Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
X-Powered-By
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
CF-Cache-Status
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Adblock-Key
X-Drupal-Cache
Alt-Svc
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
P3p
X-Template
Status
X-Language
Timing-Allow-Origin
Content-Encoding
X-Content-Security-Policy
X-Iinfo
X-Buckets
Upgrade
X-Kinja-Server-Push
Xkey
X-Via
X-Turbo-Charged-By
X-CDN
Keep-Alive
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Cache-Group
X-Pass-Why
X-Age
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Server
X-Backend
X-Amz-Id-2
X-Pingback
X-Amz-Request-Id
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Robots-Tag
X-Proxy-Cache
X-Hacker
Grace
X-Server-Powered-By
EagleId
X-UA-Device
X-Varnish-Cache
X-Nginx-Cache-Status
Request-Context
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
Feature-Policy
X-Device
Server-Timing
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Host
Report-To
X-Ac
X-Rq
Content-Location
X-Node
X-OneAgent-JS-Injection
X-Backend-Server
X-Response-Time
X-Cnection
X-Origin-Cache
X-Cloud-Trace-Context
X-Application-Context
EagleEye-TraceId
Allow
Request-Id
X-Readtime
Surrogate-Control
X-Country
X-Cache-Lookup
X-ORACLE-DMS-ECID
X-Cdn
X-TTL
X-DynaTrace
X-Url
X-Vhost
Pinterest-Generated-By
X-Rack-Cache
X-Ua-Compatible
X-Clacks-Overhead
X-Origin-Upstream-Status
X-Ruxit-JS-Agent
NEL
X-CST
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-FTR-Request-ID
X-ORACLE-DMS-RID
X-Country-Code
X-HW
X-Goog-Hash
X-Instart-Request-ID
X-Dispatcher
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-DataStream-Cache-Status
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Px
X-VARITI-CCR
Service-Worker-Allowed
X-DataDome
X-MS-InvokeApp
X-Mod-Pagespeed
X-Request-ID
X-Dns-Prefetch-Control
Verso
SPRequestGuid
X-Recruiting
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Variant
X-D2id
X-Varnish-TTL
X-Vcap-Request-Id
X-SharePointHealthScore
RTSS
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
TCN
DynaTrace
X-Navigation-Version
X-GitHub-Request-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Powered-By-Plesk
X-RateLimit-Remaining
X-Middleton-Response
X-Middleton-Display
Display
Response
X-Sol
X-B3-TraceId
X-Akam-SW-Version
X-ESI
Content-MD5
Charset
MS-Author-Via
Ar-Sid
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Trace
ServerID
X-Shield-Request-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Amz-Rid
Accept-Ch-Lifetime
Realpath
X-Server-Name
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Dw-Request-Base-Id
