Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
CF-Cache-Status
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Request-Id
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Adblock-Key
X-Drupal-Cache
Alt-Svc
P3p
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Content-Security-Policy
X-Iinfo
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Cache-Group
X-Pass-Why
X-Age
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Amz-Request-Id
X-Amz-Id-2
X-Pingback
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Hacker
X-Proxy-Cache
Grace
X-Server-Powered-By
EagleId
X-Varnish-Cache
X-UA-Device
X-Nginx-Cache-Status
Request-Context
Cf-Railgun
X-Amz-Version-Id
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-LiteSpeed-Cache
X-Ua-Compatible
Ali-Swift-Global-Savetime
Feature-Policy
X-Device
Server-Timing
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Host
X-Ac
Report-To
X-Rq
X-Server-Id
X-OneAgent-JS-Injection
Content-Location
X-Node
X-Backend-Server
X-Response-Time
X-Cnection
EagleEye-TraceId
X-Origin-Cache
X-Application-Context
Allow
X-Cloud-Trace-Context
Request-Id
X-Readtime
Surrogate-Control
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Country
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Pinterest-Generated-By
X-Url
X-Ruxit-JS-Agent
X-Cdn
X-DynaTrace
X-Rack-Cache
X-Vhost
X-Clacks-Overhead
X-Origin-Upstream-Status
X-CST
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Goog-Hash
X-TTL
X-Instart-Request-ID
X-Dispatcher
X-DataStream-Cache-Status
Edge-Control
X-Px
X-Vname
X-PC
X-TtlSet
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-VARITI-CCR
Service-Worker-Allowed
X-Mod-Pagespeed
X-ESI
X-B3-TraceId
X-MS-InvokeApp
Verso
SPRequestGuid
X-Recruiting
X-Request-ID
X-Kinja
X-Exp-Id
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Revision
X-DataDome
X-D2id
X-Server-Name
X-Varnish-TTL
X-Vcap-Request-Id
X-Abt-Application-Version
X-SharePointHealthScore
X-Amz-Server-Side-Encryption
X-RateLimit-Remaining
Accept-Ch-Lifetime
X-Powered-By-Plesk
TCN
Display
X-Middleton-Display
X-Sol
Response
X-Middleton-Response
DynaTrace
X-Navigation-Version
X-GitHub-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
Charset
RTSS
AR-ATIME
AR-PoweredBy
AR-CACHE
Ar-Sid
X-Akam-SW-Version
MS-Author-Via
AR-Request-ID
X-Amz-Rid
X-Trace
ServerID
Realpath
X-Shield-Request-Id
X-Dw-Request-Base-Id
X-Cached
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-DynaTrace-JS-Agent
X-Powered-CMS
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Version
X-TEC-API-VERSION
Nginx-Cache
X-Server-ID
X-Forwarded-Proto
X-Shard
