Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Pragma
X-Powered-By
ETag
Link
Expect-CT
X-XSS-Protection
Via
Age
CF-RAY
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-Served-By
CF-Ray
X-Xss-Protection
X-Timer
X-Varnish
X-Download-Options
Access-Control-Allow-Methods
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
P3p
X-FRAME-OPTIONS
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Status
X-AspNetMvc-Version
Content-Encoding
Upgrade
X-CDN
X-Template
X-Language
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Keep-Alive
X-Via
X-Ws-Request-Id
Feature-Policy
X-Age
X-AH-Environment
X-Backend
X-Hacker
X-Cache-Group
X-Buckets
X-Robots-Tag
X-Server
X-Amz-Request-Id
X-UA-Device
EagleId
X-Amz-Id-2
X-Proxy-Cache
X-Turbo-Charged-By
X-Server-Powered-By
Request-Context
X-Dns-Prefetch-Control
Server-Timing
Host-Header
X-Nginx-Cache-Status
Grace
Report-To
Xkey
X-Page-Speed
X-Rq
X-OneAgent-JS-Injection
X-Pingback
X-Varnish-Cache
Cf-Bgj
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Amz-Version-Id
X-Vhost
NEL
X-Host
X-Dispatcher
X-Device
X-Backend-Server
X-Node
Surrogate-Control
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Response-Time
X-Origin-Cache
Content-Location
X-Akam-SW-Version
Request-Id
X-Ac
X-ASPNET-VERSION
X-Server-Id
X-Country
X-Mod-Pagespeed
EagleEye-TraceId
X-HW
Accept-CH
Rating
Accept-CH-Lifetime
X-Readtime
X-ORACLE-DMS-ECID
X-Cloud-Trace-Context
X-ORACLE-DMS-RID
X-Application-Context
X-DataDome
Pinterest-Generated-By
Edge-Control
X-Url
X-Country-Code
X-Vname
X-TtlSet
X-PC
X-Origin-Upstream-Status
X-Varnish-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cnection
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Id
X-D2id
X-GitHub-Request-Id
Akamai-Age-Ms
X-MS-InvokeApp
X-ESI
X-Content-Type
X-Clacks-Overhead
Allow
X-Server-Name
X-Abt-Application-Version
X-Navigation-Version
X-FTR-Request-ID
X-Pinterest-Rid
X-Vcap-Request-Id
Pinterest-Version
X-Trace
Display
Pagespeed
X-Middleton-Response
X-Sol
Response
X-Middleton-Display
Verso
X-B3-TraceId
X-Px
X-Rack-Cache
X-Cached
X-Server-ID
X-Element-Page-Cache
X-Fastly-Request-ID
Service-Worker-Allowed
X-DynaTrace
X-Client-IP
MS-Author-Via
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Powered-By-Plesk
Accept-Ch
X-Upstream
X-Version
X-TTL
X-Forwarded-Proto
X-Dw-Request-Base-Id
Content-MD5
X-NF-Request-ID
X-T
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
X-SharePointHealthScore
SPRequestGuid
Ar-Sid
Fastly-Restarts
X-Debug
X-VARITI-CCR
X-Webkit-CSP
X-Jurisdiction
X-Kinja
X-Kinja-Build
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Server
Accept-Ch-Lifetime
TP-L2-Cache
Access-Control-Request-Method
TP-Cache
X-Goog-Hash
X-XRDS-Location
