Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
P3P
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Accept-CH
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
P3p
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Permissions-Policy
X-Request-ID
X-Ua-Compatible
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-CDN
X-Check
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
Cf-Apo-Via
X-Turbo-Charged-By
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
EagleId
X-UA-Device
X-Server
X-Dispatcher
X-Vhost
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Dns-Prefetch-Control
Accept-CH-Lifetime
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Litespeed-Cache
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Allow
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Cache-Lookup
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
Xkey
X-Akam-SW-Version
EagleEye-TraceId
X-Host
Surrogate-Control
X-Response-Time
X-Readtime
Cf-Railgun
X-Node
X-HW
X-Ruxit-JS-Agent
X-LiteSpeed-Cache
X-Server-Id
Request-Id
X-Country
X-Url
X-Nginx-Cache-Status
X-Content-Type
Cache-Tag
Content-Location
X-Nginx-Upstream-Cache-Status
X-Application-Context
X-NWS-LOG-UUID
X-Clacks-Overhead
Service-Worker-Allowed
X-Trace
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Amz-Server-Side-Encryption
X-Country-Code
X-Rack-Cache
X-Times
X-TtlSet
X-PC
X-Vname
X-Mcache
X-Midtier
X-Edge
Rating
Surrogate-Key
X-Server-Name
X-Middleton-Display
Pagespeed
X-Sol
X-Cache-TTL
Display
X-Browser-Type
X-Cnection
X-Element-Page-Cache
X-Abt-Application-Version
X-Oneagent-Js-Injection
X-ESI
X-Cdn-Fetch
Nginx-Cache
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Ser
Edge-Control
Verso
X-Ac
X-D2id
X-Vcap-Request-Id
X-ECACHE
X-MS-InvokeApp
X-Client-IP
X-Dw-Request-Base-Id
X-ARC
X-B3-TraceId
X-Middleton-Response
X-Amz-Rid
Response
X-CST
X-ORACLE-DMS-RID
X-Goog-Hash
X-Powered-CMS
X-Navigation-Version
X-Server-ID
X-Wormhole-Sdk
X-Upstream
X-Edge-Location-Klb
X-Kinsta-Cache
X-Erf-Bev-Bev-Is-Generated
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
Accept-Ch-Lifetime
X-Daa-Tunnel
X-Forwarded-For
X-Ratelimit-Limit
X-Amzn-Trace-Id
X-NF-Request-ID
RTSS
X-Cache-Key
SPRequestDuration
SPIisLatency
X-Ratelimit-Remaining
X-Mod-Pagespeed
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-SID
Edge-Cache-Tag
Cache-Status
X-Ttl
Public-Key-Pins
X-FastCGI-Cache
X-Ruxit-Js-Agent
X-Version
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Content-Digest
X-Mg-S
X-SharePointHealthScore
SPRequestGuid
S
Realpath
Cross-Origin-Resource-Policy
X-MSEdge-Ref
AR-CACHE
X-Fastly-Request-ID
Fastcgi-Cache
X-T
X-Shield-Request-Id
X-Cached
X-Ua-Device
X-Recruiting
X-Varnish-TTL
X-Accel-Expires
Front-End-Https
X-Distributor
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Access-Control-Request-Method
TP-Cache
X-Azure-Ref
X-Newrelic-App-Data
X-Id
Arr-Disable-Session-Affinity
X-Request-Received
X-Request-Processing-Time
X-Ua-Browser
X-Debug
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
Count-Hit
MicrosoftSharePointTeamServices
Server-Node
Origin-Trial
X-Content-Security-Policy-Report-Only
X-Correlation-Id
X-LLID
Cache-Tags
X-Ismobilevalue
Pinterest-Generated-By
X-TTL
X-Pinterest-Rid
Pinterest-Version
X-Cluster-Name
X-PressLabs-Stats
X-VARITI-CCR
X-Frontend
X-HS-Combine-CSS
X-Hits
Accept-Ch
X-GUploader-UploadID
X-Varnish-Backend
Payment
