Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
Alt-Svc
X-Adblock-Key
X-Drupal-Cache
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
Timing-Allow-Origin
X-Iinfo
Content-Encoding
X-Content-Security-Policy
X-Buckets
P3p
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
EagleId
X-Server-Powered-By
X-UA-Device
X-Varnish-Cache
Request-Context
X-Nginx-Cache-Status
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Host
X-Rq
Report-To
X-Ac
X-Node
Content-Location
X-OneAgent-JS-Injection
X-Request-ID
X-Cnection
X-Backend-Server
X-Response-Time
X-Cloud-Trace-Context
X-Origin-Cache
X-Application-Context
X-Readtime
Request-Id
Allow
EagleEye-TraceId
Surrogate-Control
X-Country
X-ORACLE-DMS-ECID
X-DynaTrace
X-Cdn
X-Cache-Lookup
X-Vhost
X-TTL
Pinterest-Generated-By
X-Url
X-Rack-Cache
X-Ua-Compatible
X-Clacks-Overhead
X-Origin-Upstream-Status
NEL
X-FTR-Request-ID
X-Ruxit-JS-Agent
X-Dns-Prefetch-Control
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-CST
X-HW
X-ORACLE-DMS-RID
X-Dispatcher
X-Goog-Hash
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-DataStream-Cache-Status
Edge-Control
X-PC
X-TtlSet
X-Vname
X-DataDome
X-Px
X-VARITI-CCR
Service-Worker-Allowed
Verso
X-Mod-Pagespeed
X-MS-InvokeApp
X-Recruiting
X-D2id
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Exp-Variant
X-Varnish-TTL
X-Exp-Id
SPRequestGuid
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
RTSS
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
TCN
DynaTrace
X-SharePointHealthScore
X-Navigation-Version
X-GitHub-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Middleton-Display
X-Sol
X-Middleton-Response
Response
Display
X-Akam-SW-Version
X-Powered-By-Plesk
X-RateLimit-Remaining
MS-Author-Via
X-B3-TraceId
Charset
X-ESI
X-Shield-Request-Id
Content-MD5
ServerID
X-Amz-Rid
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
AR-CACHE
AR-ATIME
AR-PoweredBy
Ar-Sid
X-Forwarded-Proto
X-Trace
Realpath
X-Powered-CMS
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
Nginx-Cache
X-Goog-Stored-Content-Encoding
Accept-Ch-Lifetime
X-Upstream
X-Dw-Request-Base-Id
Fastly-Restarts
X-Version
X-Cached
Public-Key-Pins
AR-Request-ID
X-Shard
X-Server-Name
X-DynaTrace-JS-Agent
Accept-Ch
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Pagespeed
Access-Control-Request-Method
X-MSEdge-Ref
Paypal-Debug-Id
X-Goog-Storage-Class
X-Grace
SPIisLatency
X-Client-IP
SPRequestDuration
S
X-Debug
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
Accept-CH
X-FTR-Backend
X-Country-Code-Real
X-FTR-Expires