X-Goog-Stored-Content-Length
X-Powered-CMS
AR-Request-ID
X-DynaTrace-JS-Agent
X-Forwarded-Proto
Nginx-Cache
X-Cached
X-Version
X-Upstream
X-Shard
Fastly-Restarts
Accept-Ch
Public-Key-Pins
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
SPRequestDuration
SPIisLatency
X-Goog-Storage-Class
Access-Control-Request-Method
Paypal-Debug-Id
X-MSEdge-Ref
Pinterest-Version
X-Upstream-Proxy
X-Pinterest-Rid
X-Client-IP
Pagespeed
S
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Debug
X-Amz-Meta-S3cmd-Attrs
Accept-CH
X-Grace
X-Id
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Expires
X-Ezoic-Cdn
X-N
X-T
X-DIS-Request-ID
X-Fastly-Request-ID
MicrosoftSharePointTeamServices
Arr-Disable-Session-Affinity
X-Amzn-Trace-Id
X-NF-Request-ID
Front-End-Https
X-Vcache
X-Content-Type
X-XRDS-Location
X-Hits
X-Ser
X-B3-Sampled
X-Varnish-Age
X-Mobile-Rewrite
PB-PID
Arc-Version
PB-RID
Alternate-Protocol
X-Server-ID
Fastcgi-Cache
X-Acc-Meta-Resource-Type
X-FTR-Cache-Host
X-Frontend
X-FastCGI-Cache
X-Logged-In
X-Content-Digest
Server-Name
X-Srv
X-VCache
X-Correlation-Id
X-Pad
X-Forwarded-For
X-B3-Traceid
Nel
Host
Powered-By-ChinaCache
AMP-Access-Control-Allow-Source-Origin
X-Node-Name
X-Request-Handler-Origin-Region
X-Microsite
FilterID
TP-L2-Cache
TP-Cache
Healthy
X-Rid
X-Kinsta-Cache
Edge-Cache-Tag
X-Type
X-LB-Cache
X-IPLB-Instance
X-Cache-Key
X-Request-Processing-Time
X-Request-Received
X-User-Agent
X-Debug-Info
X-AOL-HN
X-Cached-By
X-Fastcgi-Cache
X-GUploader-UploadID
X-Cache-2
X-Revision
X-F-Cache
X-Hostname
X-Amz-Apigw-Id
X-XRDS-LOCATION
X-Zen-Fury
Powered
X-Amzn-RequestId
X-Cache-Rule
X-HS-Hub-Id
X-HS-Content-Id
Backend-Timing
Surrogate-Key
X-Analytics
X-Cache-Age
X-Accel-Expires
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Page-Id
X-Content-Security-Policy-Report-Only
VIX-Pulpo-Upstream-Status
X-RateLimit-Limit
X-Varnish-Backend
X-Az
X-AppVersion
X-Activity-Id
VIX-Pulpo-Node
X-BCube-Filmed-By
X-Varnish-Grace
X-Instance
X-Content-Options
Source
X-FB-Debug
X-Cluster
X-Jobs
X-Tumblr-Pixel
X-Tumblr-User
X-Via-JSL
X-Tumblr-Pixel-0
X-Amz-Replication-Status
X-Akamai-Edgescape
Cache-Status
X-PHP-Backend
X-App-Environment
X-Request-Guid
X-Content-Powered-By
X-TT
Cleartype
X-Framework
Server-Node
X-Esi
X-Forwarded-Host
Tracecode
Refresh
X-Varnish-Hostname
WPE-Backend
X-B-Cache
X-Signature
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Hash
X-ATG-Version
X-FW-Serve
Host-Header
Liferay-Portal
X-Mobile
X-Cache-Operation
DC
X-Cache-Control
X-Time
Accept-Charset
X-Edge-Location
X-NWS-LOG-UUID
X-Cache-Action
Actual-Object-TTL
X-Drupal-Cache-Tags
Accept-CH-Lifetime