X-Powered-CMS
X-Content-Digest
X-Release
X-Edge
X-MSEdge-Ref
X-NWS-LOG-UUID
X-Ttl
TCN
SPIisLatency
SPRequestDuration
RTSS
X-PressLabs-Stats
S
X-Amz-Rid
Cache-Tag
X-FastCGI-Cache
Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
Public-Key-Pins
X-Yandex-Sdch-Disable
X-Pinterest-Direct
X-Ezoic-Cdn
X-MCACHE
X-Node-Name
X-Mid
X-Accel-Expires
Server-Node
X-Cache-Key
X-CST
X-Logged-In
X-Cache-Hit
X-Amzn-Trace-Id
Front-End-Https
ServerID
X-Ratelimit-Remaining
X-Ser
X-Request-Handler-Origin-Region
X-Microsite
Alternate-Protocol
X-Recruiting
X-Page-Id
X-Origin-Server
X-Kinsta-Cache
X-ECACHE
X-B
Host
Accept-Charset
X-Ratelimit-Limit
X-Hostname
X-Mobile-URL
X-FireWall-Port
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-FTR-Backend-Server
X-Forwarded-For
X-Varnish-Age
X-Country-Code-Real
X-FTR-Backend
Nginx-Cache
Mrf-Cache-Status
X-B3-TraceId-Primal
X-FTR-Balancer
X-FTR-DC
MRF-Tech
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Expires
X-Content-Security-Policy-Report-Only
Filterid
X-Id
X-DIS-Request-ID
X-Seen-By
Realpath
X-Load-Cache
X-Shield-Request-Id
X-Jobs
X-Content-Options
X-Daa-Tunnel
Edge-Cache-Tag
X-F-Cache
X-Git-Hash
X-LB-Cache
X-App-Environment
X-Varnish-Backend
X-Type
X-Varnish-Grace
Paypal-Debug-Id
X-Correlation-ID
X-AppVersion
X-Az
X-Activity-Id
X-N
X-Request-Guid
X-Rid
X-Hits
X-Grace
X-Mg-S
Fastcgi-Useragent
X-Zen-Fury
X-FB-Debug
X-Amz-Server-Side-Encryption
X-Proxy
DynaTrace
Access-Control-Allow-Method
Cache-Tags
X-App-Server
X-Upgrade-Enabled
X-WebKit-CSP-Report-Only
DC
X-Akamai-Edgescape
MicrosoftSharePointTeamServices
X-Content-Powered-By
Content-Disposition
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cleartype
X-Cache-Rule
X-Geo-Country
X-Cache-Operation
AMP-Access-Control-Allow-Source-Origin
X-HP-Webp
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Fastcgi-Cache
X-TEC-API-VERSION
X-Cached-By
X-Wix-Request-Id
X-VCache
X-Endurance-Cache-Level
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
X-XRDS-LOCATION
X-User-Agent
X-IPLB-Instance
X-Amz-Meta-S3cmd-Attrs
X-Host-Name
X-B3-Sampled
X-HTML-Minification-Powered-By
X-Ua
Refresh
Healthy
X-B-Cache
X-HS-Hub-Id
X-HS-Cache-Config
X-AOL-HN
X-HS-Content-Id
X-Signature
X-Cacheable-TTL
X-Is-Bot
X-Rendered-As
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-UUID
X-Region
X-FW-Dynamic
X-Distributor
X-Whom
X-FW-Static
X-FW-Type
X-HS-Combine-CSS
X-FW-Serve
X-FW-Hash
MS-CV
X-FW-Server
X-Cache-Time
Payment
NGB
X-Amz-Apigw-Id
Datacenter
X-Amzn-RequestId
X-Rule
X-Instance
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Countrycode
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Powered-By-ChinaCache
X-Debug-Info
X-Hp-Webp
X-Mobile
X-Frontend
