Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
Alt-Svc
X-Adblock-Key
X-Drupal-Cache
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
Timing-Allow-Origin
X-Iinfo
Content-Encoding
X-Content-Security-Policy
X-Buckets
P3p
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-CDN
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
EagleId
X-Server-Powered-By
X-UA-Device
X-Varnish-Cache
Request-Context
X-Nginx-Cache-Status
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Host
X-Rq
Report-To
X-Ac
X-Node
Content-Location
X-Request-ID
X-Cnection
X-Backend-Server
X-Response-Time
X-OneAgent-JS-Injection
X-Cloud-Trace-Context
X-Origin-Cache
X-Application-Context
X-Readtime
Request-Id
Allow
X-Dns-Prefetch-Control
EagleEye-TraceId
Surrogate-Control
X-Country
X-ORACLE-DMS-ECID
X-DynaTrace
X-Cdn
X-Cache-Lookup
X-Vhost
X-TTL
Pinterest-Generated-By
X-Url
X-Ua-Compatible
X-Rack-Cache
X-Clacks-Overhead
X-Origin-Upstream-Status
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-CST
X-Ruxit-JS-Agent
X-HW
X-ORACLE-DMS-RID
X-Dispatcher
X-Goog-Hash
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
X-DataStream-Cache-Status
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Px
X-DataDome
X-VARITI-CCR
Service-Worker-Allowed
Verso
X-Mod-Pagespeed
X-MS-InvokeApp
X-Recruiting
X-D2id
X-Exp-Variant
X-Kinja-Build
X-Varnish-TTL
X-Kinja-Server
SPRequestGuid
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
RTSS
X-Vcap-Request-Id
DynaTrace
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
TCN
X-SharePointHealthScore
X-Navigation-Version
X-B3-TraceId
X-SRCache-Fetch-Status
X-GitHub-Request-Id
X-SRCache-Store-Status
X-Middleton-Display
X-Sol
X-Middleton-Response
Display
Response
X-Akam-SW-Version
X-Powered-By-Plesk
MS-Author-Via
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Charset
X-RateLimit-Remaining
X-Shield-Request-Id
X-ESI
Content-MD5
ServerID
X-Amz-Rid
X-Forwarded-Proto
Ar-Sid
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Trace
Realpath
X-Powered-CMS
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Nginx-Cache
Accept-Ch-Lifetime
X-DynaTrace-JS-Agent
X-Upstream
X-Dw-Request-Base-Id
X-Version
Fastly-Restarts
X-Cached
Public-Key-Pins
AR-Request-ID
X-Server-Name
X-Shard
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Accept-Ch
Access-Control-Request-Method
Pagespeed
Paypal-Debug-Id
X-MSEdge-Ref
X-Goog-Storage-Class
X-Grace
SPRequestDuration
X-Client-IP
SPIisLatency
S
X-Vcache
X-Debug
X-DataStream-MidMile-RTT
Accept-CH
X-DataStream-Origin-MEX-Latency
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Expires
X-Id
X-Amz-Meta-S3cmd-Attrs
Pinterest-Version
X-Pinterest-Rid
X-Ezoic-Cdn
X-Upstream-Proxy
X-N
X-Fastly-Request-ID
X-T
X-DIS-Request-ID
X-Amzn-Trace-Id
Front-End-Https
Arr-Disable-Session-Affinity
X-NF-Request-ID
X-Content-Type
MicrosoftSharePointTeamServices
X-Hits
X-FastCGI-Cache
X-B3-Sampled
X-FTR-Cache-Host
X-Ser
X-Varnish-Age
X-Frontend
PB-RID
Arc-Version
Fastcgi-Cache
PB-PID
X-Mobile-Rewrite
X-Acc-Meta-Resource-Type
Server-Name
