Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
Alt-Svc
X-Adblock-Key
X-Drupal-Cache
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
P3p
X-Template
X-Language
Status
Timing-Allow-Origin
X-Iinfo
Content-Encoding
X-Content-Security-Policy
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
EagleId
X-Server-Powered-By
X-UA-Device
X-Varnish-Cache
Request-Context
X-Nginx-Cache-Status
X-Request-ID
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Server-Id
X-WebKit-CSP
Server-Timing
Feature-Policy
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Host
X-Rq
Report-To
X-Ac
X-Node
Content-Location
X-OneAgent-JS-Injection
X-Cnection
X-Response-Time
X-Backend-Server
X-Cloud-Trace-Context
X-Origin-Cache
X-Application-Context
X-Readtime
Request-Id
Allow
Surrogate-Control
EagleEye-TraceId
X-ORACLE-DMS-ECID
X-Country
X-DynaTrace
X-Vhost
X-Cdn
X-TTL
X-Cache-Lookup
Pinterest-Generated-By
X-Ua-Compatible
X-Rack-Cache
X-Origin-Upstream-Status
X-Clacks-Overhead
X-Url
X-FTR-Request-ID
NEL
Rating
X-Dns-Prefetch-Control
X-Country-Code
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dispatcher
X-ORACLE-DMS-RID
X-HW
X-CST
X-Goog-Hash
X-Instart-Request-ID
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
X-DataStream-Cache-Status
Edge-Control
X-PC
X-Vname
X-TtlSet
X-DataDome
X-Px
X-VARITI-CCR
Service-Worker-Allowed
Verso
X-Mod-Pagespeed
X-Recruiting
X-MS-InvokeApp
X-Kinja-Build
X-Varnish-TTL
X-Use-Magma
X-Kinja-Server
X-Kinja
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-Cdn-Fetch
X-GoogleNews-Bot
RTSS
X-D2id
SPRequestGuid
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
TCN
X-SharePointHealthScore
X-Navigation-Version
X-GitHub-Request-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
DynaTrace
X-Akam-SW-Version
X-Sol
X-Middleton-Display
Response
Display
X-Middleton-Response
X-Powered-By-Plesk
X-RateLimit-Remaining
MS-Author-Via
X-B3-TraceId
Charset
X-Shield-Request-Id
X-ESI
Realpath
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
ServerID
X-Forwarded-Proto
X-Amz-Rid
Content-MD5
X-Powered-CMS
AR-ATIME
Ar-Sid
AR-PoweredBy
AR-CACHE
X-Trace
X-Upstream
Nginx-Cache
Fastly-Restarts
X-Version
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Public-Key-Pins
X-Cached
X-Dw-Request-Base-Id
X-Server-Name
X-Shard
AR-Request-ID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Accept-Ch-Lifetime
Access-Control-Request-Method
Pagespeed
Paypal-Debug-Id
Accept-CH
X-Grace
X-DynaTrace-JS-Agent
X-MSEdge-Ref
X-Goog-Storage-Class
SPRequestDuration
SPIisLatency
X-Client-IP
Accept-Ch
S