Pinterest-Version
X-Upstream-Proxy
X-Pinterest-Rid
Pagespeed
X-Upstream
SPIisLatency
SPRequestDuration
X-Goog-Storage-Class
Accept-Ch
Public-Key-Pins
Paypal-Debug-Id
X-Client-IP
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
X-MSEdge-Ref
X-VCache
Access-Control-Request-Method
S
Fastly-Restarts
X-Amz-Meta-S3cmd-Attrs
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Ezoic-Cdn
X-Debug
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend-Server
X-Id
X-FTR-Expires
X-DIS-Request-ID
Accept-CH
X-T
X-Fastly-Request-ID
X-N
MicrosoftSharePointTeamServices
X-Ser
X-Mobile-Rewrite
PB-RID
Alternate-Protocol
Arc-Version
PB-PID
X-Varnish-Age
Arr-Disable-Session-Affinity
X-NF-Request-ID
Fastcgi-Cache
X-Hits
X-Acc-Meta-Resource-Type
X-Amzn-Trace-Id
Front-End-Https
X-XRDS-Location
X-Content-Type
X-B3-Sampled
X-FTR-Cache-Host
X-Frontend
X-Grace
Nel
X-Logged-In
Server-Name
X-Content-Digest
X-Pad
X-Srv
Host
X-Forwarded-For
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
FilterID
X-Node-Name
X-Correlation-Id
Powered-By-ChinaCache
TP-Cache
Healthy
TP-L2-Cache
X-Debug-Info
X-LB-Cache
X-Rid
X-Fastcgi-Cache
X-Type
X-Kinsta-Cache
Edge-Cache-Tag
X-IPLB-Instance
X-AOL-HN
X-Request-Received
X-Request-Processing-Time
X-XRDS-LOCATION
X-User-Agent
X-HS-Hub-Id
X-Cache-2
X-Vcache
X-HS-Content-Id
X-Cached-By
X-GUploader-UploadID
X-Hostname
X-Cache-Rule
X-Revision
Surrogate-Key
Powered
X-F-Cache
X-Accel-Expires
X-Page-Id
Backend-Timing
X-Analytics
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Age
X-Zen-Fury
X-RateLimit-Limit
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
X-BCube-Filmed-By
X-Content-Options
X-Varnish-Grace
X-Cache-Key
X-Jobs
X-FB-Debug
X-Cluster
X-Request-Guid
X-Amz-Replication-Status
Cache-Status
X-PHP-Backend
X-Content-Powered-By
X-Tumblr-User
X-Tumblr-Pixel-0
X-TT
Source
X-Tumblr-Pixel
X-Instance
Tracecode
X-App-Environment
Cleartype
X-Akamai-Edgescape
WPE-Backend
X-Az
X-Activity-Id
X-AppVersion
X-Varnish-Hostname
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Framework
X-Cache-TTL
Host-Header
Server-Node
X-Mobile
X-Forwarded-Host
X-Via-JSL
Refresh
X-Cache-Control
X-NWS-LOG-UUID
X-Cache-Operation
X-ATG-Version
X-TA-CDN-Provider
Actual-Object-TTL
X-FW-Hash
X-FW-Type
X-FW-Serve
X-FW-Static
X-FW-Server
Accept-Charset
X-Drupal-Cache-Tags
X-Signature
X-B-Cache
X-Time
DC
X-Accel-Buffering
Upgrade-Insecure-Requests
X-Whom
X-App-Server
X-Edge-Location
Access-Control-Allow-Method
X-Cache-Hit
X-Cache-Action
Liferay-Portal
X-Response-Served-From
X-Storage
Payment
X-TX-ID
X-Content-Age
X-UA-Device-Type
X-WebKit-CSP-Report-Only