X-Content-Digest
X-Logged-In
Alternate-Protocol
X-XRDS-Location
X-Correlation-Id
X-B3-Traceid
X-Srv
Nel
X-Cache-Key
X-Pad
X-Node-Name
X-Forwarded-For
AMP-Access-Control-Allow-Source-Origin
X-Request-Handler-Origin-Region
X-Microsite
Host
Powered-By-ChinaCache
FilterID
TP-Cache
TP-L2-Cache
X-Type
X-User-Agent
X-Rid
X-XRDS-LOCATION
Healthy
X-Kinsta-Cache
X-LB-Cache
X-IPLB-Instance
X-Request-Received
X-Request-Processing-Time
Edge-Cache-Tag
X-F-Cache
X-Debug-Info
X-AOL-HN
X-Cache-2
X-Cached-By
X-Zen-Fury
X-VCache
Powered
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Revision
X-HS-Hub-Id
X-HS-Content-Id
X-Cache-Age
Backend-Timing
X-Analytics
X-Cache-Rule
X-Esi
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-GUploader-UploadID
X-Fastcgi-Cache
X-Accel-Expires
X-Hostname
X-Via-JSL
X-Az
X-AppVersion
X-Activity-Id
Surrogate-Key
VIX-Pulpo-Node
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
X-BCube-Filmed-By
X-Content-Options
X-Instance
X-Page-Id
X-Amz-Replication-Status
X-FB-Debug
X-Varnish-Grace
X-Cluster
X-Tumblr-Pixel-0
X-PHP-Backend
X-Content-Powered-By
X-Request-Guid
X-Akamai-Edgescape
X-Jobs
X-Tumblr-Pixel
X-Tumblr-User
Source
Cache-Status
Server-Node
X-TT
X-App-Environment
X-B-Cache
X-Framework
Refresh
X-Forwarded-Host
Cleartype
X-Signature
Accept-CH-Lifetime
Liferay-Portal
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Type
X-FW-Server
X-Varnish-Hostname
X-RateLimit-Limit
X-ATG-Version
DC
Tracecode
Host-Header
WPE-Backend
Accept-Charset
Fastcgi-Useragent
Access-Control-Allow-Method
X-Mobile
X-Cache-Operation
X-Cache-Action
X-Cache-Control
X-Edge-Location
X-Drupal-Cache-Tags
X-Time
Actual-Object-TTL
X-Cache-Hit
X-APP-VERSION
X-B
X-Erf-Bev-Bev
X-Accel-Buffering
X-Response-Served-From
X-Erf-Bev-Bev-Is-Generated
Payment
X-Hp-Webp
X-Mobile-URL
X-Storage
X-TX-ID
X-Whom
X-SS-Set-Cookie
X-WebKit-CSP-Report-Only
X-App-Server
X-NWS-LOG-UUID
X-WA-Info
X-Content-Age
X-TT-TIMESTAMP
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Git-Hash
Upgrade-Insecure-Requests
Cache-Tv-Group
Filters
X-UA-Device-Type
X-Cacheable-TTL
X-Handled-By
NGB
Cache
X-GeoIP
X-Status
X-Adobe-Loc
X-Tumblr-Pixel-1
X-Adobe-Content
X-Tumblr-Pixel-2
Eomportal-Instance
X-ProcessESI
X-RemovedCookies
X-RequestSource
Xserver
Viewport
X-Geo-Country
Cache-Tag
X-VG-WebCache
X-Ratelimit-Limit
Retry-After
X-Cache-TTL
Datacenter
Webserver
X-Server-ID
X-FW-Dynamic
X-Cache-TTL-Remaining
X-Ratelimit-Reset
X-TA-CDN-Provider
Server-Info
X-Seen-By
X-FB-TRIP-ID
MS-CV
X-Webkit-Csp
X-Cache-Enabled
X-Oracle-Dms-Rid
X-Presslabs-Stats
X-Host-Name
X-Oneagent-Js-Injection
X-Contextid
X-Guploader-Uploadid
X-Generated-By
Frame-Options
X-Origin-Server
From-Origin
X-Hyper-Cache
X-RTag
Ms-Operation-Id
S-Cnection
Country
X-PressLabs-Stats
X-Mode
X-CF-Powered-By
X-Cache-Var-Map
X-Cache-Var
Machine
X-Cache-Config
X-RN-RSRV
Meta-Geo
X-B3-Spanid
Load-Balancing
X-ES-SERVER
X-Path-Route
X-Tumblr-Pixel-3
X-Upstream-HT
X-Routing-Service
X-Cache-Grace
X-Labrador-Cache-Channel
Cache-Key
X-MP-GENERATED-AT
X-Proxied
X-Section