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Balancer
X-Id
X-Pinterest-Rid
X-Amz-Meta-S3cmd-Attrs
X-Ezoic-Cdn
Pinterest-Version
X-Upstream-Proxy
X-N
X-FastCGI-Cache
X-Vcache
X-Fastly-Request-ID
X-T
X-DIS-Request-ID
X-Amzn-Trace-Id
Front-End-Https
Arr-Disable-Session-Affinity
X-NF-Request-ID
X-Content-Type
MicrosoftSharePointTeamServices
X-Hits
X-B3-Sampled
X-XRDS-Location
X-B3-Traceid
X-FTR-Cache-Host
X-Ser
X-Varnish-Age
X-Frontend
X-Mobile-Rewrite
Arc-Version
Fastcgi-Cache
PB-PID
PB-RID
X-Acc-Meta-Resource-Type
X-Logged-In
Alternate-Protocol
Server-Name
X-Content-Digest
X-Correlation-Id
X-Srv
X-Cache-Key
X-Pad
Nel
X-Node-Name
X-VCache
X-Forwarded-For
AMP-Access-Control-Allow-Source-Origin
X-Request-Handler-Origin-Region
X-Microsite
FilterID
Powered-By-ChinaCache
Host
TP-L2-Cache
TP-Cache
X-Type
X-User-Agent
Healthy
X-Rid
X-Kinsta-Cache
X-LB-Cache
X-Request-Received
X-IPLB-Instance
X-Request-Processing-Time
Edge-Cache-Tag
X-F-Cache
X-AOL-HN
X-Debug-Info
X-Cache-2
X-Zen-Fury
X-Amzn-RequestId
X-Amz-Apigw-Id
Powered
X-Cached-By
X-Revision
X-GUploader-UploadID
X-XRDS-LOCATION
X-Hostname
X-Analytics
X-HS-Content-Id
Backend-Timing
X-HS-Hub-Id
X-Cache-Age
X-Cache-Rule
X-Esi
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Accel-Expires
X-Az
X-Activity-Id
X-Via-JSL
X-AppVersion
Surrogate-Key
X-Content-Security-Policy-Report-Only
VIX-Pulpo-Upstream-Status
X-Varnish-Backend
VIX-Pulpo-Node
X-Content-Options
X-BCube-Filmed-By
X-Instance
X-Page-Id
X-Varnish-Grace
X-FB-Debug
X-Cluster
X-Amz-Replication-Status
X-Tumblr-User
X-Content-Powered-By
X-PHP-Backend
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Akamai-Edgescape
X-Request-Guid
X-Jobs
Cache-Status
Source
Server-Node
X-App-Environment
X-TT
X-Fastcgi-Cache
X-RateLimit-Limit
X-Signature
Refresh
X-B-Cache
X-Forwarded-Host
Cleartype
X-Framework
Accept-CH-Lifetime
Liferay-Portal
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Type
X-Varnish-Hostname
X-ATG-Version
DC
Tracecode
Host-Header
WPE-Backend
Accept-Charset
Fastcgi-Useragent
X-APP-VERSION
Access-Control-Allow-Method
X-Cache-Operation
X-Mobile
X-Edge-Location
X-Cache-Action
X-Cache-Control
X-Drupal-Cache-Tags
X-Time
X-Cache-Hit
Actual-Object-TTL
X-B
X-Accel-Buffering
X-Mobile-URL
X-Response-Served-From
X-Erf-Bev-Bev-Is-Generated
X-Hp-Webp
X-Erf-Bev-Bev
Payment
X-Storage
X-TX-ID
X-Whom
X-SS-Set-Cookie
X-WebKit-CSP-Report-Only
X-NWS-LOG-UUID
X-Content-Age
X-WA-Info
X-App-Server
X-Yottaa-Optimizations
X-Git-Hash
X-Yottaa-Metrics
Upgrade-Insecure-Requests
X-TT-TIMESTAMP
Cache-Tv-Group
