Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
Alt-Svc
X-Adblock-Key
X-Drupal-Cache
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
P3p
X-Template
X-Language
Status
Timing-Allow-Origin
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
EagleId
X-Server-Powered-By
X-UA-Device
X-Varnish-Cache
Request-Context
X-Nginx-Cache-Status
X-Request-ID
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
Feature-Policy
X-Server-Id
Server-Timing
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Host
X-Rq
Report-To
X-Ac
X-Node
Content-Location
X-OneAgent-JS-Injection
X-Backend-Server
X-Response-Time
X-Cnection
X-Cloud-Trace-Context
X-Origin-Cache
X-Application-Context
X-Readtime
Allow
Request-Id
EagleEye-TraceId
Surrogate-Control
X-Country
X-ORACLE-DMS-ECID
X-Cache-Lookup
X-Vhost
X-TTL
X-DynaTrace
X-Url
X-Cdn
Pinterest-Generated-By
X-Rack-Cache
X-Clacks-Overhead
X-Origin-Upstream-Status
X-Ua-Compatible
NEL
X-FTR-Request-ID
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
X-CST
X-Ruxit-JS-Agent
X-Dns-Prefetch-Control
X-HW
X-ORACLE-DMS-RID
X-Dispatcher
X-Goog-Hash
X-Instart-Request-ID
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
X-DataStream-Cache-Status
Edge-Control
X-PC
X-TtlSet
X-Vname
X-DataDome
X-Px
X-VARITI-CCR
Service-Worker-Allowed
Verso
X-Mod-Pagespeed
X-MS-InvokeApp
X-Recruiting
X-D2id
X-Varnish-TTL
X-Cdn-Fetch
X-Use-Magma
X-Exp-Id
X-Kinja-Build
X-Kinja
X-Exp-Variant
SPRequestGuid
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Vcap-Request-Id
RTSS
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
TCN
DynaTrace
X-SharePointHealthScore
X-Navigation-Version
X-GitHub-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-RateLimit-Remaining
X-Middleton-Response
Response
X-Middleton-Display
Display
X-Sol
X-Powered-By-Plesk
X-Akam-SW-Version
X-B3-TraceId
MS-Author-Via
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Accept-Ch-Lifetime
Charset
X-Shield-Request-Id
Content-MD5
ServerID
X-Amz-Rid
AR-CACHE
AR-ATIME
AR-PoweredBy
Ar-Sid
X-Forwarded-Proto
Realpath
X-Trace
X-Powered-CMS
X-ESI
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
Nginx-Cache
X-Dw-Request-Base-Id
X-DynaTrace-JS-Agent
X-Version
X-Upstream
Fastly-Restarts
AR-Request-ID
X-Cached
Accept-Ch
X-Server-Name
Public-Key-Pins
X-Shard
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Pagespeed
Access-Control-Request-Method
Paypal-Debug-Id
X-MSEdge-Ref
X-Vcache
X-Goog-Storage-Class
SPRequestDuration
SPIisLatency
X-Client-IP
S
X-Debug
X-Grace
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Expires
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-Id
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Proxy
X-Amz-Meta-S3cmd-Attrs
X-Ezoic-Cdn
X-FastCGI-Cache
Accept-CH
X-N
X-Fastly-Request-ID
X-T
X-DIS-Request-ID
Front-End-Https
X-Amzn-Trace-Id
Arr-Disable-Session-Affinity
X-NF-Request-ID
X-Content-Type
MicrosoftSharePointTeamServices
X-XRDS-Location
X-Hits
X-B3-Sampled
X-Varnish-Age
X-FTR-Cache-Host
X-Ser
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-Acc-Meta-Resource-Type
X-Frontend