X-Hp-Webp
X-Mobile-URL
Server-Info
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-VG-WebCache
X-Handled-By
X-TT-TIMESTAMP
X-GeoIP
X-Cacheable-TTL
X-RequestSource
X-SS-Set-Cookie
Filters
Fastcgi-Useragent
X-Git-Hash
Eomportal-Instance
X-Adobe-Loc
X-Adobe-Content
X-B
X-RemovedCookies
X-Tumblr-Pixel-1
Cache-Tv-Group
X-Geo-Country
X-Tumblr-Pixel-2
Webserver
Viewport
X-ProcessESI
Xserver
X-Ttl
X-FB-TRIP-ID
X-Litespeed-Cache
X-WA-Info
Cache-Tag
X-Cache-TTL-Remaining
X-Ratelimit-Reset
Datacenter
Cache
X-Cache-Enabled
Retry-After
X-B3-Traceid
X-Ratelimit-Limit
X-Presslabs-Stats
X-Status
X-Contextid
NGB
S-Cnection
X-Seen-By
X-FW-Dynamic
X-CF-Powered-By
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Origin-Server
X-Magnolia-Registration
X-Mode
X-Real-IP
X-APP-VERSION
X-Varnish-Hits
X-Host-Name
X-Rendered-As
X-Daa-Tunnel
X-Guploader-Uploadid
Country
X-Cache-Var-Map
Machine
X-Cache-Var
X-RN-RSRV
Meta-Geo
Load-Balancing
X-Cache-NE
X-ES-SERVER
X-VCT
X-Path-Route
X-LJ-Flow-ID
X-AWS-Id
X-Cache-Config
X-VWS-Id
Release
GEO-INFO
X-Upstream-CT
X-Upstream-HT
Mail-Subject
X-Routing-Service
From-Origin
MS-CV
Vix-Hermes-Req-Id
We-Hiring
X-Human
DSUID
X-Proxied
X-Zipkin-Id
Uber-Trace-Id
Mn-Server-Ip
X-Access
X-From
X-TNCMS
X-RCS-CacheZone
X-Hit
X-Backend-Name
X-Varnish-Cache-Hits
Frame-Options
X-Viewer-Country
X-EIG-Tracking-Id
X-Loop
X-Device-Type
Cache-Key
X-Cache-Grace
X-Labrador-Cache-Channel
X-Varnish-Server
X-Debug-Cache
X-OCL
X-PCL
X-Section
X-Cache-Host
X-ProxyCache-Key
Now
X-Origin-Response-Time
X-Web-Node
X-Rule
X-CCM
X-Cluster-Node
X-Tumblr-Pixel-3
X-VG-TLSProxy
X-ProxyCache-Status
X-Proto
X-Akamai-Request-ID
ServedBy
X-BYPASS-REASON
X-Upgrade-Enabled
X-MP-GENERATED-AT
X-R9-Blue-Green-Version
Rt-Fastcgi-Cache
OT-Force-Account-Verify
X-Redis-Cache
X-Cache-Remote
X-Hyper-Cache
Akamai-GRN
X-JoinUs
X-Timing-Wait
X-Platform-Server
X-S
X-Proxy-Build
X-Hosted-By
X-FC-Vary-Parameters
X-Xfnlog-Site
X-UUID
X-Generated
NGX
X-NCache
X-Region
X-Environment-Context
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Via-Fastly
X-ShopId
X-ShardId
X-Goog-Meta-Goog-Reserved-File-Mtime
Cache-Name
X-Shopify-Stage
X-L-Path
X-Alternate-Cache-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Decoy-Debug-Key
DB-Nickname
X-Site-Version
X-Trace-Id
X-Hl-Ver
X-Www-Served-By
X-Nginx-Cache
X-Locale
X-PressLabs-Stats
X-Endurance-Cache-Level
Ms-Operation-Id
X-ECACHE
X-Generated-By
X-EdgeConnect-Cache-Status
X-GRACE
X-RTag
X-NewRelic-App-Data
X-Vgn-Hpd-Reason
X-Rocket-Nginx-Bypass
X-Drupal-Cache-Contexts
X-ServerID
X-MServer
Cteonnt-Length
X-Dc
X-Load-Cache