Vix-Hermes-Req-Id
X-Access
X-Zipkin-Id
X-Upstream-CT
X-Hit
X-OCL
X-Upgrade-Enabled
X-Backend-Name
X-Varnish-Server
X-Cache-Host
Decoy-Debug-Key
X-Human
Decoy-Debug-TTL
X-From
X-TNCMS
X-Loop
X-Web-Node
Now
X-Viewer-Country
Decoy-Debug-Status
X-RCS-CacheZone
X-Varnish-Cache-Hits
X-PCL
X-Origin-Response-Time
Mn-Server-Ip
ServedBy
X-Debug-Cache
X-R9-Blue-Green-Version
X-VWS-Id
X-Environment-Context
X-Endurance-Cache-Level
X-Region
X-LJ-Flow-ID
X-VG-TLSProxy
X-Via-Fastly
X-L-Path
X-Magnolia-Registration
X-Sorting-Hat-ShopId
X-CCM
X-Rule
X-AWS-Id
X-Alternate-Cache-Key
X-ShardId
X-EIG-Tracking-Id
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Akamai-Request-ID
Rt-Fastcgi-Cache
Mail-Subject
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Rendered-As
X-Timing-Wait
X-S
X-Proxy-Build
X-JoinUs
X-Drupal-Cache-Contexts
X-NCache
OT-Force-Account-Verify
We-Hiring
X-Proto
GEO-INFO
X-Generated
X-FC-Vary-Parameters
X-Xfnlog-Site
Akamai-GRN
X-Cluster-Node
X-Varnish-Hits
DB-Nickname
Cache-Name
DSUID
X-Device-Type
Release
Uber-Trace-Id
X-Trace-Id
Version
X-Nginx-Cache
X-Locale
X-Site-Version
X-BYPASS-REASON
Cteonnt-Length
X-ProxyCache-Key
X-Www-Served-By
X-ProxyCache-Status
ProcessTime
X-Request-Time
X-Load-Cache
X-NewRelic-App-Data
X-VCT
NGX
SRV
X-IP
X-Dc
X-Platform-Server
X-Time-Microsecs
X-Redis-Cache
X-UUID
Time
S-Rt
Azure-Version
X-FW-Version
Azure-SlotName
X-Wix-Request-Id
X-Origin
Azure-SiteName
Azure-InstanceId
X-Via-CDN
Azure-RegionName
X-Cache-NE
X-EdgeConnect-Cache-Status
X-Daa-Tunnel
Webcakes-App-Name
X-Origin-Hint
Webcakes-App-Version
Webcakes-Region
X-MServer
TWC-GeoIP-Country
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Akamai-Request-ID2
CACHE
X-Rocket-Nginx-Bypass
NtCoent-Length
X-Hl-Ver
X-ECACHE
X-No-Session
X-FireWall-Port
X-Proxy
X-ServerID
X-IPS-LoggedIn
X-Vgn-Hpd-Reason
Origin
X-UA
X-Cache-Remote
X-HTML-Minification-Powered-By
X-GEO
X-CDN-Forward
X-ApacheServer
X-Akamai-Transformed
Odigeo-Trace-Id
X-Cache-Server
X-Distributor
X-PERF
X-Format
X-CS
X-RateLimit-Reset
Fastly-SSL
LB
Ec-Rule-Version
X-Cache-Backend
X-Compress-Hint
Access-Control-Request-Headers
Cache-Tags
L5d-Success-Class
X-Real-IP
X-UnsetCookies
X-SERVER-NAME
X-Pubstack
X-Microcachable
Served-By
Accept-Language
X-Ratelimit-Remaining
Hostname
Origin-Cache-Control
Origin-Edge-Control
X-Unique-ID
Fastcgi-X-Cache-Version
X-Tb
X-BACKEND-TTL
X-B3-Parentspanid
X-Cache-Category-Id
X-Grey
IBM-Web2-Location
X-Org
X-NU-AKA-ACS-Version
Cdn-Host
Cdn-Request-Time
Cache-Prefix
Content-Script-Type
Cache-Cookie-Set-From
AsisCache
BehaviorPad-Version
Cache-Cookie-Set-Idcheck
ServerName
Cache-Cookie-Set-Lfrom
Arc-Country
A
Node
X-Aed
X-Accel-Expires-Debug
X-Developer
X-AIR-PT
X-App-Name
X-A-Wwc
X-A-Dgt
X-A
X-A-Ccd
X-A-Dam
X-A-Dcw
X-Application
X-ARC
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cluster-Name
X-Connection-Hash
X-D
X-Cdn-Srv
X-Date
X-Detected-As
X-Destination
X-B-Cookie
X-Cache-Bucket
X-DPWN-IS-SECURE
VivaBuild
X-Internal-Host
GEO-REGION-INFO
X-Instart-Info
X-IN-APIGATEWAY
MD5-Digest