Alternate-Protocol
Fastcgi-Cache
X-Logged-In
Server-Name
X-Content-Digest
X-B3-Traceid
X-Correlation-Id
X-Srv
X-Pad
X-Forwarded-For
X-Node-Name
Nel
AMP-Access-Control-Allow-Source-Origin
X-Cache-Key
X-Request-Handler-Origin-Region
X-Microsite
Host
FilterID
Powered-By-ChinaCache
TP-L2-Cache
TP-Cache
X-Type
X-Kinsta-Cache
Healthy
X-Rid
X-User-Agent
X-LB-Cache
X-Server-ID
X-IPLB-Instance
X-Request-Received
X-Request-Processing-Time
Edge-Cache-Tag
X-AOL-HN
X-Debug-Info
X-F-Cache
X-Cached-By
X-Cache-2
X-GUploader-UploadID
X-Esi
X-Zen-Fury
Powered
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Revision
X-VCache
X-Hostname
X-HS-Hub-Id
X-HS-Content-Id
X-Cache-Age
X-Cache-Rule
X-Analytics
Backend-Timing
X-XRDS-LOCATION
X-Accel-Expires
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-AppVersion
X-Activity-Id
Surrogate-Key
X-Via-JSL
X-Az
VIX-Pulpo-Node
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
X-Content-Security-Policy-Report-Only
X-BCube-Filmed-By
X-Page-Id
X-Instance
X-RateLimit-Limit
X-Cluster
X-Varnish-Grace
X-FB-Debug
X-Amz-Replication-Status
X-Content-Options
X-Request-Guid
X-PHP-Backend
X-Jobs
X-Akamai-Edgescape
X-Content-Powered-By
X-Tumblr-Pixel-0
X-Tumblr-User
Source
X-Tumblr-Pixel
Cache-Status
X-App-Environment
X-TT
Server-Node
X-Framework
Cleartype
X-Forwarded-Host
X-B-Cache
X-Signature
Refresh
X-Fastcgi-Cache
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Server
X-Varnish-Hostname
Liferay-Portal
X-FW-Hash
Tracecode
DC
X-ATG-Version
WPE-Backend
Host-Header
Accept-Charset
X-Mobile
X-Cache-Operation
X-Cache-Control
Access-Control-Allow-Method
X-Cache-Action
X-Edge-Location
Fastcgi-Useragent
X-Drupal-Cache-Tags
Actual-Object-TTL
X-Time
Accept-CH-Lifetime
X-Cache-Hit
X-B
X-Accel-Buffering
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Mobile-URL
Payment
X-Response-Served-From
X-Hp-Webp
X-NWS-LOG-UUID
X-Whom
X-Storage
X-TX-ID
X-APP-VERSION
X-WebKit-CSP-Report-Only
X-Git-Hash
X-App-Server
X-Content-Age
Upgrade-Insecure-Requests
Cache
Cache-Tv-Group
X-Yottaa-Optimizations
X-WA-Info
X-TT-TIMESTAMP
X-Yottaa-Metrics
X-SS-Set-Cookie
Filters
X-Handled-By
X-Cacheable-TTL
X-UA-Device-Type
X-Status
X-GeoIP
Eomportal-Instance
X-Adobe-Content
X-Adobe-Loc
NGB
X-Tumblr-Pixel-1
Xserver
X-RequestSource
X-Tumblr-Pixel-2
X-ProcessESI
X-RemovedCookies
X-Geo-Country
Viewport
X-VG-WebCache
X-Cache-TTL
Cache-Tag
Retry-After
X-Ratelimit-Reset
Webserver
Datacenter
X-Cache-TTL-Remaining
X-FW-Dynamic
Server-Info
X-FB-TRIP-ID
X-Seen-By
X-TA-CDN-Provider
MS-CV
X-Cache-Enabled
X-Host-Name
X-Contextid
X-Oracle-Dms-Rid
X-Ratelimit-Limit
X-Presslabs-Stats
X-PressLabs-Stats
X-Origin-Server
Frame-Options
S-Cnection
X-Generated-By
From-Origin
X-RTag
Country
Ms-Operation-Id
X-Hyper-Cache
X-B3-Spanid
X-CF-Powered-By
X-Mode
X-ES-SERVER
X-Cache-Config
X-RN-RSRV
Machine
X-Path-Route
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
Load-Balancing
X-Routing-Service
X-Zipkin-Id
X-Access
X-Proxied
X-Hit
X-Tumblr-Pixel-3
X-Upstream-HT
X-MP-GENERATED-AT
Vix-Hermes-Req-Id
X-Labrador-Cache-Channel
X-Section
Cache-Key