X-Debug
X-FTR-DC
X-FTR-Backend
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Id
X-Ezoic-Cdn
X-Amz-Meta-S3cmd-Attrs
X-Vcache
X-FastCGI-Cache
X-N
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Proxy
X-Fastly-Request-ID
Front-End-Https
X-Amzn-Trace-Id
X-T
X-DIS-Request-ID
X-NF-Request-ID
Arr-Disable-Session-Affinity
X-Content-Type
MicrosoftSharePointTeamServices
X-Hits
X-B3-Sampled
X-XRDS-Location
X-B3-Traceid
X-FTR-Cache-Host
X-Varnish-Age
X-Ser
X-Acc-Meta-Resource-Type
X-Frontend
PB-PID
X-Mobile-Rewrite
Arc-Version
PB-RID
Fastcgi-Cache
X-Logged-In
Server-Name
X-Content-Digest
X-Correlation-Id
Alternate-Protocol
X-Cache-Key
X-Srv
Nel
X-Node-Name
X-VCache
X-Pad
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
FilterID
TP-Cache
TP-L2-Cache
X-Forwarded-For
Host
X-User-Agent
X-Type
X-Rid
X-Kinsta-Cache
Healthy
Powered-By-ChinaCache
X-LB-Cache
X-Request-Processing-Time
X-F-Cache
X-IPLB-Instance
X-Request-Received
X-Zen-Fury
Powered
X-Cache-2
X-Amzn-RequestId
X-Amz-Apigw-Id
Edge-Cache-Tag
X-AOL-HN
X-Debug-Info
X-Revision
X-Cached-By
X-GUploader-UploadID
X-XRDS-LOCATION
X-Esi
X-Hostname
X-Cache-Age
Backend-Timing
X-Analytics
X-HS-Hub-Id
X-Kong-Upstream-Latency
X-HS-Content-Id
X-Kong-Proxy-Latency
X-Via-JSL
Accept-CH-Lifetime
X-Cache-Rule
X-Activity-Id
X-Accel-Expires
X-AppVersion
X-Az
Surrogate-Key
X-Varnish-Backend
X-Content-Security-Policy-Report-Only
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Content-Options
X-Page-Id
X-Instance
X-BCube-Filmed-By
X-Varnish-Grace
X-Content-Powered-By
X-Amz-Replication-Status
X-Cluster
X-FB-Debug
X-PHP-Backend
X-Tumblr-User
Server-Node
X-Tumblr-Pixel-0
X-Request-Guid
X-Jobs
X-Tumblr-Pixel
X-Akamai-Edgescape
Source
Cleartype
X-B-Cache
X-Signature
Refresh
Cache-Status
X-Fastcgi-Cache
X-TT
X-App-Environment
X-RateLimit-Limit
X-Forwarded-Host
X-Framework
Liferay-Portal
X-FW-Type
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Server
DC
X-Varnish-Hostname
X-ATG-Version
Tracecode
Host-Header
Accept-Charset
X-Mobile
Fastcgi-Useragent
Access-Control-Allow-Method
WPE-Backend
X-APP-VERSION
X-Cache-Action
X-Cache-Operation
X-Edge-Location
X-Cache-Control
X-Drupal-Cache-Tags
X-Time
X-B
X-Cache-Hit
Actual-Object-TTL
X-Whom
X-Mobile-URL
X-Erf-Bev-Bev
X-Hp-Webp
X-Erf-Bev-Bev-Is-Generated
Payment
X-Response-Served-From
X-Accel-Buffering
X-WA-Info
X-Storage
X-TX-ID
X-App-Server
X-Content-Age
NGB
X-Git-Hash
X-SS-Set-Cookie
X-WebKit-CSP-Report-Only
X-Yottaa-Metrics
Upgrade-Insecure-Requests
Cache-Tv-Group
X-TT-TIMESTAMP
X-Yottaa-Optimizations
X-Cacheable-TTL