X-Handled-By
Filters
X-UA-Device-Type
NGB
X-Cacheable-TTL
X-GeoIP
X-Adobe-Loc
X-Tumblr-Pixel-2
Eomportal-Instance
X-Tumblr-Pixel-1
X-Status
X-Adobe-Content
X-ProcessESI
X-RemovedCookies
X-RequestSource
X-Geo-Country
Cache-Tag
Viewport
X-VG-WebCache
Xserver
Cache
X-Cache-TTL
Retry-After
X-Presslabs-Stats
Webserver
X-FW-Dynamic
X-Server-ID
X-Cache-TTL-Remaining
X-TA-CDN-Provider
Datacenter
Server-Info
X-Seen-By
X-FB-TRIP-ID
MS-CV
X-Cache-Enabled
X-Oracle-Dms-Rid
X-Ratelimit-Limit
X-Ratelimit-Reset
X-Host-Name
X-Contextid
X-Origin-Server
Frame-Options
X-Generated-By
X-B3-Spanid
X-RTag
From-Origin
X-Hyper-Cache
Ms-Operation-Id
S-Cnection
Country
X-Mode
X-CF-Powered-By
X-ES-SERVER
X-Cache-Config
Machine
X-Path-Route
Load-Balancing
Meta-Geo
X-Tumblr-Pixel-3
X-Cache-Var
X-Cache-Var-Map
X-RN-RSRV
X-Proxied
Cache-Key
X-Routing-Service
X-MP-GENERATED-AT
X-Access
X-Labrador-Cache-Channel
X-Zipkin-Id
X-Cache-Grace
X-Upstream-HT
X-Section
X-Hit
Vix-Hermes-Req-Id
X-Upstream-CT
Decoy-Debug-TTL
Decoy-Debug-Key
X-From
X-Cache-Host
X-Backend-Name
Now
X-Human
X-Varnish-Server
X-Viewer-Country
X-Web-Node
X-Varnish-Cache-Hits
X-Guploader-Uploadid
X-PCL
X-TNCMS
X-Upgrade-Enabled
X-Loop
X-OCL
Decoy-Debug-Status
X-RCS-CacheZone
X-Alternate-Cache-Key
X-Akamai-Request-ID
X-AWS-Id
X-Rule
X-Origin-Response-Time
X-Via-Fastly
ServedBy
Rt-Fastcgi-Cache
GEO-INFO
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Region
X-ShopId
Mn-Server-Ip
X-VWS-Id
X-VG-TLSProxy
X-Endurance-Cache-Level
X-R9-Blue-Green-Version
X-CCM
X-LJ-Flow-ID
X-ShardId
X-EIG-Tracking-Id
X-Debug-Cache
X-Environment-Context
X-Drupal-Cache-Contexts
X-Magnolia-Registration
X-L-Path
X-Proto
DSUID
X-Timing-Wait
Mail-Subject
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cluster-Node
X-Xfnlog-Site
X-FC-Vary-Parameters
X-JoinUs
X-NCache
X-Hosted-By
X-S
X-Rendered-As
X-Proxy-Build
We-Hiring
X-Generated
OT-Force-Account-Verify
X-PressLabs-Stats
SRV
X-Varnish-Hits
DB-Nickname
Akamai-GRN
Cache-Name
Uber-Trace-Id
X-Device-Type
Release
Version
X-Trace-Id
X-Locale
X-Site-Version
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Www-Served-By
Cteonnt-Length
X-NewRelic-App-Data
X-Load-Cache
X-VCT
CACHE
ProcessTime
X-Request-Time
NGX
X-Redis-Cache
X-Nginx-Cache
X-Platform-Server
X-Dc
X-Time-Microsecs
X-IP
X-UUID
Time
Azure-SlotName
Azure-SiteName
Azure-Version
S-Rt
X-Origin
X-FW-Version
Azure-RegionName
X-Wix-Request-Id
X-Via-CDN
Azure-InstanceId
X-EdgeConnect-Cache-Status
X-Cache-NE
X-ECACHE
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
Property-Id