Access-Control-Allow-Method
Fastcgi-Useragent
X-Cache-Hit
Upgrade-Insecure-Requests
X-Mobile-URL
X-Accel-Buffering
X-Response-Served-From
X-Hp-Webp
X-App-Server
Payment
Cache
X-Whom
X-Storage
X-Cache-TTL
X-TX-ID
X-B
X-SS-Set-Cookie
X-Content-Age
X-UA-Device-Type
X-WebKit-CSP-Report-Only
X-Yottaa-Optimizations
X-Handled-By
X-Yottaa-Metrics
X-TT-TIMESTAMP
X-Cacheable-TTL
X-GeoIP
X-Erf-Bev-Bev
Filters
X-Git-Hash
Xserver
X-RequestSource
X-Tumblr-Pixel-1
X-Erf-Bev-Bev-Is-Generated
X-Tumblr-Pixel-2
X-Adobe-Content
X-Adobe-Loc
X-VG-WebCache
Eomportal-Instance
X-WA-Info
Cache-Tv-Group
X-ProcessESI
Viewport
X-RemovedCookies
X-Status
X-Geo-Country
X-APP-VERSION
X-Ratelimit-Reset
Server-Info
NGB
Cache-Tag
X-FB-TRIP-ID
Webserver
Datacenter
X-Cache-TTL-Remaining
X-Cache-Enabled
Retry-After
X-TA-CDN-Provider
X-FW-Dynamic
X-Contextid
X-Ratelimit-Limit
X-Presslabs-Stats
X-Seen-By
S-Cnection
X-Host-Name
MS-CV
X-Origin-Server
Country
From-Origin
X-Mode
X-Hyper-Cache
X-PressLabs-Stats
Frame-Options
Machine
X-Cache-Var
X-AWS-Id
X-Path-Route
X-Cache-Config
X-RN-RSRV
X-VWS-Id
X-Tumblr-Pixel-3
X-LJ-Flow-ID
Meta-Geo
X-CF-Powered-By
X-Generated-By
X-Cache-Var-Map
X-ES-SERVER
Load-Balancing
X-Human
X-Upstream-CT
X-Routing-Service
X-Upstream-HT
X-Proxied
X-Labrador-Cache-Channel
X-Cache-Grace
X-Hit
Mail-Subject
DSUID
Cache-Key
X-RTag
Vix-Hermes-Req-Id
We-Hiring
X-Cache-Host
Ms-Operation-Id
X-Zipkin-Id
X-Backend-Name
X-Varnish-Cache-Hits
Release
X-Varnish-Hits
X-Magnolia-Registration
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Section
X-Guploader-Uploadid
X-TNCMS
X-Debug-Cache
X-From
X-OCL
X-EIG-Tracking-Id
X-Access
ServedBy
Uber-Trace-Id
X-Varnish-Server
X-Upgrade-Enabled
X-Viewer-Country
X-Web-Node
GEO-INFO
Mn-Server-Ip
Now
X-MP-GENERATED-AT
X-Device-Type
X-Loop
X-RCS-CacheZone
X-Rendered-As
X-PCL
X-R9-Blue-Green-Version
X-Cluster-Node
X-Origin-Response-Time
X-Rule
Akamai-GRN
X-Sorting-Hat-PodId
X-Proto
X-Akamai-Request-ID
X-Alternate-Cache-Key
X-BYPASS-REASON
X-VG-TLSProxy
Rt-Fastcgi-Cache
X-ProxyCache-Status
OT-Force-Account-Verify
X-ProxyCache-Key
X-CCM
X-Environment-Context
X-Shopify-Stage
X-ShardId
X-Sorting-Hat-ShopId
X-Endurance-Cache-Level
X-ShopId
X-L-Path
X-Via-Fastly
X-JoinUs
X-Generated
X-Proxy-Build
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Timing-Wait
X-Region
Cache-Name
X-Daa-Tunnel
X-Xfnlog-Site
X-FC-Vary-Parameters
X-S
DB-Nickname
X-NCache
X-VCT
X-Drupal-Cache-Contexts
X-Redis-Cache
NGX
X-Trace-Id
X-B3-Spanid
X-Nginx-Cache
X-Locale
X-Load-Cache
X-Site-Version
X-Platform-Server
X-UUID
X-Www-Served-By
X-Cache-NE
X-NewRelic-App-Data
Cteonnt-Length
ProcessTime