X-Upstream-CT
X-Cache-Grace
X-Cache-Host
X-From
X-OCL
X-Human
X-PCL
X-Web-Node
X-Upgrade-Enabled
Now
X-Viewer-Country
X-RCS-CacheZone
X-Backend-Name
X-Loop
X-Varnish-Cache-Hits
X-TNCMS
X-Varnish-Server
Decoy-Debug-TTL
X-CCM
Mn-Server-Ip
Decoy-Debug-Status
X-Akamai-Request-ID
X-AWS-Id
X-Alternate-Cache-Key
ServedBy
Rt-Fastcgi-Cache
Decoy-Debug-Key
X-LJ-Flow-ID
X-VG-TLSProxy
X-ShardId
X-Origin-Response-Time
X-Magnolia-Registration
X-VWS-Id
X-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Varnish-Hits
X-L-Path
X-EIG-Tracking-Id
X-Region
X-Debug-Cache
X-Endurance-Cache-Level
X-Environment-Context
X-R9-Blue-Green-Version
OT-Force-Account-Verify
Cache-Name
X-Via-Fastly
X-Rule
X-S
GEO-INFO
DSUID
DB-Nickname
Mail-Subject
X-Rendered-As
We-Hiring
X-Hosted-By
X-JoinUs
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated
X-FC-Vary-Parameters
Akamai-GRN
X-Timing-Wait
X-Proxy-Build
X-Xfnlog-Site
X-Cluster-Node
X-Proto
X-Drupal-Cache-Contexts
X-Device-Type
X-NCache
Uber-Trace-Id
Release
X-Guploader-Uploadid
X-Trace-Id
X-Nginx-Cache
X-Site-Version
X-Locale
X-ProxyCache-Status
Cteonnt-Length
X-BYPASS-REASON
X-Redis-Cache
X-ProxyCache-Key
X-Www-Served-By
X-VCT
Version
X-Load-Cache
NGX
SRV
X-UUID
ProcessTime
X-Platform-Server
X-Request-Time
X-IP
X-Time-Microsecs
Time
X-Cache-NE
X-Daa-Tunnel
X-NewRelic-App-Data
Azure-InstanceId
Azure-SiteName
Azure-SlotName
X-Via-CDN
X-ECACHE
S-Rt
X-EdgeConnect-Cache-Status
Azure-RegionName
X-FW-Version
Azure-Version
X-Wix-Request-Id
X-Origin
X-Dc
X-MServer
X-GEO
TWC-Device-Class
Webcakes-Region
TWC-Privacy
TWC-GeoIP-Country
X-Origin-Hint
TWC-Locale-Group
X-Rocket-Nginx-Bypass
TWC-Connection-Speed
TWC-GeoIP-LatLong
Webcakes-App-Version
X-Hl-Ver
Webcakes-App-Name
Property-Id
X-Cache-Remote
X-FireWall-Port
X-Vgn-Hpd-Reason
NtCoent-Length
X-No-Session
X-ServerID
X-Akamai-Request-ID2
CACHE
X-IPS-LoggedIn
X-Proxy
Origin
X-Litespeed-Cache
X-HTML-Minification-Powered-By
X-Akamai-Transformed
X-Real-IP
X-ApacheServer
Odigeo-Trace-Id
X-Distributor
X-PERF
Fastly-SSL
X-CS
X-Format
X-CDN-Forward
X-Oneagent-Js-Injection
X-Cache-Server
X-Cache-Backend
Ec-Rule-Version
L5d-Success-Class
X-RateLimit-Reset
X-Unique-ID
X-Microcachable
X-UA
X-Pubstack
Access-Control-Request-Headers
Cache-Tags
X-Compress-Hint
Served-By
Hostname
X-UnsetCookies
Origin-Cache-Control
Origin-Edge-Control
Fastcgi-X-Cache-Version
X-Webkit-Csp
X-Tb
LB
X-SERVER-NAME
IBM-Web2-Location
X-Grey
X-Cache-Category-Id
X-Varnish-Cacheable
Accept-Language
X-B3-Parentspanid
Backend-Name
Cache-Cookie-Set-Lfrom
BehaviorPad-Version
MD5-Digest
GEO-REGION-INFO
Cache-Cookie-Set-From
Cache-Prefix
Cache-Cookie-Set-Idcheck
AsisCache
Fastly-SWR
Fastly-SIE
Meta-Geo-Continent
A
ServerName
Cross-Origin-Window-Policy
Arc-Country
Cdn-Request-Time
Cdn-Host
Fly-Cache
Content-Script-Type
Content-Style-Type
Fly-Request-Id
X-Application
X-PAYTM-SRV-ID
X-Org
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Request-UUID
X-Region-Sid
X-NU-AKA-ACS-Version
X-Is-Bot
X-External-Request-Id
X-Edge-Server
X-G
X-IN-APIGATEWAY
X-Internal-Host
X-Instart-Info