X-NWS-LOG-UUID
X-Handled-By
X-UA-Device-Type
Filters
X-RemovedCookies
X-Presslabs-Stats
Eomportal-Instance
X-GeoIP
X-Adobe-Content
Cache-Tag
X-Tumblr-Pixel-2
X-Adobe-Loc
Viewport
X-ProcessESI
X-Tumblr-Pixel-1
X-Status
X-RequestSource
X-Geo-Country
X-TA-CDN-Provider
X-VG-WebCache
Retry-After
X-Cache-TTL
X-FW-Dynamic
Webserver
X-Cache-TTL-Remaining
X-Server-ID
Xserver
MS-CV
X-Seen-By
Datacenter
Cache
X-FB-TRIP-ID
Server-Info
X-Cache-Enabled
X-Host-Name
X-Ratelimit-Limit
X-Oracle-Dms-Rid
X-Contextid
Frame-Options
X-RTag
X-B3-Spanid
Ms-Operation-Id
X-Hyper-Cache
From-Origin
X-Generated-By
X-Origin-Server
X-Ratelimit-Reset
Country
X-Mode
S-Cnection
Load-Balancing
X-Path-Route
X-Tumblr-Pixel-3
X-CF-Powered-By
X-Cache-Config
X-RN-RSRV
X-Cache-Var
Machine
X-ES-SERVER
X-Cache-Var-Map
Meta-Geo
X-Proxied
X-Cache-Grace
X-MP-GENERATED-AT
X-Section
Vix-Hermes-Req-Id
X-Labrador-Cache-Channel
X-Zipkin-Id
X-Upstream-HT
Cache-Key
X-Upstream-CT
X-Routing-Service
X-Access
X-Varnish-Cache-Hits
X-Upgrade-Enabled
X-TNCMS
X-Guploader-Uploadid
X-Viewer-Country
X-From
X-Drupal-Cache-Contexts
X-Hit
X-Human
X-Loop
GEO-INFO
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-PCL
X-OCL
Now
X-Web-Node
SRV
X-Backend-Name
X-Cache-Host
X-Varnish-Server
X-Region
X-Rule
X-EIG-Tracking-Id
X-Sorting-Hat-PodId
X-Debug-Cache
X-Sorting-Hat-ShopId
X-Origin-Response-Time
X-AWS-Id
X-LJ-Flow-ID
X-Magnolia-Registration
X-Akamai-Request-ID
X-CCM
X-Shopify-Stage
X-Trace-Id
X-Alternate-Cache-Key
X-L-Path
X-ShopId
ServedBy
Rt-Fastcgi-Cache
X-R9-Blue-Green-Version
Mn-Server-Ip
X-Endurance-Cache-Level
X-VWS-Id
X-ShardId
X-VG-TLSProxy
X-Environment-Context
X-Via-Fastly
DB-Nickname
X-FC-Vary-Parameters
DSUID
OT-Force-Account-Verify
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hosted-By
X-Generated
Mail-Subject
X-JoinUs
We-Hiring
X-Rendered-As
Akamai-GRN
X-Xfnlog-Site
X-Site-Version
CACHE
X-Cluster-Node
X-Timing-Wait
X-Proxy-Build
X-S
Cache-Name
X-Locale
X-Proto
X-NCache
X-RCS-CacheZone
X-Www-Served-By
X-Varnish-Hits
X-Device-Type
Release
Version
X-Dc
Uber-Trace-Id
ProcessTime
X-Load-Cache
X-Request-Time
X-Time-Microsecs
X-IP
X-VCT
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-PressLabs-Stats
X-RateLimit-Reset
X-NewRelic-App-Data
X-Nginx-Cache
Time
X-Redis-Cache
NGX
Cteonnt-Length
S-Rt
Azure-Version
Azure-SlotName
X-UUID
X-FW-Version
X-Wix-Request-Id
X-Origin
NtCoent-Length
Azure-SiteName
X-Platform-Server
Azure-InstanceId
Azure-RegionName
X-Akamai-Request-ID2
X-Via-CDN
TWC-Device-Class
X-Origin-Hint
TWC-GeoIP-Country