PB-RID
PB-PID
Arc-Version
X-Varnish-Server
X-Cache-Age
X-Respond-Thread
Surrogate-Key
Powered
X-PHP-Backend
X-Backend-Name
S-Cnection
X-App-Version
Cache
X-Oneagent-Js-Injection
X-Protected-By
X-Azure-Ref
X-NewRelic-App-Data
X-Cache-Server
X-Via-JSL
X-Hyper-Cache
X-DynaTrace-JS-Agent
X-WA-Info
Viewport
Liferay-Portal
X-FTR-Cache-Host
X-Litespeed-Cache
X-Acc-Debug-Context
X-Proxy-Cache-Status
X-Cache-Control
X-Cache-Expired-At
Referer-Policy
Retry-After
X-Time
X-EdgeConnect-Cache-Status
X-CSRF-Token
X-FB-TRIP-ID
Charset
Webserver
X-Source
X-Sucuri-ID
Filters
X-Cache-Var-Map
X-ES-SERVER
X-RN-RSRV
X-Cache-Var
Meta-Geo
X-ProcessESI
X-RemovedCookies
X-Mode
X-Debug-Cache
X-Locale
X-Real-IP
X-GeoIP
X-Qloud-Router
X-Device-Type
X-Cache-Action
X-AWS-Id
X-ProxyCache-Key
X-Via-Fastly
Section-Io-Cache
Mn-Server-Ip
X-BYPASS-REASON
X-Cache-Host
X-VWS-Id
X-Time-Microsecs
X-Server-W
X-LJ-Flow-ID
X-Framework
X-R9-Blue-Green-Version
X-Amz-Replication-Status
X-ProxyCache-Status
X-Site-Version
TWC-Connection-Speed
Property-Id
TWC-GeoIP-Country
TWC-Device-Class
Selected-Fe
Cross-Origin-Window-Policy
X-Proxy-Build
X-L-Path
X-Origin-Hint
X-Environment-Context
X-PCL
Cache-Tv-Group
X-Timing-Wait
Eomportal-Instance
TWC-GeoIP-LatLong
X-Zipkin-Id
Webcakes-App-Name
X-Cluster
From-Origin
X-Routing-Service
TWC-Locale-Group
X-Human
X-Hl-Ver
X-Handled-By
X-FW-Version
X-TNCMS
X-Loop
Webcakes-Region
Webcakes-App-Version
X-Proxied
TWC-Privacy
X-Xfnlog-Site
X-OCL
X-Ratelimit-Reset
X-Labrador-Cache-Channel
X-Revision
X-Hosted-By
X-NYM-Debug-Backend
X-PHP-Host
X-JoinUs
Ec-Rule-Version
X-Be
X-BCube-Filmed-By
X-Yottaa-Metrics
X-Amzn-Remapped-Content-Length
X-Yottaa-Optimizations
X-Detected-As
X-Generated-By
X-From
DB-Nickname
X-RTag
X-Proto
X-ServerID
X-SaId
Ms-Operation-Id
X-Status
Uber-Trace-Id
X-Access
X-Redis-Cache
X-Section
X-Format
FSS-Cache
Version
X-Cache-TTL-Remaining
X-Air-Hostname
X-Varnish-Cache-Hits
Frame-Options
X-No-Session
X-Cache-PHP
X-ATG-Version
X-NWS-UUID-VERIFY
GEO-INFO
X-Drupal-Cache-Contexts
X-Sucuri-Cache
X-TA-CDN-Provider
X-NCache
X-Unique-Id
X-Origin
Server-Name
X-Contextid
X-Drupal-Cache-Tags
CF-Cached-On
X-EIG-Tracking-Id
X-EC-Lua
X-IPS-LoggedIn
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-CACHE-AGE
OT-Force-Account-Verify
X-Akamai-Transformed
X-Cache-Enabled
X-IP
X-Vgn-Hpd-Cached
X-Bc-Bl
X-Vgn-Hpd-Variations-Key
X-GoCache-CacheStatus
X-Cache-Backend
X-Backend-Host
X-TIME
X-Tumblr-Pixel-3
X-AIR-PT
X-Adobe-Content
X-CDN-Forward
X-APP-VERSION
X-Adobe-Loc
Time
Azure-SiteName
Azure-SlotName
Azure-Version
X-TT
Azure-RegionName
Now
Azure-InstanceId
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Ruxit-Js-Agent
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