ProcessTime
Accept-CH-Lifetime
X-Wix-Request-Id
X-Request-Time
L5d-Success-Class
X-IPS-LoggedIn
X-IP
Time
CACHE
X-Time-Microsecs
X-CLOUD-TRACE-CONTEXT
X-RateLimit-Reset
Served-By
S-Rt
X-Via-CDN
X-Microcachable
X-Cache-Backend
X-B3-Spanid
X-Unique-ID
X-Esi
X-Origin
X-Origin-Hint
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
Webcakes-App-Name
Origin-Cache-Control
TWC-Device-Class
Origin-Edge-Control
NtCoent-Length
Webcakes-Region
X-Pubstack
Webcakes-App-Version
TWC-Locale-Group
Version
Property-Id
TWC-Connection-Speed
X-Distributor
Azure-RegionName
Azure-InstanceId
X-Nc
Azure-SiteName
Fastcgi-X-Cache-Version
X-FW-Version
Azure-Version
Azure-SlotName
Access-Control-Request-Headers
X-GEO
X-Proxy
X-Oneagent-Js-Injection
Fastly-SSL
X-UA
X-Cache-Server
X-Grey
Origin
X-BACKEND-TTL
X-Cache-Category-Id
X-Datadome
X-FireWall-Port
X-No-Session
X-Detected-As
X-Is-Bot
X-Via-NSCOPI
IBM-Web2-Location
X-PERF
X-ApacheServer
X-Webkit-Csp
Cache-Tags
Proxy-Connection
X-Powered-By-Defense
X-Format
X-Edge
X-Cdn-Forward
X-Varnish-Cacheable
Backend-Name
X-Akamai-Transformed
SRV
X-HTML-Minification-Powered-By
Hostname
Content-Style-Type
Cdn-Request-Time
Content-Script-Type
Cross-Origin-Window-Policy
Fly-Request-Id
GEO-REGION-INFO
X-Date
X-Destination
Fly-Cache
X-Developer
Ec-Rule-Version
X-DPWN-IS-SECURE
Xc-Version
X-Eu-Site
Arc-Country
X-External-Request-Id
X-Worker
X-G
X-CS
AsisCache
X-Edge-Server
Cache-Prefix
X-D
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
BehaviorPad-Version
Cache-Cookie-Set-From
Cdn-Host
X-Connection-Hash
X-App-Name
Viewtype
VivaBuild
X-Application
X-ARC
X-Cache-Bucket
X-B-Cookie
X-AIR-PT
X-Aed
X-A-Dam
X-A-Dcw
X-A-Ccd
X-A
X-Accel-Expires-Debug
X-A-Wwc
ServerName
Server-ID
Meta-Geo-Continent
Mobile-Detection-Method
X-CGP
MD5-Digest
HA-Ipaddr
X-Cluster-Name
Node
X-CF-Lambda-Version
Request-Time
Rt-Proxy-Cache
Request-EU
Request-Country
X-CF-Lambda-Fn
Rendered-Blocks
Ha-Gx-Prefs
A
X-Ua
X-IN-APIGATEWAY
X-A-Dgt
X-ScT
X-HS-Combine-CSS
X-Server-Time
X-Trv-Group
X-Transaction
X-SRCache-Key
X-HS-Cache-Config
X-S-Maxage
X-ND-Cache
X-Region-Sid
X-Org
X-PAYTM-SRV-ID
X-Processor
X-NU-AKA-ACS-Version
X-Request-UUID
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-Twitter-Response-Tags
X-Instart-Info
X-Vtex-Processado-Em
X-VG-WebServer
X-Vtex-Remote-Cache
Mime-Version
Odigeo-Trace-Id
X-C
On-Server
Proxy-Firewall
X-Cdn-Srv
Platform
X-Generated-On
X-Clientip
X-Key
X-Debug-Cookies
X-Debug-Log
X-Core-Mission
X-Level-Front-Cache
Resin-Trace
X-Variation
Memcached
RNT-Time
X-Rebelmouse-Surrogate-Control
X-Hash
X-Reqid
X-NX-Host