TWC-Locale-Group
Webcakes-App-Version
X-No-Session
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-CDN-Forward
X-EdgeConnect-Cache-Status
Property-Id
X-UA
X-ECACHE
X-GEO
X-Proxy
X-MServer
X-FireWall-Port
X-Cache-NE
X-Rocket-Nginx-Bypass
X-Daa-Tunnel
X-Hl-Ver
X-IPS-LoggedIn
X-ServerID
Origin
Odigeo-Trace-Id
X-Vgn-Hpd-Reason
X-HTML-Minification-Powered-By
X-ApacheServer
X-Cache-Remote
X-Oneagent-Js-Injection
X-Akamai-Transformed
X-PERF
X-Distributor
X-CS
X-Cache-Server
X-Format
LB
Ec-Rule-Version
Cache-Tags
Access-Control-Request-Headers
Fastly-SSL
Accept-Language
X-UnsetCookies
X-Webkit-Csp
L5d-Success-Class
X-SERVER-NAME
X-Tb
X-Unique-ID
Hostname
X-Pubstack
X-Microcachable
Origin-Cache-Control
Origin-Edge-Control
X-BACKEND-TTL
X-Real-IP
Fastcgi-X-Cache-Version
X-URL
X-Cache-Backend
Served-By
X-NC
X-Compress-Hint
X-Varnish-Cacheable
Cache-Prefix
Cdn-Request-Time
Cdn-Host
Cache-Cookie-Set-From
Arc-Country
AKAMAI
AsisCache
BehaviorPad-Version
Cache-Cookie-Set-Idcheck
Content-Script-Type
Cache-Cookie-Set-Lfrom
Fastly-SIE
Proxy-Firewall
REQUESTUUID
Request-Time
Rendered-Blocks
Request-Country
Xc-Version
Request-EU
Node
Mobile-Detection-Method
Fly-Cache
Fastly-SWR
Cross-Origin-Window-Policy
Fly-Request-Id
GEO-REGION-INFO
Meta-Geo-Continent
MD5-Digest
Content-Style-Type
X-VG-WebServer
X-Cache-Bucket
X-Rebelmouse-Surrogate-Control
X-Cdn-Srv
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
X-Rebelmouse-Cache-Control
A
X-Region-Sid
X-ARC
X-Application
X-Rojux
X-Rewrite-Enabled
X-Request-UUID
X-B-Cookie
X-Detected-As
X-CF-Lambda-Version
X-IN-APIGATEWAY
X-D
X-Geo-Header
X-Destination
X-Generated-On
X-Date
X-Instart-Info
X-Connection-Hash
X-NU-AKA-ACS-Version
X-Org
X-Level-Front-Cache
X-Is-Bot
X-Internal-Host
X-Cluster-Name
X-S-Cookie
X-S-Maxage
X-Varnish-Url
X-Edge-Server
X-DPWN-IS-SECURE
X-A-Dcw
X-A-Dgt
X-External-Request-Id
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
VivaBuild
Viewtype
X-A
X-A-Ccd
X-Worker
X-A-Dam
X-Twitter-Response-Tags
X-Trv-Group
X-Server-Time
X-Developer
X-AIR-PT
X-ScT
X-G
X-App-Name
X-SRCache-Key
X-SVT-ORM-RULES
X-A-Wwc
X-Transaction
X-SVT-ORM-VERSION
X-Accel-Expires-Debug
X-Aed
Server-ID
Rt-Proxy-Cache
X-B3-Parentspanid
Proxy-Connection
X-Dynatrace-Js-Agent
X-Amzn-Remapped-Content-Length
X-Grey
X-Cache-Category-Id
IBM-Web2-Location
X-ElasticPress-Search
Backend-Name
Selected-Fe
ServerName
Platform
X-Cache-Id
X-Backend-State
X-Cache-Info
X-Cdn-Origin
On-Server
X-CGP
RNT-Time
X-Edge
X-Clientip
Server-Int
Resin-Trace
True-Client-Country-4JS
RNT-Machine
W
Section-Io-Cache