VIX-Pulpo-Node
Access-Control-Request-Headers
X-RCS-CacheZone
VIX-Pulpo-Upstream-Status
X-Correlation-Id
X-Instart-Request-ID
X-CCM
X-Cdn
Node
X-Cache-2
SD-X-WS
X-URL
X-A-Wwc
DCR-Decision-By
DCR-Processing-Time-Ms
Fastcgi-X-Cache-Version
Host-ID
CloudFront-Viewer-Country
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Machine
MD5-Digest
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A
Surrogated-Key
Meta-Geo-Continent
Mobile-Detection-Method
Rendered-Blocks
X-Accel-Expires-Debug
X-ARC
X-S
X-Aed
X-ScT
X-NGENIX-Cache
X-Rojux
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Processor
X-Request-UUID
X-Transaction
X-Trv-Group
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-Twitter-Response-Tags
X-Vdms-Path
X-Vdms-Version
X-Minions-Version
X-S-Cookie
X-NC
X-CF-Lambda-Version
X-B-Cookie
X-External-Request-Id
X-D
X-Cache-NE
X-Date
X-Destination
X-CF-Lambda-Fn
X-G
X-Connection-Hash
X-Application
X-Forwarded-Host
X-Cache-Grace
X-ApacheServer
X-PERF
X-Backend-TTL
X-Soup
X-Pubstack
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
X-CUA
X-Varnishpool
X-Up
X-Variation
X-Cache-Bucket
X-Adobe-Source
Adler-Geo
X-Alternate-Cache-Key
X-Bip
X-Thanos
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-PullZone
Fastly-SIE
X-Rebelmouse-Cache-Control
X-Generation-Time
X-Rebelmouse-Surrogate-Control
X-Req
X-DPWN-IS-SECURE
X-Edge-Location
X-Owner
Ufe-Result
X-Hash
Wxu-Next-Region
X-OVcl
Wxu-Next-Commit
We-Hiring
X-OVcl-Cache
X-Dispatcher-Server
Platform
Is-Eu
X-SN
Fastly-SWR
X-Method
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
Mail-Subject
X-Skip-Cache
X-Servername
NM-Fastcgi-Cache
X-ShardId
X-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
Wxu-Next-Hostname
HostName
X-Cluster-Name
X-Cache-Config
X-Storage
X-TX-ID
Cache-Status
X-Viewer-Country
X-UA
Fastly-SSL
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
PFcat
Origin
Rt-Fastcgi-Cache
X-VG-TLSProxy
X-Cache-Date
X-Backend-State
X-Auto-Login
X-Li-Pop
L5d-Success-Class
L
X-Policy
X-Proxy-Upstream
X-VarnishDD-TTL
Fastly-Drupal-HTML
X-Platform
Gh-Request-Id
X-Cache-NGX
HA-Ipaddr
Ha-Gx-Prefs
Group
X-Varnish-Cacheable
X-Microcachable
X-Eu-Site
X-Envoy-Decorator-Operation
X-WADP-Cache
X-Webstats-RespID
X-Fastly-Backend
X-Fmm-Version
X-HN
X-LI-UUID
X-Gamma-Serve
X-Level-Front-Cache
X-Csrf-Jwt
X-Core-Value
Country-Code
X-Clara-WADP
X-CGP
X-Generated-On
X-Clientip
X-Micro-Cache
X-Li-Fabric
X-Core-Mission
X-Cms-Context
X-Cache-Tags
X-Varnish-Ttl
CacheControlHeader
C-Via
X-Request-Start
X-Reqid
AKAMAI
X-Render-Time
Decoy-Debug-Status
X-SayCDN-TTL
X-ECache
Country
Backend
X-Say-TTL
Decoy-Debug-Key
X-Web-Node
Decoy-Debug-TTL
X-Say-Cacheable
X-Agile-Id