X-MServer
X-Hl-Ver
X-EdgeConnect-Cache-Status
X-Oracle-Dms-Rid
X-Vgn-Hpd-Reason
X-ECACHE
X-Cache-Remote
X-ServerID
X-Rocket-Nginx-Bypass
X-Real-IP
SRV
X-Request-Time
X-Time-Microsecs
X-IP
Time
Version
X-Origin
X-Wix-Request-Id
X-Via-CDN
X-FW-Version
X-IPS-LoggedIn
X-GEO
S-Rt
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
Azure-Version
Webcakes-Region
X-Origin-Hint
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Origin
X-Proxy
X-Dc
NtCoent-Length
L5d-Success-Class
X-No-Session
X-Oneagent-Js-Injection
X-FireWall-Port
Served-By
X-Distributor
X-Cache-Backend
CACHE
Fastly-SSL
X-RateLimit-Reset
Odigeo-Trace-Id
X-Unique-ID
X-UA
X-Akamai-Transformed
X-Microcachable
X-Pubstack
X-Cache-Server
X-Akamai-Request-ID2
X-PERF
Origin-Edge-Control
X-ApacheServer
Origin-Cache-Control
X-CS
X-Format
Fastcgi-X-Cache-Version
X-Webkit-Csp
X-Cache-Category-Id
IBM-Web2-Location
X-Grey
X-Powered-By-Defense
X-Edge
X-CDN-Forward
Hostname
X-HTML-Minification-Powered-By
Ec-Rule-Version
X-Compress-Hint
Proxy-Connection
X-Detected-As
X-UnsetCookies
X-Is-Bot
X-Via-NSCOPI
Cache-Tags
Access-Control-Request-Headers
X-BACKEND-TTL
X-Varnish-Cacheable
X-NC
Backend-Name
X-CF-Lambda-Version
HA-Ipaddr
X-CF-Lambda-Fn
X-Cdn-Srv
Request-Country
X-Tb
Ha-Gx-Prefs
X-Eu-Site
X-Connection-Hash
X-External-Request-Id
X-Cluster-Name
X-CGP
MD5-Digest
Meta-Geo-Continent
Xc-Version
Proxy-Firewall
X-HS-Cache-Config
X-HS-Combine-CSS
X-Worker
X-B-Cookie
X-Cache-Bucket
Mobile-Detection-Method
X-G
Node
Rendered-Blocks
Rt-Proxy-Cache
X-Edge-Server
X-DPWN-IS-SECURE
Fastly-SIE
X-Destination
X-Developer
Cache-Prefix
Cache-Cookie-Set-Lfrom
X-Date
X-Debug-Cookies
Cdn-Request-Time
X-Debug-Log
Content-Style-Type
Cdn-Host
Cross-Origin-Window-Policy
X-D
Fastly-SWR
Arc-Country
AsisCache
A
Request-EU
GEO-REGION-INFO
Request-Time
BehaviorPad-Version
Fly-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Fly-Request-Id
Content-Script-Type
X-IN-APIGATEWAY
X-Processor
X-ScT
X-A-Dcw
X-PAYTM-SRV-ID
X-A-Dgt
X-SRCache-Key
X-S-Maxage
X-Rebelmouse-Cache-Control
X-Rojux
X-S-Cookie
X-Internal-Host
X-Application
X-A-Wwc
X-App-Name
VivaBuild
X-A
X-Org
X-NU-AKA-ACS-Version
X-NX-Host
Viewtype
X-Aed
Server-ID
X-Server-Time
X-AIR-PT
X-Accel-Expires-Debug
X-Transaction
X-ARC
LB
X-Request-UUID
X-Trv-Group
X-Vtex-Processado-Em
X-Rebelmouse-Surrogate-Control
X-A-Ccd
X-Region-Sid
ServerName
X-Instart-Info
X-VG-WebServer
X-Vtex-Remote-Cache
PageSpeed
X-Rewrite-Enabled
X-A-Dam
X-Twitter-Response-Tags
X-B3-Parentspanid
X-ElasticPress-Search
Is-Eu
Countrycode
On-Server
Esi-Enabled
X-Reqid
X-ServiceProvider
Platform
X-Request-URI
X-PHP-Host
