache
X-Signature
X-Fastcgi-Cache
X-FW-Static
X-Server-ID
X-FW-Type
X-FW-Server
X-Varnish-Hostname
X-FW-Serve
X-FW-Hash
Liferay-Portal
Tracecode
DC
X-ATG-Version
Host-Header
WPE-Backend
Accept-Charset
X-Cache-Operation
X-Mobile
X-Cache-Control
Access-Control-Allow-Method
X-Edge-Location
Fastcgi-Useragent
X-Cache-Action
X-Drupal-Cache-Tags
X-APP-VERSION
Actual-Object-TTL
X-Time
X-Cache-Hit
Accept-CH-Lifetime
X-Mobile-URL
X-Response-Served-From
X-Hp-Webp
Payment
X-Accel-Buffering
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-B
X-Storage
X-TX-ID
X-NWS-LOG-UUID
Upgrade-Insecure-Requests
X-Git-Hash
X-App-Server
X-Whom
X-WebKit-CSP-Report-Only
X-Content-Age
X-Oracle-Dms-Rid
X-WA-Info
Cache-Tv-Group
X-Yottaa-Metrics
X-TT-TIMESTAMP
X-Yottaa-Optimizations
X-SS-Set-Cookie
Filters
Cache
X-Cacheable-TTL
X-UA-Device-Type
Eomportal-Instance
X-Adobe-Loc
X-Status
X-GeoIP
X-Handled-By
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Adobe-Content
X-RemovedCookies
X-RequestSource
NGB
X-ProcessESI
Xserver
Viewport
X-Geo-Country
X-VG-WebCache
Cache-Tag
Retry-After
Webserver
Datacenter
X-Ratelimit-Reset
X-Cache-TTL-Remaining
X-FW-Dynamic
Server-Info
X-Cache-TTL
X-Seen-By
X-FB-TRIP-ID
X-Cache-Enabled
X-TA-CDN-Provider
MS-CV
X-Host-Name
X-Contextid
X-Ratelimit-Limit
X-B3-Spanid
X-Presslabs-Stats
X-PressLabs-Stats
S-Cnection
Frame-Options
X-Origin-Server
X-Generated-By
From-Origin
X-Hyper-Cache
Country
Ms-Operation-Id
X-RTag
X-Mode
X-ES-SERVER
Load-Balancing
X-Tumblr-Pixel-3
X-RN-RSRV
Machine
Meta-Geo
X-Cache-Var-Map
X-Cache-Config
X-Cache-Var
X-Path-Route
X-CF-Powered-By
X-Cache-Grace
X-Hit
X-Access
Vix-Hermes-Req-Id
Cache-Key
X-Labrador-Cache-Channel
X-MP-GENERATED-AT
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-Upstream-CT
X-Upstream-HT
X-Section
X-Varnish-Server
Decoy-Debug-TTL
X-Cache-Host
X-Web-Node
Decoy-Debug-Key
X-Backend-Name
X-Varnish-Cache-Hits
X-From
X-RCS-CacheZone
X-Upgrade-Enabled
Decoy-Debug-Status
Now
X-PCL
X-Viewer-Country
X-Loop
X-OCL
X-TNCMS
X-Sorting-Hat-PodId
X-ShardId
X-AWS-Id
X-Shopify-Stage
X-Akamai-Request-ID
X-Alternate-Cache-Key
Rt-Fastcgi-Cache
X-Rule
X-L-Path
X-Sorting-Hat-ShopId
Mn-Server-Ip
X-ShopId
X-LJ-Flow-ID
X-Magnolia-Registration
X-Varnish-Hits
X-Human
X-Debug-Cache
X-Origin-Response-Time
X-EIG-Tracking-Id
X-Environment-Context
X-Endurance-Cache-Level
X-VWS-Id
X-CCM
X-Region
X-VG-TLSProxy
X-FC-Vary-Parameters
X-Via-Fastly
DSUID
Mail-Subject
X-S
X-R9-Blue-Green-Version
GEO-INFO
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Timing-Wait
ServedBy
X-Generated
X-NCache
X-Proto
X-Hosted-By
X-Rendered-As
X-Proxy-Build
We-Hiring
X-JoinUs
X-Xfnlog-Site
OT-Force-Account-Verify
Cache-Name
SRV
X-Drupal-Cache-Contexts
DB-Nickname