X-Developers
X-Request-URI
X-PHP-Host
X-NX-Host
X-Nginx-Cache-Key
X-ServiceProvider
X-Skip-Cache
X-We-Are-Hiring
X-Variation
X-Sn-Servicetimems
X-Method
X-Location
Memcached
X-Debug-Log
X-Debug-Cookies
X-Epic-Correlation-Id
X-Fastly-Cache
X-HS-Combine-CSS
X-HS-Cache-Config
X-GeoIP-Country-Code
X-Core-Mission
X-Eu-Site
HA-Ipaddr
X-C
Countrycode
Adler-Geo
Content-Disposition
Esi-Enabled
Ha-Gx-Prefs
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Gh-Request-Id
Apple-News-Services-Handled
Is-Eu
X-SERVER
X-Qloud-Router
CDCHOST
X-GeoIP-City
X-Cache-FS-Status
X-Hash
X-Block-Status
X-Irp-Debug
X-Device-Os
X-Distil-CS
X-Hnp-Log
X-Gen-Mode
X-CDN-Cache
X-Fetched-On
X-Key
Country-Code
X-Dispatch
X-Cms-Context
X-Clara-WADP
X-Gannett-Site-Version
X-FPC
Fastly-Soc-X-Request-Id
X-Dispatcher-Server
X-Owner
X-Swa-Ws
X-TH-Server
X-Nc
X-SIPLIST1
X-Servername
X-Thanos
X-WADP-Cache
UCS
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-WebServer
X-Secret
X-SD-PageType
X-Bip
X-Proxy-Cache-Status
X-LI-UUID
X-LI-Proto
X-Li-Pop
X-Proxy-Upstream
X-Reboot
X-BBXSRF
X-Response-By
X-Request-Start
X-Reqid
X-Li-Fabric
X-Generation-Time
SD-X-WS
X-TrackingId
X-Server-IP
PFcat
X-Amz-Meta-Cache-Control
IsBot
Server-Host
User-Cache-Control
Web-Mar-Node
SS
L
V-Age
N-Cache
X-Auto-Login
Thinkindot-CacheControl
X-Pf-Uncompressing
X-Crawler
X-Via-NSCOPI
Pramga
Thinkindot-Control
X-Matched-Rule
Thinkindot-CacheControl-Type
X-Origin-Date
X-Served-From
Kp-EeAlive
X-VServer
GW-Server
Heartbleed
Powered-By
Who
X-VC-Cache
Wxu-Next-Region
X-Webstats-RespID
Wxu-Next-Hostname
X-Thinkindot-L3
Wxu-Next-Commit
X-Processor
X-Origin-Expires
X-Powered-By-Defense
X-Azure-Ref
X-Release
X-Azure-Ref-OriginShield
CF-IPCountry
X-Parent-Response-Time
Locale
X-Varnish-Ttl
X-Urbn-Context-Path
X-Urbn-Site-Id
X-OVcl
X-OVcl-Cache
X-FE
X-Via-Edge
X-CLOUD-TRACE-CONTEXT
X-Via-SSL
X-CUA
PageSpeed
Magicmarker
User-Agent
X-Ratelimit-Remaining
Mime-Version
X-Hello
X-Protected-By
X-ND-Cache
X-Flog
X-Varnish-Beresp-Ttl
X-LAGOON
X-ABtesting
X-Be
Memory
Pagetype
X-Ua
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Generated-In
X-Backend-Host
Pragrma
X-User
X-Page-Type
X-Planisys-CDN-Cache
X-Backend-Url
X-Fstrz
X-Origin-TTL
X-Newrelic-Synthetics
X-Origin-CC
X-Up
X-Geo
X-COUNTRY
X-Tt-Trace-Tag
X-MSEdge-Flight
X-MSEdge-Features
X-Ttl
X-GoCache-CacheStatus
X-Cache-Ttl
X-Debug-Cache-Store
X-Soup
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Zone
Geoip-Latitude
X-Check-Cacheable
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-B3-SpanId
X-Oss-Storage-Class