X-Origin-Hint
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Device-Class
X-MServer
TWC-Privacy
X-Akamai-Request-ID2
X-Hl-Ver
X-GEO
NtCoent-Length
X-Rocket-Nginx-Bypass
X-Daa-Tunnel
X-RateLimit-Reset
X-No-Session
X-CDN-Forward
X-FireWall-Port
X-Proxy
X-ServerID
X-Vgn-Hpd-Reason
X-IPS-LoggedIn
X-Cache-Remote
X-UA
Origin
X-HTML-Minification-Powered-By
X-Oneagent-Js-Injection
X-Akamai-Transformed
X-Distributor
X-PERF
X-ApacheServer
Odigeo-Trace-Id
X-Cache-Server
X-CS
X-Format
Fastly-SSL
Ec-Rule-Version
LB
X-Real-IP
X-Webkit-Csp
Cache-Tags
L5d-Success-Class
Access-Control-Request-Headers
X-Unique-ID
X-Pubstack
X-Cache-Backend
X-Microcachable
X-UnsetCookies
X-SERVER-NAME
Served-By
Origin-Edge-Control
Hostname
X-Compress-Hint
Accept-Language
Origin-Cache-Control
X-Tb
X-BACKEND-TTL
Fastcgi-X-Cache-Version
X-Varnish-Cacheable
X-Grey
X-Cache-Category-Id
IBM-Web2-Location
X-NC
Fly-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
BehaviorPad-Version
Proxy-Firewall
MD5-Digest
GEO-REGION-INFO
Fly-Request-Id
Node
Mobile-Detection-Method
Content-Script-Type
Cdn-Request-Time
Content-Style-Type
Fastly-SWR
Fastly-SIE
Cdn-Host
Meta-Geo-Continent
Cross-Origin-Window-Policy
Cache-Cookie-Set-Lfrom
Cache-Prefix
Arc-Country
AsisCache
X-CF-Lambda-Version
X-PAYTM-SRV-ID
X-Org
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Request-UUID
X-Region-Sid
X-NU-AKA-ACS-Version
X-Is-Bot
X-External-Request-Id
X-Edge-Server
X-G
X-IN-APIGATEWAY
X-Internal-Host
X-Instart-Info
X-Rewrite-Enabled
X-Rojux
X-VG-WebServer
X-Varnish-Url
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Worker
X-Twitter-Response-Tags
X-Trv-Group
X-S-Maxage
X-S-Cookie
X-ScT
X-Server-Time
X-Transaction
X-SRCache-Key
X-DPWN-IS-SECURE
X-Developer
X-A-Dcw
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-Aed
X-Accel-Expires-Debug
X-A
VivaBuild
Request-EU
Request-Country
Request-Time
Rt-Proxy-Cache
Viewtype
Server-ID
X-AIR-PT
X-App-Name
X-Connection-Hash
X-Cluster-Name
X-D
X-Date
X-Detected-As
X-Destination
A
X-CF-Lambda-Fn
X-ARC
X-Application
X-B-Cookie
X-Cache-Bucket
X-Cdn-Srv
Rendered-Blocks
X-A-Dam
Proxy-Connection
Backend-Name
X-Edge
X-B3-Parentspanid
ServerName
X-ElasticPress-Search
Ha-Gx-Prefs
X-HS-Cache-Config
Platform
X-GeoIP-Country-Code
RNT-Machine
On-Server
Resin-Trace
HA-Ipaddr
X-Nginx-Cache-Key
Is-Eu
X-PHP-Host
RNT-Time
X-NX-Host
Memcached
X-HS-Combine-CSS
Section-Io-Cache
W
X-CGP
X-Clientip
X-Cdn-Origin
X-Cache-Info
X-Backend-State
X-Cache-Id
X-Core-Mission
True-Client-Country-4JS
X-Epic-Correlation-Id
Gh-Request-Id