X-Guploader-Uploadid
Uber-Trace-Id
X-Cluster-Node
X-Device-Type
Akamai-GRN
X-Trace-Id
Release
X-Locale
X-Site-Version
X-Nginx-Cache
Cteonnt-Length
X-ProxyCache-Key
X-Redis-Cache
X-BYPASS-REASON
X-ProxyCache-Status
X-Www-Served-By
X-Load-Cache
X-VCT
Version
NGX
X-UUID
X-Request-Time
ProcessTime
X-Platform-Server
X-IP
X-Time-Microsecs
X-Daa-Tunnel
Time
X-Cache-NE
X-Via-CDN
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
X-ECACHE
Azure-InstanceId
X-Wix-Request-Id
X-Origin
X-FW-Version
Azure-Version
S-Rt
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-MServer
X-GEO
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
TWC-GeoIP-Country
X-Rocket-Nginx-Bypass
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
X-Origin-Hint
X-Hl-Ver
NtCoent-Length
X-Cache-Remote
X-No-Session
X-Dc
X-ServerID
X-Proxy
X-FireWall-Port
CACHE
X-Akamai-Request-ID2
X-IPS-LoggedIn
X-Vgn-Hpd-Reason
Origin
X-CDN-Forward
X-SERVER-NAME
X-HTML-Minification-Powered-By
X-Akamai-Transformed
X-PERF
Odigeo-Trace-Id
X-ApacheServer
X-Distributor
X-Real-IP
X-Oneagent-Js-Injection
Fastly-SSL
X-CS
X-Format
X-Cache-Backend
X-Cache-Server
Ec-Rule-Version
X-RateLimit-Reset
L5d-Success-Class
Cache-Tags
X-Microcachable
X-Unique-ID
X-UA
Access-Control-Request-Headers
X-Compress-Hint
X-Pubstack
Served-By
X-UnsetCookies
Origin-Edge-Control
Hostname
Origin-Cache-Control
LB
X-Webkit-Csp
Fastcgi-X-Cache-Version
X-Tb
X-NC
IBM-Web2-Location
X-Cache-Category-Id
X-Grey
Accept-Language
Backend-Name
X-B3-Parentspanid
X-Varnish-Cacheable
Fastly-SIE
Fastly-SWR
X-VG-WebServer
Cross-Origin-Window-Policy
Content-Script-Type
Content-Style-Type
Fly-Cache
Fly-Request-Id
X-Transaction
X-Edge-Server
X-External-Request-Id
X-G
X-Trv-Group
GEO-REGION-INFO
Cdn-Request-Time
Cdn-Host
AsisCache
BehaviorPad-Version
Arc-Country
X-Internal-Host
X-IN-APIGATEWAY
A
Cache-Cookie-Set-From
X-S-Maxage
Cache-Prefix
X-Is-Bot
Cache-Cookie-Set-Lfrom
X-DPWN-IS-SECURE
X-Twitter-Response-Tags
X-Instart-Info
Mobile-Detection-Method
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dam
X-A
X-A-Ccd
X-Aed
X-CF-Lambda-Version
X-Application
X-ARC
X-B-Cookie
X-App-Name
X-AIR-PT
X-CF-Lambda-Fn
X-Cdn-Srv
X-Cluster-Name
VivaBuild
X-Destination
Proxy-Firewall
Rendered-Blocks
X-Detected-As
X-Developer
Meta-Geo-Continent
Node
Request-Country
Request-EU
X-D
X-Connection-Hash
Viewtype
X-Date
Server-ID
Request-Time
Rt-Proxy-Cache
MD5-Digest
Cache-Cookie-Set-Idcheck
X-BACKEND-TTL
X-Cache-Bucket
X-Region-Sid
X-Request-UUID
X-Vtex-Remote-Cache
X-NU-AKA-ACS-Version
X-Org
X-ScT
X-Vtex-Processado-Em
X-SRCache-Key
X-Rebelmouse-Surrogate-Control
Xc-Version
X-Worker
X-Rewrite-Enabled
X-Edge
X-S-Cookie
X-PAYTM-SRV-ID
X-Rojux
X-Rebelmouse-Cache-Control
X-Server-Time