X-Core-Mission
X-Qloud-Router
X-Clientip
Memcached
X-Cache-Info
Gh-Request-Id
X-Cache-Id
X-Server-IP
X-Cdn-Origin
True-Client-Country-4JS
X-Variation
RNT-Machine
RNT-Time
X-Ua
Resin-Trace
X-TH-Server
X-Fastly-Cache
X-Generated-On
X-Geo-Header
Server-Host
X-We-Are-Hiring
Server-Int
Section-Io-Cache
X-Hash
X-C
X-GeoIP-Country-Code
Country-Code
SS
X-Level-Front-Cache
Apple-News-Services-Request-Url
X-Epic-Correlation-Id
X-Sn-Servicetimems
X-Location
X-Nginx-Cache-Key
X-Skip-Cache
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Dispatcher-Server
X-Backend-State
X-Irp-Debug
Apple-News-Services-Handled
X-Key
X-Dispatch
Adler-Geo
X-BBXSRF
X-Amz-Meta-Cache-Control
X-Auto-Login
X-Gannett-Site-Version
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Li-Fabric
X-SVT-ORM-RULES
X-Swa-Ws
X-SVT-ORM-VERSION
X-Method
X-ND-Cache
X-SD-PageType
X-Response-By
X-Request-Start
X-Secret
X-Served-From
X-SIPLIST1
X-Servername
X-WebServer
X-Webstats-RespID
X-Distil-CS
X-Fetched-On
X-FPC
X-Device-Os
X-Crawler
X-Cache-FS-Status
X-CDN-Cache
X-Reboot
X-Gen-Mode
X-Wikidot-Static-Cache
X-Wikidot-Backend
W
X-Hnp-Log
X-Generation-Time
X-Developers
X-Block-Status
REQUESTUUID
Powered-By
Pramga
SD-X-WS
UCS
PFcat
Mime-Version
AKAMAI
CDCHOST
Content-Disposition
IsBot
User-Cache-Control
X-Nc
Wxu-Next-Hostname
Accept-Language
V-Age
Web-Mar-Node
Who
Wxu-Next-Region
Wxu-Next-Commit
X-SERVER-NAME
X-Datadome
X-Release
X-GeoIP-City
X-Thinkindot-L3
X-Clara-WADP
X-VServer
X-Cms-Context
X-CUA
X-Matched-Rule
X-Owner
X-Origin-Date
GW-Server
X-Protected-By
Fastly-Soc-X-Request-Id
X-Via-Edge
X-Origin-Expires
X-WADP-Cache
Heartbleed
X-Bip
Thinkindot-CacheControl
X-Azure-Ref-OriginShield
X-Azure-Ref
X-Varnish-Url
CF-IPCountry
X-Via-SSL
Thinkindot-Control
X-Thanos
Thinkindot-CacheControl-Type
X-Parent-Response-Time
X-Varnish-Ttl
X-OVcl
X-OVcl-Cache
X-CLOUD-TRACE-CONTEXT
L
Pragrma
X-VC-Cache
X-Fstrz
N-Cache
X-Ratelimit-Remaining
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Planisys-CDN-TTL
X-TrackingId
X-Amzn-Remapped-Content-Length
Kp-EeAlive
X-LAGOON
X-FE
X-Planisys-CDN-Rules
X-Cdn-Forward
Memory
X-Planisys-CDN-Cache
X-GRACE
X-Origin-TTL
Selected-Fe
X-Varnish-Beresp-Ttl
X-Origin-CC
X-B3-SpanId
User-Agent
X-Phone
X-Core-Value
X-Pf-Uncompressing
X-IN-WAF
X-Urbn-Site-Id
X-DC
X-Be
X-Urbn-Context-Path
Locale
X-Page-Type
Magicmarker
X-Birta-Served
X-Birta-Cache-Post
X-URL
X-Zone
X-Ttl
X-Geo
X-Varnish-IP
X-Info
X-Dynatrace-Js-Agent
X-Varnish-Beresp-Status
X-ABtesting
Pagetype
HitType
X-Varnish-Beresp-Grace
X-Flog
Selected-FE
X-Hello
X-User
Cdn
X-Backend-TTL
X-Generated-In
X-TT-LOGID
X-Backend-Host
X-Backend-Url