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-B3-Parentspanid
PageSpeed
True-Client-Country-4JS
Server-Host
Section-Io-Cache
X-Irp-Debug
X-Geo-Header
X-GeoIP-Country-Code
X-Request-URI
X-Backend-State
RNT-Machine
Is-Eu
Countrycode
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-ServiceProvider
Country-Code
Apple-News-Services-Request-Url
X-TH-Server
X-Dispatcher-Server
X-Fastly-Cache
X-Fstrz
X-We-Are-Hiring
Apple-News-Services-Handled
Fastly-SWR
X-Server-IP
X-Epic-Correlation-Id
Fastly-SIE
Adler-Geo
X-UnsetCookies
X-SVT-ORM-VERSION
X-Response-By
X-Cache-Info
X-Cache-Id
X-Block-Status
X-SVT-ORM-RULES
X-BBXSRF
X-Request-Start
X-PHP-Host
X-Protected-By
X-WebServer
X-Internal-Host
X-ElasticPress-Search
X-Fetched-On
X-Reboot
X-Amz-Meta-Cache-Control
X-Tb
X-Distil-CS
X-Device-Os
X-Developers
X-SD-PageType
X-Dispatch
X-LI-Proto
X-Gen-Mode
X-Li-Pop
X-Secret
X-Served-From
X-Crawler
X-Gannett-Site-Version
X-Li-Fabric
X-LI-UUID
X-Location
X-SIPLIST1
X-Cdn-Origin
X-Skip-Cache
X-Webstats-RespID
X-CDN-Cache
X-Hnp-Log
X-Servername
X-Wikidot-Static-Cache
X-Method
X-Wikidot-Backend
X-Nginx-Cache-Key
X-Sn-Servicetimems
Wxu-Next-Commit
Content-Disposition
Server-Int
Wxu-Next-Region
SS
Esi-Enabled
CDCHOST
SD-X-WS
PFcat
Pramga
IsBot
REQUESTUUID
Gh-Request-Id
AKAMAI
Who
User-Cache-Control
V-Age
UCS
Web-Mar-Node
Wxu-Next-Hostname
X-Compress-Hint
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Cms-Context
X-Swa-Ws
X-Owner
GW-Server
Heartbleed
X-Release
X-Parent-Response-Time
X-Origin-Date
X-Origin-Expires
X-Auto-Login
Pragrma
X-GeoIP-City
X-Generation-Time
X-Bip
X-Thanos
Fastly-Soc-X-Request-Id
X-Cache-FS-Status
X-Via-Edge
X-Via-SSL
X-Be
X-CDN-Forward
X-Origin-TTL
X-Akamai-Request-ID2
X-Birta-Cache-Post
X-Origin-CC
X-Birta-Served
X-Matched-Rule
X-IN-WAF
Powered-By
X-VServer
X-Thinkindot-L3
X-B3-SpanId
X-OVcl-Cache
X-OVcl
X-Phone
LB
X-VC-Cache
X-Core-Value
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-App-Version
X-Varnish-IP
X-Varnish-Ttl
X-FPC
Selected-FE
HitType
X-Ratelimit-Remaining
X-Azure-Ref
W
Memory
X-LAGOON
X-CUA
X-Azure-Ref-OriginShield
X-Geo
X-CACHE-KEY
X-Info
X-NC
X-Varnish-Url
X-Clara-WADP
CF-IPCountry
X-WADP-Cache
Accept-Language
L
X-Source
X-Page-Type
N-Cache
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Varnish-Beresp-Ttl
X-URL
X-Web-Server
Cdn
X-FE
X-TrackingId
X-Zone
X-Dynatrace-Js-Agent
X-Pf-Uncompressing
X-Agile-Id
X-Agile-Age
Kp-EeAlive
X-Agile
X-Cache-Debug
X-Amzn-Remapped-Content-Length
X-Varnish-Beresp-Status
User-Agent
X-Varnish-Beresp-Grace
Magicmarker
Selected-Fe
X-Urbn-Context-Path
X-DC
X-Urbn-Site-Id