X-Rewrite-Enabled
X-Rojux
X-VG-WebServer
X-Twitter-Response-Tags
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Worker
X-Trv-Group
X-Transaction
X-S-Maxage
X-S-Cookie
X-ScT
X-Server-Time
X-SRCache-Key
X-DPWN-IS-SECURE
X-Developer
VivaBuild
Viewtype
X-A
X-A-Dam
X-A-Dgt
X-A-Dcw
Server-ID
Rt-Proxy-Cache
Proxy-Firewall
Node
Rendered-Blocks
Request-Country
Request-Time
Request-EU
X-A-Wwc
X-Accel-Expires-Debug
X-Connection-Hash
X-Cluster-Name
X-D
X-Date
X-Detected-As
X-Destination
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-AIR-PT
X-Aed
X-App-Name
X-ARC
X-B-Cookie
Mobile-Detection-Method
X-A-Ccd
X-BACKEND-TTL
X-Edge
Proxy-Connection
X-NC
X-ElasticPress-Search
RNT-Time
Resin-Trace
W
X-PHP-Host
Server-Int
X-Request-URI
Section-Io-Cache
True-Client-Country-4JS
On-Server
Ha-Gx-Prefs
X-ServiceProvider
Gh-Request-Id
HA-Ipaddr
Is-Eu
X-NX-Host
X-Nc
Memcached
Platform
X-Location
X-Core-Mission
X-Clientip
X-CGP
X-Cdn-Srv
X-Powered-By-Defense
X-Eu-Site
X-Developers
X-Epic-Correlation-Id
X-Debug-Log
X-Debug-Cookies
X-Cdn-Origin
X-Cache-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Level-Front-Cache
X-Skip-Cache
X-GeoIP-Country-Code
X-Backend-State
X-Generated-On
X-Cache-Bucket
X-Geo-Header
X-Nginx-Cache-Key
RNT-Machine
Apple-News-Services-Host
Apple-News-Services-Handled
Countrycode
X-Sn-Servicetimems
Esi-Enabled
X-Varnish-Url
AKAMAI
X-C
Adler-Geo
Content-Disposition
X-Variation
Apple-News-Services-Parsed-Url
X-We-Are-Hiring
X-SVT-ORM-VERSION
Apple-News-Services-Request-Url
X-SVT-ORM-RULES
X-Ua
User-Cache-Control
X-Wikidot-Static-Cache
X-Cache-FS-Status
V-Age
X-Hnp-Log
UCS
X-CDN-Cache
X-Auto-Login
X-Cache-Info
CDCHOST
X-Amz-Meta-Cache-Control
X-Hash
Web-Mar-Node
X-Wikidot-Backend
X-Key
X-LI-UUID
X-LI-Proto
X-Li-Pop
X-Method
X-WebServer
X-Generation-Time
X-Li-Fabric
X-Irp-Debug
X-Block-Status
SS
X-WADP-Cache
X-Gannett-Site-Version
X-Via-NSCOPI
Fastly-Soc-X-Request-Id
X-Fastly-Cache
X-Response-By
PFcat
X-Device-Os
X-SD-PageType
X-TH-Server
X-Server-IP
X-Servername
IsBot
REQUESTUUID
X-Secret
X-Served-From
X-Distil-CS
X-Fetched-On
X-Clara-WADP
X-Dispatcher-Server
X-Processor
SD-X-WS
X-SIPLIST1
X-Gen-Mode
Server-Host
X-Qloud-Router
X-Reboot
X-Request-Start
X-Cms-Context
Country-Code
X-Reqid
X-Dispatch
X-Amzn-Remapped-Content-Length
N-Cache
X-Bip
X-Azure-Ref-OriginShield
X-FPC
X-GeoIP-City
X-Crawler
X-BBXSRF
Wxu-Next-Commit
X-Via-SSL
X-Azure-Ref
X-VServer
X-Owner
Thinkindot-CacheControl
X-Via-Edge
X-Thinkindot-L3
L
Powered-By
Pramga
X-Release
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Matched-Rule
Wxu-Next-Region
X-Webstats-RespID
X-Swa-Ws
GW-Server
Wxu-Next-Hostname
X-Origin-Date
Selected-Fe
Heartbleed
X-Origin-Expires
Who
X-Thanos
Mime-Version
X-TrackingId
CF-IPCountry
X-Parent-Response-Time
X-Proxy-Upstream
X-CUA
X-VC-Cache
X-Proxy-Cache-Status
X-Varnish-Ttl
Kp-EeAlive
X-FE
X-OVcl-Cache
X-OVcl
X-ND-Cache
X-CLOUD-TRACE-CONTEXT
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Protected-By
X-Pf-Uncompressing
X-Ratelimit-Remaining
User-Agent
X-LAGOON
Magicmarker
PageSpeed
X-Varnish-Beresp-Ttl
Memory