X-Amz-Meta-Cb-Modifiedtime
X-Irp-Debug
X-Is-Gdpr
X-Old-Content-Length
X-Ms-Request-Id
X-Has-Esi
X-Geo-Header
X-HS-Content-Campaign-Id
X-Agile-Age
X-Gzip
X-Wikidot-Backend
X-Developers
X-Location
X-Esi-Check
X-Fastly-Cache
X-Wikidot-Static-Cache
X-Content-Age
X-Cache-URL
Akamai-GRN
X-Cdn-Srv
X-VHOST
UCS
X-Cache-Id
X-Agile
Fastly-Backend-Name
X-Varnish-Beresp-Ttl
Pagetype
Memcached
X-Request-Host
X-Slack-Backend
X-JWT-State
X-Ms-Version
FSS-Proxy
X-Esi
X-Mvc-Supplant-Cachable
X-Dc
X-PF-Uncompressing
X-RateLimit-Remaining
Nel
X-CS
X-Cdn-Forward
M-TraceId
X-LB-ID
X-Refresh
X-Aicache-OS
X-Wa
Upgrade-Insecure-Requests
X-NODE
X-Varnish-Remaining-TTL
X-Via-Popn
X-Platform-Server
X-LAGOON
X-Varnish-CookieHashed-On
X-DefHash
X-DefElseHash
X-Via-Poph
X-Varnish-CookieINHashed-On
X-BC
X-UPSTREAM-Address
X-ZONE
X-Branch-Name
Arc-Country
X-B3-Spanid
X-Route-Name
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Providence-Cookie
Viewtype
X-Session-Fingerprint
X-Cache-Debug
VivaBuild
X-Via-Ucdn
X-LI-Proto
X-Servedbyhost
X-Mvc-Supplant-OutputCached
Actual-Object-TTL
X-Ua-Device
NGX
X-ORACLE-APMCS-REQUEST-ID
X-RunCloud-Cache
Srv
X-Request-Time
Cdn-Request-Time
CACHE
X-Zone
X-Edge-Server
X-Debug-Cache-Store
X-Bc
Cdn-Host
X-Debug-Cache-Fetch
X-SERVER
Geo-Info
X-Srv
X-Unique-ID
Memory
Xserver
X-Varnish-Hostname
X-Vgn-Hpd-Ssi
X-Page-View
X-Nginx-Cache
X-GEO
X-DC
X-Cs
X-NGINX-Cache
X-APP
X-Action
Sid
X-LiteSpeed-Cache-Control
X-FPC
X-HS-Status
X-Ftr-Cache-Host
X-MP-GENERATED-AT
X-B3-Traceid
X-Akamai-Request-ID2
X-DSS
X-DI
WWW-Authenticate
X-Via-Popv
X-DW
X-RSL
X-RPS
X-RPM
X-Check-Cacheable
X-DB
SRV
X-Cluster-Node
X-CF-Powered-By
X-Geo
Geoip-Latitude
X-Epic-Correlation-Id
X-Oss-Cdn-Auth
Server-Info
GeoIp-Country-Code
NtCoent-Length
X-FC-Vary-Parameters
X-Mobile-Rewrite
X-Vcache
Hostname
X-Hit
Processtime
Apigw-Requestid
X-VCL-Version
ProcessTime
X-Dynatrace-Js-Agent
GeoIP-Country-Code
GeoIP-Latitude
X-Nc
X-Via-CDN
X-NU-AKA-ACS-Version
X-UnsetCookies
X-CSRF-TOKEN
User-Agent
X-Sql-Count
X-Sql-Duration-Ms
X-Via-SSL
W
X-SERVER-NAME
X-Vcl-Version
XServer
Edge-Copy-Time
X-Via-Edge
X-Webkit-CSP-Report-Only
X-FORWARDED-FOR
S-Rt
On-Server
X-We-Are-Hiring
X-Fpc
X-Svr
SID
X-HOST
WebServer
Origin-Edge-Control
Origin-Cache-Control
Esi-Enabled
X-Fastly-Country-Code
X-Envoy-Upstream-Healthchecked-Cluster
X-Www-Served-By
X-Presslabs-Stats
Accept-Language
CF-IPCountry
X-Key
X-Tb
X-Pinterest-Sli-Latency-Threshold
X-Pinterest-Sli-Response-Type
X-Pinterest-Sli-Endpoint-Name
X-Dynatrace
Ohc-File-Size
Amp-Access-Control-Allow-Source-Origin
X-HITS
X-S-Maxage
ServedBy
Cache-Hits
LB
T-Server
X-Cache-Hfrom
Proxy-Firewall
X-Dispatch
X-Cache-Remote
X-Cache-Hm
Cdn
X-MSEdge-Features