X-Eu-Site
Server-Int
X-Developers
X-Debug-Cookies
X-Debug-Log
X-Fastly-Cache
X-Location
X-ServiceProvider
X-C
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Adler-Geo
Apple-News-Services-Handled
Apple-News-Services-Request-Url
Content-Disposition
X-We-Are-Hiring
X-Variation
X-Sn-Servicetimems
X-Skip-Cache
REQUESTUUID
AKAMAI
X-Generated-On
Countrycode
X-Geo-Header
X-SVT-ORM-RULES
Esi-Enabled
X-Request-URI
X-Level-Front-Cache
X-SVT-ORM-VERSION
X-Powered-By-Defense
X-Amzn-Remapped-Content-Length
X-Wikidot-Static-Cache
X-Distil-CS
X-WebServer
X-Auto-Login
X-Dispatcher-Server
X-Wikidot-Backend
X-Cache-FS-Status
X-Cms-Context
X-WADP-Cache
X-Clara-WADP
X-CDN-Cache
X-Method
X-BBXSRF
X-Block-Status
X-Dispatch
X-Gannett-Site-Version
X-Amz-Meta-Cache-Control
X-Secret
X-Server-IP
X-Servername
X-LI-UUID
X-SD-PageType
X-Nc
X-Reboot
X-Reqid
X-Qloud-Router
X-Processor
X-Response-By
X-LI-Proto
X-Li-Pop
X-Gen-Mode
X-Generation-Time
X-Request-Start
X-FPC
X-Fetched-On
X-GeoIP-City
X-Hash
X-Key
X-Li-Fabric
X-Irp-Debug
X-SIPLIST1
X-Hnp-Log
X-TH-Server
X-Device-Os
SS
CDCHOST
Fastly-Soc-X-Request-Id
User-Cache-Control
UCS
Country-Code
Selected-Fe
Web-Mar-Node
IsBot
X-Via-NSCOPI
V-Age
Server-Host
PFcat
SD-X-WS
N-Cache
GW-Server
X-Release
X-Thanos
X-TrackingId
X-Origin-Expires
Thinkindot-CacheControl
X-Matched-Rule
Powered-By
Pramga
X-Origin-Date
X-Served-From
Heartbleed
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Crawler
X-Swa-Ws
X-Thinkindot-L3
X-Bip
X-Proxy-Upstream
X-Azure-Ref-OriginShield
X-Owner
X-VC-Cache
X-Via-Edge
L
X-Webstats-RespID
X-VServer
X-Via-SSL
CF-IPCountry
X-Azure-Ref
X-Proxy-Cache-Status
Wxu-Next-Hostname
Wxu-Next-Commit
Who
Wxu-Next-Region
X-Varnish-Ttl
X-CLOUD-TRACE-CONTEXT
X-OVcl
X-Pf-Uncompressing
X-OVcl-Cache
X-FE
X-CUA
Kp-EeAlive
X-Urbn-Context-Path
X-Parent-Response-Time
Locale
X-Urbn-Site-Id
X-ND-Cache
Magicmarker
Mime-Version
X-Ua
PageSpeed
X-Ratelimit-Remaining
X-Dynatrace-Js-Agent
X-Varnish-Beresp-Ttl
X-Protected-By
User-Agent
X-LAGOON
Pragrma
X-Fstrz
X-ABtesting
Memory
X-Flog
X-Hello
X-Be
X-Origin-CC
X-Origin-TTL
Pagetype
X-Planisys-CDN-TTL
X-Page-Type
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-URL
X-Ttl
X-Generated-In
X-Backend-Host
X-User
X-Backend-Url
X-Geo
X-Cache-Ttl
X-Zone
X-Core-Value
X-GoCache-CacheStatus
X-Up
X-Newrelic-Synthetics
X-Tt-Trace-Tag
X-Phone
X-MSEdge-Flight
X-IN-WAF
X-MSEdge-Features
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Debug-Cache-Expiry
X-B3-SpanId
X-Backend-TTL
X-Soup
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-DC