Pragrma
X-Fstrz
X-Origin-TTL
X-Origin-CC
X-Flog
X-Hello
X-ABtesting
X-Page-Type
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Be
X-Ruxit-Js-Agent
Pagetype
X-B3-SpanId
X-URL
X-Cdn-Forward
X-User
X-Phone
X-Geo
X-Ttl
X-Generated-In
X-Backend-Host
X-Core-Value
X-IN-WAF
X-Backend-Url
X-Dynatrace-Js-Agent
X-Cache-Ttl
X-Zone
X-DC
X-Backend-TTL
X-MSEdge-Features
X-Up
X-MSEdge-Flight
X-Tt-Trace-Tag
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Newrelic-Synthetics
X-GoCache-CacheStatus
X-Soup
X-Debug-Cache-Store
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Birta-Cache-Post
X-Birta-Served
X-GRACE
X-TT-LOGID
Cdn
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Servedbyhost
X-Oss-Server-Time
X-Oss-Storage-Class
X-Varnish-IP
X-Check-Cacheable
X-Info
Selected-FE
GeoIp-Country-Code
Geoip-Latitude
SN
Geoip-City
HitType
X-MID
X-SayCDN-TTL
X-Old-Content-Length
X-Say-Cacheable
Cache-Hits
X-HS-Status
X-Say-TTL
X-Real-Ip
X-ZONE
X-Mid
X-Vcl-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Aicache-OS
X-VCL-Version
X-Datadome
X-Akamai-SSL-Client-Sid
Amp-Access-Control-Allow-Source-Origin
CF-Cached-On
X-Refresh
X-Agile-Age
X-Agile
FSS-Proxy
FSS-Cache
X-Agile-Id
X-Cache-Debug
X-App-Version
X-CSRF-TOKEN
X-Source
Inserted-Into-Cache-At
X-Node-Id
X-ServedByHost
Srv
GeoIP-Country-Code
Fastly-Backend-Name
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Cache-Time
X-Web-Server
X-Bc
GeoIP-Latitude
Server-Cache-Control
HostName
Ajk
GeoIP-City
WZWS-RAY
X-IN-APIGATEWAYSSL
X-Logtrace-Id
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Varnish-Authentication
Server-Surrogate-Control
X-EC-Lua
X-BC
RequestId
X-APP
XServer
X-UPSTREAM-Address
X-COUNTRY
X-Via-Ucdn
X-Nananana
X-CACHE-KEY
X-CSRF-Token
X-FORWARDED-FOR
X-Wa
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Cf-Ipcountry
X-ECache
X-TIME
X-NWS-UUID-VERIFY
Ohc-Cache-HIT
X-Proxy-Cacherz
Xkeyrz
X-WR-MODIFICATION
Group
Ohc-File-Size
X-Varnish-Beresp-TTL
WebServer
X-Dynatrace
HTTPS
T-Server
X-BE
X-LiteSpeed-Cache-Control
Backend
X-LB-ID
PICS-Label
X-Unique-Id
Xkeynj
X-SRV
URI
X-SN
Get-Access-Time
Is-Session-Tracking
X-Fastly-Country-Code
X-Render-Time
X-PAGE-TYPE
X-Cache-Tag
X-GDPR
Www
X-PJAX-URL
X-Cache-Miss-From
Lb
X-Sedo-Request-Id
X-Micro-Cache
X-Instart-Isnd
X-Request-Url
X-Requestid
X-Edge-IP
X-MCACHE
MIME-Version
Dynatrace
Requestid
X-Cache-Expires
Host-ID
Cneonction
X-Uri
Pics-Label
X-Fastly-Backend-Reqs
X-Pjax-Url
X-Policy
CDN
DataCenter
X-Correlation-ID
Xet-Cookie
SID
X-Vct
X-Swift-Error
X-PF-Uncompressing
X-Apw-Access-Token
X-Apw-Access-Action
X-Lb-Id
X-Apw-Hits
X-Apw-Access-Object
X-NGINX-Cache
X-Dw-Trace-Id
X-WA
Correlation-Id
X-Ecache
X-Cdn-Request-ID
X-Fpc
Cache-Provider
X-Varnish-Action
X-Service
X-Cf-Powered-By
Epwk-Cache
X-Newrelic-App-Data
X-NGENIX-Cache
X-Serial
Warning
X-Bug-Bounty
Lfy
X-Akamai-ERPolicy
X-WPE-Loopback-Upstream-Addr
Sid
RequestUuid
Fastcgi-X-Cache
X-Akamai-ERRuleID
X-Html-Edge-Cache
X-Fastly-Cache-Hits
X-DW
X-ServerName
X-RPM
X-RPS
X-DSS
X-DI
X-Flow-Id
X-Page-Impression-Id
X-Zalando-Child-Request-Id
X-DB
X-RSL