GeoIp-Country-Code
X-Core-Value
Geoip-City
X-Oss-Request-Id
X-Phone
X-Oss-Server-Time
X-Backend-TTL
X-IN-WAF
X-Varnish-Beresp-Grace
X-TT-LOGID
X-Varnish-Beresp-Status
X-Litespeed-Cache
Cache-Hits
X-ZONE
X-Servedbyhost
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Old-Content-Length
X-Cdn-Forward
X-DC
X-Real-Ip
XServer
X-Akamai-SSL-Client-Sid
Cdn
X-Birta-Cache-Post
X-Birta-Served
X-Mid
X-VCL-Version
SN
X-HS-Status
X-Datadome
X-Aicache-OS
X-CSRF-TOKEN
X-Varnish-IP
Amp-Access-Control-Allow-Source-Origin
X-Info
X-Cache-Time
X-Ruxit-Js-Agent
X-MID
X-Node-Id
HitType
Fastly-Backend-Name
Selected-FE
X-FORWARDED-FOR
FSS-Proxy
FSS-Cache
X-Vcl-Version
Inserted-Into-Cache-At
WZWS-RAY
X-Logtrace-Id
X-IN-APIGATEWAYSSL
X-ServedByHost
X-BC
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Tb-Optimization-Total-Bytes-Saved
Ajk
X-Refresh
X-EC-Lua
X-Varnish-Authentication
X-UPSTREAM-Address
HostName
X-Cache-Debug
X-Agile-Age
X-Agile-Id
X-Agile
X-Contensis-Viewer-Groups
CF-Cached-On
Server-Surrogate-Control
Server-Cache-Control
X-Cache-ASPX
X-Bc
X-Source
X-Wa
RequestId
X-APP
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Srv
X-CSRF-Token
X-Nananana
Dynatrace
X-Proxy-Cacherz
GeoIP-Country-Code
X-GRACE
Xkeyrz
X-Via-Ucdn
X-App-Version
X-Web-Server
T-Server
X-TIME
GeoIP-Latitude
X-WR-MODIFICATION
GeoIP-City
X-ECache
X-PJAX-URL
PICS-Label
WebServer
MIME-Version
X-LiteSpeed-Cache-Control
X-NWS-UUID-VERIFY
X-LB-ID
X-Varnish-Beresp-TTL
X-Render-Time
X-GDPR
Cf-Ipcountry
Ohc-File-Size
X-Tec-Api-Root
X-Tec-Api-Origin
Xkeynj
X-Unique-Id
Ohc-Cache-HIT
Get-Access-Time
Group
X-SRV
X-Tec-Api-Version
X-Cache-Tag
URI
X-Fastly-Country-Code
X-Micro-Cache
X-PAGE-TYPE
CDN
X-CACHE-KEY
Is-Session-Tracking
DataCenter
X-Cache-Miss-From
X-Sedo-Request-Id
X-Uri
X-Policy
HTTPS
X-BE
X-Requestid
SID
X-MCACHE
X-Fastly-Backend-Reqs
X-Request-Url
Www
Backend
X-Edge-IP
X-SN
X-NGINX-Cache
Xet-Cookie
Cache-Provider
X-Service
Lb
X-Vct
X-Lb-Id
X-Pjax-Url
Pics-Label
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
Cneonction
X-Swift-Error
X-Apw-Hits
X-Instart-Isnd
X-Dw-Trace-Id
X-Cdn-Request-ID
Host-ID
X-Cf-Powered-By
X-Cache-Expires
X-Ecache
Correlation-Id
FNAC-ModuleRouting
Requestid
Warning
X-Var-Ttl
X-WA
X-Newrelic-App-Data
X-Html-Edge-Cache
X-Serial
X-Is-Gdpr
X-JWT-State
Lfy
X-Bug-Bounty
Ohc-Response-Time
X-Has-Esi
X-Fe
X-DI
X-Fastly-Cache-Hits
X-DSS
X-Zalando-Child-Request-Id
X-DW
X-Fpc
X-RPS
X-RPM
X-Page-Impression-Id
X-ServerName
X-RSL
X-Akamai-ERRuleID
X-Varnish-Action
X-DB
X-PF-Uncompressing
X-Flow-Id
X-Akamai-ERPolicy