X-ElasticPress-Search
ServerName
Gh-Request-Id
X-Sn-Servicetimems
X-PHP-Host
Ha-Gx-Prefs
X-Fastly-Cache
Esi-Enabled
X-Clientip
X-Debug-Cookies
RNT-Machine
RNT-Time
X-Skip-Cache
Resin-Trace
X-Processor
X-Debug-Log
Is-Eu
X-Developers
True-Client-Country-4JS
On-Server
X-Core-Mission
X-ServiceProvider
Platform
Server-Int
X-We-Are-Hiring
X-Epic-Correlation-Id
X-Eu-Site
W
X-Location
Memcached
Proxy-Connection
HA-Ipaddr
Countrycode
X-GeoIP-Country-Code
X-HS-Cache-Config
X-HS-Combine-CSS
X-NX-Host
AKAMAI
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Cdn-Origin
X-Powered-By-Defense
X-Backend-State
X-Cache-Id
X-C
X-Level-Front-Cache
X-Cache-Info
X-Variation
X-Nginx-Cache-Key
Apple-News-Services-Request-Url
Adler-Geo
Section-Io-Cache
X-Varnish-Url
X-SVT-ORM-VERSION
X-CGP
Content-Disposition
X-SVT-ORM-RULES
X-Request-URI
X-Geo-Header
X-Generated-On
X-Ua
X-CDN-Cache
X-Auto-Login
X-BBXSRF
X-Block-Status
Server-Host
X-Cache-FS-Status
X-SD-PageType
X-Reqid
SS
X-Secret
X-Clara-WADP
V-Age
X-Reboot
X-Cms-Context
X-WADP-Cache
X-Request-Start
User-Cache-Control
Web-Mar-Node
X-Served-From
X-Amz-Meta-Cache-Control
UCS
X-Response-By
X-Distil-CS
CDCHOST
REQUESTUUID
X-TH-Server
X-Hash
X-Generation-Time
Country-Code
Fastly-Soc-X-Request-Id
SD-X-WS
X-Gen-Mode
X-Hnp-Log
X-Via-SSL
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Li-Fabric
X-Key
X-Via-Edge
X-Irp-Debug
X-Method
X-Wikidot-Static-Cache
X-Gannett-Site-Version
X-SIPLIST1
X-FPC
X-Dispatcher-Server
X-Device-Os
PFcat
X-Via-NSCOPI
X-Servername
X-WebServer
X-Dispatch
X-Wikidot-Backend
IsBot
X-Fetched-On
CF-IPCountry
X-Amzn-Remapped-Content-Length
X-Owner
X-Matched-Rule
X-Qloud-Router
X-Thinkindot-L3
X-Origin-Expires
N-Cache
X-Thanos
X-Origin-Date
X-Release
X-GeoIP-City
X-VServer
X-Webstats-RespID
X-Server-IP
X-Crawler
Wxu-Next-Commit
Selected-Fe
Who
Wxu-Next-Hostname
Thinkindot-Control
Thinkindot-CacheControl-Type
L
Thinkindot-CacheControl
X-Nc
Wxu-Next-Region
X-Bip
X-Azure-Ref-OriginShield
X-Azure-Ref
Heartbleed
X-OVcl-Cache
X-TrackingId
Powered-By
X-Proxy-Upstream
GW-Server
X-OVcl
X-Proxy-Cache-Status
X-Swa-Ws
Pramga
X-VC-Cache
X-Parent-Response-Time
X-CUA
X-Varnish-Ttl
X-FE
X-CLOUD-TRACE-CONTEXT
X-Pf-Uncompressing
Kp-EeAlive
X-ND-Cache
Mime-Version
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Protected-By
X-Ratelimit-Remaining
User-Agent
X-LAGOON
PageSpeed
Magicmarker
X-Varnish-Beresp-Ttl
Pragrma
Memory
X-Fstrz
X-Origin-CC
X-Cache-Ttl
X-Page-Type
X-Origin-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Hello
X-Flog
X-ABtesting
X-Planisys-CDN-Rules
X-DC
Pagetype
X-Be
X-URL
X-Phone
X-Ttl
X-User
X-Backend-Url
X-Generated-In
X-Backend-Host
X-Geo
X-IN-WAF
X-Core-Value
X-Zone
X-Dynatrace-Js-Agent
X-Backend-TTL
X-GoCache-CacheStatus