X-Oss-Request-Id
Geoip-Latitude
X-Oss-Storage-Class
Geoip-City
X-Oss-Server-Time
X-Oss-Object-Type
X-TT-LOGID
X-Oss-Hash-Crc64ecma
X-Cdn-Forward
X-Check-Cacheable
GeoIp-Country-Code
X-Litespeed-Cache
X-Birta-Served
X-Servedbyhost
X-Birta-Cache-Post
X-Varnish-IP
X-Info
X-Real-Ip
Cache-Hits
X-Old-Content-Length
X-ZONE
X-Say-Cacheable
SN
X-SayCDN-TTL
X-Say-TTL
Cdn
Selected-FE
X-Mid
X-MID
HitType
X-Datadome
X-HS-Status
X-VCL-Version
X-Ruxit-Js-Agent
X-Akamai-SSL-Client-Sid
X-GRACE
Amp-Access-Control-Allow-Source-Origin
FSS-Proxy
X-Vcl-Version
X-Aicache-OS
FSS-Cache
X-CSRF-TOKEN
XServer
X-Amzn-Remapped-Connection
X-ServedByHost
Inserted-Into-Cache-At
X-Node-Id
X-Amzn-Remapped-Date
Fastly-Backend-Name
X-Refresh
X-Cache-Time
CF-Cached-On
X-Agile-Id
X-Agile-Age
X-Agile
X-Cache-Debug
X-Tb-Optimization-Total-Bytes-Saved
X-Bc
X-Source
X-Contensis-Viewer-Groups
Server-Cache-Control
HostName
X-Varnish-Authentication
Server-Surrogate-Control
X-Cache-ASPX
X-IN-APIGATEWAYSSL
X-Logtrace-Id
Ajk
WZWS-RAY
X-EC-Lua
X-BC
RequestId
X-Via-Ucdn
X-Web-Server
X-COUNTRY
GeoIP-Country-Code
X-UPSTREAM-Address
Srv
X-Nananana
X-FORWARDED-FOR
X-CSRF-Token
GeoIP-Latitude
X-RateLimit-Limit-Second
GeoIP-City
X-RateLimit-Remaining-Second
X-APP
X-Wa
X-App-Version
X-TIME
X-NWS-UUID-VERIFY
X-Proxy-Cacherz
X-ECache
Xkeyrz
X-WR-MODIFICATION
WebServer
Group
X-Varnish-Beresp-TTL
Cf-Ipcountry
PICS-Label
X-PJAX-URL
T-Server
Ohc-File-Size
Ohc-Cache-HIT
X-LiteSpeed-Cache-Control
Xkeynj
X-Fastly-Country-Code
URI
X-BE
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
HTTPS
X-Unique-Id
X-GDPR
X-Micro-Cache
X-Render-Time
X-PAGE-TYPE
X-LB-ID
X-SRV
MIME-Version
Get-Access-Time
Is-Session-Tracking
X-Cache-Tag
X-CACHE-KEY
DataCenter
X-SN
X-Cache-Miss-From
X-Sedo-Request-Id
CDN
Backend
Www
X-Edge-IP
X-Requestid
Dynatrace
X-MCACHE
X-Uri
SID
X-Instart-Isnd
X-NGINX-Cache
X-Request-Url
X-Policy
X-Fastly-Backend-Reqs
Xet-Cookie
Lb
X-Apw-Access-Object
X-Vct
Pics-Label
X-Apw-Access-Action
X-Pjax-Url
X-Swift-Error
X-Apw-Hits
X-Lb-Id
X-Apw-Access-Token
X-Cache-Expires
Requestid
Cneonction
Host-ID
X-Dw-Trace-Id
Cache-Provider
X-Ecache
X-Cdn-Request-ID
X-Cf-Powered-By
Correlation-Id
X-Service
X-WA
X-Newrelic-App-Data
X-Html-Edge-Cache
X-Akamai-ERPolicy
X-Var-Ttl
X-Bug-Bounty
FNAC-ModuleRouting
X-Akamai-ERRuleID
X-Serial
Warning
Lfy
X-RPM
X-Fastly-Cache-Hits
X-DB
X-DI
X-WPE-Loopback-Upstream-Addr
X-Flow-Id
X-Page-Impression-Id
X-Zalando-Child-Request-Id
X-DSS
X-DW
X-Varnish-Action
X-ServerName
X-Fpc
Epwk-Cache
X-RPS
X-RSL
X-PF-Uncompressing