X-Newrelic-Synthetics
X-Litespeed-Cache
SN
X-Debug-Cache-Store
GeoIp-Country-Code
X-Debug-Cache-Fetch
X-Servedbyhost
X-Debug-Cache-Expiry
X-Soup
X-GoCache-CacheStatus
X-Up
X-MSEdge-Features
Geoip-Latitude
Geoip-City
X-MSEdge-Flight
X-Tt-Trace-Tag
X-App-Version
X-Source
X-MID
X-Mid
X-Cache-Debug
CF-Cached-On
X-Agile-Age
X-Agile-Id
X-Agile
X-Cache-Ttl
X-HS-Status
X-Refresh
X-Real-Ip
X-Web-Server
X-Check-Cacheable
X-Aicache-OS
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-VCL-Version
X-Oss-Server-Time
X-Oss-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Ruxit-Js-Agent
X-ZONE
FSS-Cache
X-Vcl-Version
X-Tb-Optimization-Total-Bytes-Saved
FSS-Proxy
X-ServedByHost
X-Old-Content-Length
X-Amzn-Remapped-Date
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Amzn-Remapped-Connection
GeoIP-Country-Code
X-Bc
X-CACHE-KEY
Server-Cache-Control
Server-Surrogate-Control
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Cache-ASPX
X-UPSTREAM-Address
X-APP
HostName
GeoIP-City
GeoIP-Latitude
Cache-Hits
X-EC-Lua
Ohc-File-Size
Ohc-Cache-HIT
X-NWS-UUID-VERIFY
X-Via-Ucdn
Group
WZWS-RAY
X-COUNTRY
RequestId
Srv
X-CSRF-Token
HTTPS
Inserted-Into-Cache-At
Fastly-Backend-Name
X-Akamai-SSL-Client-Sid
X-Node-Id
X-Nananana
X-BC
X-CSRF-TOKEN
X-WR-MODIFICATION
Www
X-IN-APIGATEWAYSSL
X-SN
X-ECache
X-Proxy-Cacherz
Backend
Xkeyrz
X-Varnish-Beresp-TTL
X-Logtrace-Id
Ajk
WebServer
X-Dynatrace
XServer
X-Cache-Time
X-Cache-Tag
Cf-Ipcountry
X-Instart-Isnd
URI
Host-ID
Lb
X-Unique-Id
Xkeynj
Get-Access-Time
X-RateLimit-Remaining-Second
X-Cache-Expires
X-FORWARDED-FOR
X-BE
X-Wa
X-TIME
X-Request-Url
Is-Session-Tracking
X-RateLimit-Limit-Second
X-Fastly-Country-Code
Requestid
X-PAGE-TYPE
X-MCACHE
X-LiteSpeed-Cache-Control
X-Cache-Miss-From
X-Requestid
X-Edge-IP
X-Sedo-Request-Id
Dynatrace
X-NGENIX-Cache
X-PJAX-URL
X-LB-ID
PICS-Label
Epwk-Cache
T-Server
X-Fastly-Backend-Reqs
X-Varnish-Action
Cneonction
X-PF-Uncompressing
Xet-Cookie
DataCenter
X-SRV
X-Apw-Hits
X-Apw-Access-Token
X-Pjax-Url
Fastcgi-X-Cache
X-Swift-Error
X-GDPR
X-Apw-Access-Object
Pics-Label
X-Apw-Access-Action
X-Render-Time
CDN
X-Micro-Cache
X-Vct
X-Dw-Trace-Id
X-NGINX-Cache
X-WA
X-Svr
X-Lb-Id
X-Ecache
Correlation-Id
X-Cf-Powered-By
X-AssetVersion
MIME-Version
X-Policy
SID
X-ServerName
X-Serial
X-WPE-Loopback-Upstream-Addr
RequestUuid
X-Uri
Ohc-Response-Time
X-Var-Ttl
X-LiteSpeed-Tag
X-DI
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Bug-Bounty
X-Fastly-Cache-Hits
X-Zalando-Child-Request-Id
FNAC-ModuleRouting
X-Page-Impression-Id
X-Flow-Id
Warning
Lfy
X-RPM
X-RPS
X-RSL
X-DW
X-DSS
X-Html-Edge-Cache
X-Sf
X-DB
X-Fpc