Fly-Request-Id
Fly-Cache
Cross-Origin-Window-Policy
X-Is-Bot
Fastly-SIE
Fastly-SWR
Meta-Geo-Continent
Mobile-Detection-Method
Server-ID
Rt-Proxy-Cache
X-External-Request-Id
X-Edge-Server
Viewtype
Request-Time
Request-EU
X-G
Proxy-Firewall
Rendered-Blocks
Request-Country
Content-Style-Type
X-PAYTM-SRV-ID
X-S-Maxage
X-ScT
X-Nc
X-Edge
X-S-Cookie
X-Rojux
X-Request-UUID
Backend-Name
X-Rewrite-Enabled
X-Worker
X-Server-Time
X-Varnish-Url
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebServer
X-Twitter-Response-Tags
X-Trv-Group
X-SRCache-Key
X-Rebelmouse-Cache-Control
X-Transaction
Proxy-Connection
Xc-Version
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-ElasticPress-Search
X-Varnish-Cacheable
X-Sn-Servicetimems
Memcached
X-Geo-Header
X-Developers
X-SVT-ORM-VERSION
Gh-Request-Id
X-Skip-Cache
X-GeoIP-Country-Code
X-HS-Combine-CSS
X-Cache-Info
X-HS-Cache-Config
Is-Eu
X-SVT-ORM-RULES
X-We-Are-Hiring
Ha-Gx-Prefs
Platform
Server-Int
X-Level-Front-Cache
Section-Io-Cache
X-Fastly-Cache
X-Eu-Site
True-Client-Country-4JS
X-Epic-Correlation-Id
W
RNT-Time
X-Variation
X-C
X-ServiceProvider
X-PHP-Host
X-Core-Mission
RNT-Machine
Resin-Trace
On-Server
HA-Ipaddr
Apple-News-Services-Parsed-Url
X-Backend-State
Content-Disposition
X-Generated-On
X-Cdn-Origin
Apple-News-Services-Request-Url
X-NX-Host
X-Location
X-Debug-Log
X-Nginx-Cache-Key
REQUESTUUID
X-Debug-Cookies
Apple-News-Services-Host
X-CGP
X-Cache-Id
Countrycode
X-Clientip
X-Request-URI
Adler-Geo
Apple-News-Services-Handled
AKAMAI
Esi-Enabled
X-Powered-By-Defense
X-NC
X-Amzn-Remapped-Content-Length
X-Cache-FS-Status
X-CDN-Cache
V-Age
Web-Mar-Node
User-Cache-Control
X-Dispatcher-Server
X-Device-Os
X-Served-From
X-Auto-Login
UCS
X-Clara-WADP
X-Wikidot-Static-Cache
X-Amz-Meta-Cache-Control
X-Wikidot-Backend
X-WebServer
X-BBXSRF
X-Method
X-WADP-Cache
X-Distil-CS
X-Dispatch
X-Cms-Context
X-Block-Status
PFcat
X-Secret
Selected-Fe
Fastly-Soc-X-Request-Id
X-Reqid
X-Server-IP
X-SIPLIST1
X-Servername
X-Irp-Debug
X-SD-PageType
X-Request-Start
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Response-By
X-Via-NSCOPI
Country-Code
X-Key
CDCHOST
X-LI-UUID
X-Hnp-Log
X-Reboot
X-Fetched-On
X-FPC
SD-X-WS
Server-Host
SS
X-Processor
X-Gannett-Site-Version
X-Gen-Mode
X-GeoIP-City
IsBot
X-Hash
X-Qloud-Router
N-Cache
X-Generation-Time
X-TH-Server
X-Matched-Rule
X-Bip
X-Release
X-Origin-Expires
X-Origin-Date
X-Crawler
X-Swa-Ws
X-Thinkindot-L3
X-Webstats-RespID
X-VC-Cache
X-VServer
X-Via-Edge
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Owner
X-Thanos
L
X-Via-SSL
X-TrackingId
Who
Wxu-Next-Region
Thinkindot-CacheControl
Wxu-Next-Hostname
Wxu-Next-Commit
GW-Server
Thinkindot-CacheControl-Type
Pramga
Powered-By
Heartbleed
Thinkindot-Control
X-Azure-Ref-OriginShield
X-Azure-Ref
Mime-Version
X-Varnish-Ttl
X-OVcl-Cache
X-OVcl
X-CLOUD-TRACE-CONTEXT
X-Pf-Uncompressing
X-CUA
X-FE
Kp-EeAlive
X-Urbn-Site-Id
X-Parent-Response-Time
X-Urbn-Context-Path
Locale
CF-IPCountry
X-Ua
Magicmarker
X-ND-Cache
PageSpeed
X-LAGOON
User-Agent
X-Protected-By