X-Pjax-Url
X-MSEdge-Flight
X-SRV
Cteonnt-Length
A
Server-Host
N-Cache
X-CACHE-KEY
X-COUNTRY
HitType
CDN
X-Pass-Why
Lb
X-Geo-Region
Magicmarker
X-Oracle-Dms-Rid
X-App
X-ServedByHost
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-SB
Pics-Label
BehaviorPad-Version
WZWS-RAY
X-Varnish-Hits
X-Generated
X-Li-Proto
Powered-By
X-Instart-Info
X-VC
X-Newrelic-App-Data
X-RAMCache
Fastcgi-Cache-TTL
Ohc-Cache-HIT
X-TrackingId
X-Newrelic-Synthetics
X-Path-Route
X-Info
X-StackifyID
Protected
X-Datadome
X-Akamai-Pragma-Client-IP
X-B3-SpanId
Xet-Cookie
X-Via-NSCOPI
X-TH-Server
Cache-Key
X-Served-From
X-Cache-Tag
X-Uri
X-Via-PopN
X-Via-PopH
X-LiteSpeed-Tag
User-Cache-Control
Cache-Provider
Server-Ttl
X-TT-LOGID
Dnion-Transfer-Encoding
X-Batcache
X-Via-PopV
X-Lb-Id
X-Varnish-Beresp-TTL
Content-Style-Type
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-WA
Content-Script-Type
X-Origin-Response-Time
Tracecode
X-Agile-Brick-Ok
Ssr
X-Tt-Logid
Cf-Alt-Svc
X-Vgn-Hpd-Reason
Tcn
X-Tid
X-Men
X-Pad
X-Cc-Req-Id
X-Scheme
Lfy
X-RateLimit-Limit
X-Erf-Bev-Bev
Who
X-Erf-Bev-Bev-Is-Generated
D-Cc-Upstream
X-Cache-Spec
X-Cc-Via
Inserted-Into-Cache-At
Mime-Version
X-Region-Sid
X-HostName
X-Magnolia-Registration
X-Pf-Uncompressing
X-PJAX-URL
X-Yottaa-OS
DSUID
X-Selected-Name
X-UA-Device-Type
X-Selected-Host-Header
X-Selected-Scheme
X-Provided-By
Odigeo-Trace-Id
CountryCode
X-Cdn-Origin
X-Nginx-Cache-Key
X-Matched-Rule
X-Node-Id
X-NodeID
X-Origin-Expires
X-Origin-Date
X-Origin-CC
X-Nyt-Route
X-Loc
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gen-Mode
X-Gdpr
X-Device-Os
X-Fetched-On
X-Developer
X-Generated-In
X-ElasticPress-Query
X-Contensis-Viewer-Groups
X-GeoIP-City
X-Origin-Time
X-Hnp-Log
X-SD-PageType
X-Thinkindot-L3
X-Swa-Ws
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Trace-Id
X-User
X-Varnish-Url
X-Varnish-Authentication
X-Var-Ttl
X-VServer
X-SRCache-Key
X-Sn-Servicetimems
X-Rocket-Build-Number
X-Response-By
X-Request-URI
X-Parent-Response-Time
X-VC-Cache
X-ServiceProvider
X-SIPLIST1
X-Sigma-Backend
X-Sigma
X-Cache-Info
X-Origin-TTL
True-Client-Country-4JS
Cneonction
Source
X-Dw-Trace-Id
X-Request-URL
Vha6-Origin
X-Snapshot-Date
FNAC-ModuleRouting
CDCHOST
Cache-Name
Cache-Host
X-Apw-Hits
X-Apw-Access-Token
X-C
PICS-Label
X-Nananana
Pragrma
X-DevSite-Last-Modified
X-MiniProfiler-Ids
X-Apw-Access-Object
X-Apw-Access-Action
X-Proxy-Cachei7
Instruction
IsBot
V-Age
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Vix-Hermes-Req-Id
Web-Mar-Node
X-Block-Status
X-BBC-Edge-Cache-Status
X-Azure-Ref-OriginShield
X-API-Version
SR-User-Adfree
Sever-Int
Pramga
Path
Locid
Kp-EeAlive
Release
Resin-Trace
Server-Id
Server-Hostname
Server-Ext
X-Cache-ASPX