X-Newrelic-Synthetics
X-MSEdge-Features
X-MSEdge-Flight
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Tt-Trace-Tag
X-Cdn-Forward
X-Up
X-Soup
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-B3-SpanId
X-Birta-Served
X-Birta-Cache-Post
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Storage-Class
X-TT-LOGID
X-Oss-Server-Time
X-Oss-Request-Id
X-Servedbyhost
X-Varnish-IP
X-Info
X-Litespeed-Cache
X-Check-Cacheable
Geoip-Latitude
GeoIp-Country-Code
Cdn
Geoip-City
HitType
X-ZONE
Selected-FE
X-MID
X-Say-Cacheable
X-SayCDN-TTL
X-Real-Ip
X-Say-TTL
X-Old-Content-Length
Cache-Hits
SN
X-HS-Status
X-VCL-Version
X-Mid
X-Tb-Optimization-Total-Bytes-Saved
X-Datadome
X-Aicache-OS
X-Akamai-SSL-Client-Sid
X-Ruxit-Js-Agent
CF-Cached-On
X-GRACE
Amp-Access-Control-Allow-Source-Origin
X-Cache-Debug
X-Refresh
X-Agile-Id
X-Agile-Age
X-Vcl-Version
X-Agile
FSS-Cache
FSS-Proxy
X-CSRF-TOKEN
X-Source
GeoIP-Country-Code
Inserted-Into-Cache-At
Fastly-Backend-Name
X-Cache-Time
X-Node-Id
X-ServedByHost
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Web-Server
X-BC
X-Bc
Server-Surrogate-Control
X-Varnish-Authentication
Server-Cache-Control
GeoIP-Latitude
X-Contensis-Viewer-Groups
X-Cache-ASPX
GeoIP-City
X-IN-APIGATEWAYSSL
HostName
WZWS-RAY
Ajk
X-Logtrace-Id
X-App-Version
X-EC-Lua
XServer
X-Via-Ucdn
RequestId
X-UPSTREAM-Address
X-COUNTRY
X-APP
X-CSRF-Token
X-FORWARDED-FOR
Srv
X-Nananana
X-Wa
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Group
Xkeyrz
X-TIME
X-Proxy-Cacherz
X-BE
X-ECache
X-WR-MODIFICATION
Ohc-Cache-HIT
Ohc-File-Size
X-NWS-UUID-VERIFY
X-Dynatrace
WebServer
X-Varnish-Beresp-TTL
T-Server
HTTPS
Cf-Ipcountry
PICS-Label
X-LB-ID
X-PJAX-URL
X-LiteSpeed-Cache-Control
Get-Access-Time
X-Render-Time
Is-Session-Tracking
X-GDPR
X-Micro-Cache
Xkeynj
URI
X-Fastly-Country-Code
X-SN
X-SRV
X-CACHE-KEY
X-Cache-Tag
Www
MIME-Version
X-Unique-Id
X-PAGE-TYPE
Backend
X-Edge-IP
X-Instart-Isnd
X-Request-Url
X-Requestid
X-Cache-Miss-From
X-Sedo-Request-Id
X-MCACHE
Dynatrace
CDN
X-ID
Lb
X-Fastly-Backend-Reqs
Cneonction
Host-ID
X-Cache-Expires
SID
Requestid
X-Policy
X-Uri
DataCenter
Xet-Cookie
X-Pjax-Url
X-Apw-Access-Object
X-Vct
X-Swift-Error
X-Apw-Hits
X-Apw-Access-Token
Pics-Label
X-Apw-Access-Action
X-Dw-Trace-Id
X-NGINX-Cache
X-Service
Epwk-Cache
X-Cdn-Request-ID
X-WA
Correlation-Id
X-PF-Uncompressing
X-Cf-Powered-By
X-Varnish-Action
X-Lb-Id
Cache-Provider
X-Ecache
X-Newrelic-App-Data
X-NGENIX-Cache
RequestUuid
X-Serial
X-Akamai-ERRuleID
Fastcgi-X-Cache
X-DW
Warning
X-Bug-Bounty
X-Flow-Id
Lfy
X-Zalando-Child-Request-Id
X-Html-Edge-Cache
X-Page-Impression-Id
X-WPE-Loopback-Upstream-Addr
X-Fastly-Cache-Hits
X-DB
X-RSL
X-Fpc
X-Akamai-ERPolicy
X-RPS
X-RPM
X-DI
X-DSS
X-ServerName