X-ABtesting
X-Fstrz
X-Varnish-Beresp-Ttl
X-Flog
X-Hello
Memory
Pragrma
X-Geo
X-Origin-CC
X-Origin-TTL
X-Be
X-B3-SpanId
X-Ruxit-Js-Agent
Pagetype
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Page-Type
X-Zone
X-URL
X-User
X-Generated-In
X-Backend-Url
X-Ttl
X-Backend-Host
X-Cache-Ttl
X-Dynatrace-Js-Agent
X-Tt-Trace-Tag
X-Core-Value
X-MSEdge-Features
X-MSEdge-Flight
X-GoCache-CacheStatus
X-Up
X-Phone
X-IN-WAF
X-Cdn-Forward
X-Newrelic-Synthetics
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Soup
X-Backend-TTL
X-Debug-Cache-Expiry
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-DC
X-Oss-Object-Type
Geoip-City
X-TT-LOGID
Geoip-Latitude
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
GeoIp-Country-Code
X-Check-Cacheable
X-Litespeed-Cache
Cdn
X-Birta-Served
X-Birta-Cache-Post
X-Info
X-Real-Ip
X-Old-Content-Length
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-Servedbyhost
Cache-Hits
X-Varnish-IP
SN
HitType
X-MID
Selected-FE
X-Mid
X-Datadome
X-Vcl-Version
X-HS-Status
X-GRACE
X-ZONE
X-Akamai-SSL-Client-Sid
Amp-Access-Control-Allow-Source-Origin
FSS-Cache
FSS-Proxy
X-ServedByHost
X-Aicache-OS
X-VCL-Version
X-Bc
X-Cache-Debug
Inserted-Into-Cache-At
Fastly-Backend-Name
X-Node-Id
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Refresh
X-Tb-Optimization-Total-Bytes-Saved
X-Agile-Id
Srv
X-Cache-Time
X-Agile-Age
CF-Cached-On
X-Agile
HostName
Server-Cache-Control
X-Logtrace-Id
Server-Surrogate-Control
X-Source
X-IN-APIGATEWAYSSL
X-Cache-ASPX
X-Varnish-Authentication
X-CSRF-TOKEN
Ajk
X-Contensis-Viewer-Groups
X-App-Version
X-CSRF-Token
WZWS-RAY
X-EC-Lua
RequestId
X-UPSTREAM-Address
X-COUNTRY
XServer
GeoIP-Country-Code
X-Via-Ucdn
X-Web-Server
X-Nananana
X-FORWARDED-FOR
X-ECache
X-RateLimit-Remaining-Second
X-BC
X-APP
GeoIP-City
X-RateLimit-Limit-Second
GeoIP-Latitude
Cf-Ipcountry
X-Varnish-Beresp-TTL
X-TIME
X-WR-MODIFICATION
Xkeyrz
X-Wa
X-NWS-UUID-VERIFY
X-Proxy-Cacherz
WebServer
Group
T-Server
Ohc-Cache-HIT
Ohc-File-Size
X-Unique-Id
X-LiteSpeed-Cache-Control
X-BE
X-PAGE-TYPE
Is-Session-Tracking
X-Fastly-Country-Code
Xkeynj
HTTPS
Get-Access-Time
X-Micro-Cache
X-Render-Time
X-PJAX-URL
X-Cache-Tag
X-CACHE-KEY
URI
PICS-Label
X-GDPR
X-LB-ID
X-SRV
X-Cache-Miss-From
X-Requestid
Backend
X-Sedo-Request-Id
Www
X-Edge-IP
X-SN
MIME-Version
X-MCACHE
X-Policy
X-Request-Url
X-Pjax-Url
X-Uri
CDN
X-Fastly-Backend-Reqs
SID
X-Instart-Isnd
Xet-Cookie
DataCenter
X-Lb-Id
Lb
X-WA
Pics-Label
X-Swift-Error
X-Vct
Requestid
X-Apw-Hits
X-Cache-Expires
Host-ID
X-Apw-Access-Object
X-Apw-Access-Token
Cneonction
X-Apw-Access-Action
X-HostName
X-Dw-Trace-Id
X-NGINX-Cache
Correlation-Id
X-Cdn-Request-ID
X-Service
X-Ecache
Cache-Provider
X-Cf-Powered-By
X-Newrelic-App-Data
X-Varnish-Action
X-Serial
Epwk-Cache
X-Html-Edge-Cache
X-WPE-Loopback-Upstream-Addr
Warning
X-RPS
X-RSL
X-Zalando-Child-Request-Id
X-RPM
X-DW
X-DB
X-DI
X-DSS
X-Page-Impression-Id
X-Flow-Id
X-Bug-Bounty
X-ServerName
Lfy
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Fastly-Cache-Hits
X-Fpc
X-PF-Uncompressing