X-Amz-Replication-Status
X-Goog-Metageneration
X-Protected-By
X-Xrds-Location
X-NGENIX-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-LB-Cache
X-Forwarded-Proto
Cleartype
X-Unique-Id
X-Varnish-Server
X-FB-Debug
X-Logged-In
X-Www-Served-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Git-Hash
X-Az
X-AppVersion
X-Activity-Id
Host
Filterid
X-Ratelimit-Reset
Content-Disposition
X-Hostname
X-Page-Id
X-App-Server
X-DIS-Request-ID
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Cambria-Cache-Control
X-Fastcgi-Cache
Akamai-GRN
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Nf-Request-Id
X-Template
X-Geo-Country
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-FTR-Request-ID
X-Aspnet-Version
Access-Control-Allow-Method
X-ASPNET-VERSION
Frame-Options
X-Origin-Server
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Load-Cache
X-WP-CF-Super-Cache
X-Varnish-Ttl
Retry-After
MS-Author-Via
X-Upgrade-Enabled
X-WP-CF-Super-Cache-Cache-Control
X-Type
Fastly-SIE
Fastly-SWR
Version
X-Ah-Environment
Viewport
Section-Io-Cache
X-TT
X-Cache-Control
X-Content-Options
Accept-Charset
X-Fb-Rlafr
Content-MD5
X-B
X-B3-Sampled
X-Rid
X-Grace
Amp-Access-Control-Allow-Source-Origin
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Envoy-Decorator-Operation
X-Source
X-Request-Guid
X-Vcl-Version
Trailer
X-Trace-Id
X-Cdn
X-Device-Type
X-Revision
X-Cache-Age
Server-Name
X-Language
X-Magnolia-Registration
Healthy
X-Buckets
X-Webkit-CSP
X-RateLimit-Remaining
X-Aspnetmvc-Version
X-Px
X-Origin-Cache
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-WP-CF-Super-Cache-Active
X-Mobile
X-CSRF-Token
X-Contextid
X-Backend-Name
X-Amz-Meta-S3cmd-Attrs
X-Akamai-Edgescape
TCN
X-TraceId
X-HS-Prerendered
X-RM-Cache-TTL
X-Status
X-Rule
X-NYM-Debug-Backend
X-L-Path
X-Instance
X-Environment-Context
X-Proxy
X-Debug-Info
X-FW-Server
X-FW-Static
X-Proxy-Cache-Info
Access-Control-Request-Headers
X-App-Environment
X-ServerID
X-Tumblr-Pixel
X-Region
X-HTML-Minification-Powered-By
X-FW-Version
X-Varnish-Grace
X-Edge-Location
X-FW-Type
X-UUID
X-Tumblr-Pixel-0
X-Webkit-Csp
SD-X-WS
NGB
X-FW-Hash
GEO-INFO
X-Tumblr-Pixel-1
X-Mg-Request-UUID
X-Tumblr-User
X-EdgeConnect-Cache-Status
X-FW-Serve
X-FW-Dynamic
X-Rendered-As
X-Node-Name
X-Storage
X-Content-Powered-By
X-Adobe-Loc
X-Is-Bot
X-Datadog-Trace-Id
X-Datadog-Parent-Id
Cross-Origin-Window-Policy
X-Cache-Time
X-Adobe-Content
X-Framework
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-RTag
Ms-Operation-Id
MS-CV
X-Yottaa-Optimizations
X-Cacheable-TTL
X-Yottaa-Metrics
X-Debug-IsConnected
X-Debug-IsPreview
X-G
Charset
X-RemovedCookies
Protected
Upgrade-Insecure-Requests
X-ProcessESI
DC
X-Seen-By
X-Whom
Countrycode
Paypal-Debug-Id
X-User-Agent
Webserver
Cross-Origin-Embedder-Policy-Report-Only
OT-Force-Account-Verify
X-Original-Request-Id
X-Lambda-Id
X-Response-Served-From
Refresh
Front
Section-Io-Id
X-Reqid
X-ECache
X-VHOST
X-TT-LOGID
X-VC
X-Amzn-Remapped-Content-Length
Alternate-Protocol
SRV
X-WebKit-CSP-Report-Only
X-B3-Traceid
X-IPS-LoggedIn
X-AB
X-Akamai-Request-ID2
X-Cache-Status-Check
X-N
X-Server-W
Country
Priority
X-WP-CF-Super-Cache-Cookies-Bypass
Backend
X-B3-SpanId
Liferay-Portal
X-Time
X-Real-IP
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Nginx-Cache
X-Mode
Onion-Location
X-Rocket-Nginx-Serving-Static
X-Format
Filters
Fastcgi-Useragent
Meta-Geo
X-Cache-Host
X-Rewrite-Enabled
X-JoinUs