Locale
Geoip-Latitude
GeoIp-Country-Code
X-Refresh
Geoip-City
X-TT-LOGID
CF-Cached-On
X-Servedbyhost
X-HS-Status
Pagetype
X-Vcl-Version
X-NWS-UUID-VERIFY
X-Mid
X-MID
X-ABtesting
X-Backend-TTL
X-User
X-Real-Ip
X-Generated-In
X-Hello
X-Flog
X-Newrelic-Synthetics
Ohc-File-Size
Ohc-Cache-HIT
SN
X-Backend-Url
X-Check-Cacheable
X-Backend-Host
X-Aicache-OS
Group
Amp-Access-Control-Allow-Source-Origin
X-Ruxit-Js-Agent
X-MSEdge-Features
X-Soup
FSS-Cache
FSS-Proxy
X-MSEdge-Flight
X-Up
X-Tt-Trace-Tag
HTTPS
X-ServedByHost
X-Debug-Cache-Expiry
X-GoCache-CacheStatus
X-APP
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-ZONE
HostName
X-UPSTREAM-Address
Www
X-Tb-Optimization-Total-Bytes-Saved
X-VCL-Version
WZWS-RAY
Backend
GeoIP-Country-Code
RequestId
X-SN
Srv
X-EC-Lua
X-Oss-Hash-Crc64ecma
Server-Surrogate-Control
X-Cache-ASPX
Server-Cache-Control
X-Varnish-Authentication
GeoIP-Latitude
X-Oss-Object-Type
X-Contensis-Viewer-Groups
GeoIP-City
X-Oss-Storage-Class
X-Instart-Isnd
X-Oss-Server-Time
X-Oss-Request-Id
X-CSRF-Token
X-Akamai-SSL-Client-Sid
Cf-Ipcountry
X-NGENIX-Cache
X-Via-Ucdn
X-Varnish-Beresp-TTL
X-COUNTRY
X-Cache-Expires
X-Bc
X-Oracle-Dms-Rid
X-Old-Content-Length
Lb
X-BC
Host-ID
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Nananana
X-PF-Uncompressing
X-Say-Cacheable
X-Cache-Tag
X-Proxy-Cacherz
X-Say-TTL
X-ECache
X-Varnish-Action
Xkeyrz
X-SayCDN-TTL
Epwk-Cache
URI
XServer
X-Dynatrace
Requestid
Fastcgi-X-Cache
X-AssetVersion
X-Fastly-Country-Code
X-LiteSpeed-Cache-Control
X-Unique-Id
X-PAGE-TYPE
X-FORWARDED-FOR
Inserted-Into-Cache-At
Get-Access-Time
Is-Session-Tracking
X-TIME
X-Node-Id
Xkeynj
X-WR-MODIFICATION
Cache-Hits
X-MCACHE
X-Request-Url
X-IN-APIGATEWAYSSL
X-Var-Ttl
Fastly-Backend-Name
Ajk
X-Logtrace-Id
X-Requestid
X-Cache-Miss-From
X-SERVER-NAME
X-Sedo-Request-Id
X-Edge-IP
X-Correlation-ID
X-Sf
WebServer
X-Cache-Ttl
FNAC-ModuleRouting
Dynatrace
X-Pjax-Url
X-Cache-Time
X-CSRF-TOKEN
Cache-Provider
Cneonction
X-Svr
X-Fastly-Backend-Reqs
Xet-Cookie
DataCenter
X-SRV
CDN
X-Fastly-Cache-Hits
X-Swift-Error
Correlation-Id
X-Lb-Id
X-RateLimit-Limit-Second
X-WA
Pics-Label
X-RateLimit-Remaining-Second
X-Fpc
X-Dw-Trace-Id
X-NGINX-Cache
X-BE
Sid
X-Apw-Hits
X-Apw-Access-Action
X-Wa
X-Apw-Access-Object
X-Policy
X-Apw-Access-Token
PICS-Label
X-RSL
T-Server
X-ServerName
X-RPS
X-App
X-Alicdn-Da-Ups-Status
Ohc-Response-Time
X-Akamai-ERPolicy
X-Bug-Bounty
Warning
X-Zalando-Child-Request-Id
X-Akamai-ERRuleID
X-Flow-Id
X-Page-Impression-Id
Lfy
X-Html-Edge-Cache
X-DI
X-DSS
X-DW
X-DB
X-LiteSpeed-Tag
X-WPE-Loopback-Upstream-Addr
RequestUuid
X-RPM