X-SaId
X-UPSTREAM-Address
X-Rn-Rsrv
ServerID
X-Request-URI
X-Restarts
X-Origin-Hint
X-Origin-Date
Property-Id
From-Origin
X-Say-Cacheable
X-Say-TTL
X-Varnish-Age
Environment
X-Tumblr-Pixel-2
X-Tb
X-SayCDN-TTL
X-Scope-Id
X-IPLB-Request-ID
X-IPLB-Instance
Webcakes-Region
Webcakes-App-Version
X-Accel-Version
X-Hosted-By
X-Frame-Option
X-Cluster-Node
Webcakes-App-Name
Web-Mar-Node
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
X-VC-Cache
X-R9-Blue-Green-Version
X-Hl-Ver
Xet-Cookie
Atl-Traceid
X-Web-Node
X-Loop
X-Logging-Id
X-PHP-Host
X-ProxyCache-Key
X-Forwarded-Host
X-ProxyCache-Status
X-Labrador-Cache-Channel
X-Fastly-Request-Id
Uber-Trace-Id
X-Cache-Expired-At
X-Cms-Context
X-Director
X-Fetched-On
X-Cache-Action
X-BYPASS-REASON
X-Redis-Cache
X-Httpd
X-Handled-By
Mn-Server-Ip
Apigw-Requestid
X-Webstats-RespID
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Skip-Cache
X-Tncms
X-Vcache
Url
X-Servername
X-FB-TRIP-ID
X-Origin-TTL
ServedBy
X-Cluster
X-Adobe-Source
X-Origin-CC
X-Soup
Cross-Origin-Embedder-Policy
X-Origin
X-Served-From
Selected-Fe
Accept-Language
X-Auth-Group-Type
X-Proxied
Expiry
DB-Nickname
X-Timing-Wait
X-Extlb
X-Routing-Service
X-Connection-Hash
X-Detected-As
X-Cloudmap
X-S
X-Proxy-Build
X-Zipkin-Id
X-Hit
Referer-Policy
X-Generated-By
X-Ms-Request-Id
X-Ms-Version
X-DynaTrace
X-DataDome
X-SRV
WPO-Cache-Message
X-Wix-Request-Id
X-XRDS-Location
WPO-Cache-Status
X-Lagoon
X-Tumblr-Pixel-3
VIX-Pulpo-Node
N-Cache
VIX-Pulpo-Upstream-Status
Xserver
X-LSADC-Cache
X-Xfnlog-Site
Cross-Origin-Opener-Policy-Report-Only
Surrogated-Key
X-Azure-Ref-OriginShield
X-RateLimit-Limit-Second
X-Worker
X-RateLimit-Remaining-Second
X-CLOUD-TRACE-CONTEXT
Source
X-NWS-UUID-VERIFY
X-App-Version
X-Generation-Time
X-Sucuri-Cache
LB
CF-IPCountry
X-Cache-Debug
X-Via-JSL
Ohc-File-Size
X-VCT
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-RCS-CacheZone
X-F-Cache
X-HS-CF-Cache-Status
CDN-RequestId
X-Cdn-Origin
Node
X-Proxy-Cache-Status
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
X-MP-GENERATED-AT
X-Geo-Region
X-Tcp-Rtt
X-Browser-Name
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Cache-Hit
X-NODE
X-Upstream-Ht
X-B-Cache
X-Upstream-Ct
X-Tx-Id
X-Varnish-Beresp-Ttl
X-Signature
X-No-Session
X-Sucuri-ID
X-TA-CDN-Provider
X-Litespeed-Tag
X-ElasticPress-Query
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-Sorting-Hat-PodId
X-FTR-Backend-Server
X-Cache-Rule
X-Cache-Operation
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-FTR-Backend
X-Storefront-Renderer-Rendered
X-UA
Cache
X-FTR-Balancer
Cluster
X-Csrf-Jwt
X-D
X-Debug-Cache-Fetch
X-Ec-Fail
X-FC-Vary-Parameters
X-Eu-Site
Apple-News-Services-Handled
X-GeoCode
X-GeoCountry
X-Ig-Origin-Region
X-Vtex-Remote-Cache
Xc-Version
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Candidate-Md5Url
X-DPWN-IS-SECURE
X-Developer
Cache-Provider
X-Ec-GeoHdr
Apple-News-Services-Request-Url
BehaviorPad-Version
X-Debug-Cache-Store
X-Conf
X-Backend-Instance
X-App-Name
Sslversion
X-Aicache-OS
X-Bc-Bl
X-BCube-Filmed-By
Producers
Redirect-Candidate
Rendered-Blocks
X-Aed
X-Access
X-A-Ccd
W
We-Hiring
X-A
X-A-Dam
X-A-Dcw
X-A-Wwc
X-A-Dgt
User-Agent
X-Bug-Bounty
Origin
Fastly-GeoIP-CountryCode
Fl-Custom-Application
X-CGP
Ha-Gx-Prefs
Fastly-Backend-Name
Expect-Staple
DCR-Decision-By
DCR-Processing-Time-Ms
X-Ig-Push-State
HA-Ipaddr
Host-ID
Meta-Geo-Continent
X-Cache-Info
Ngx.Var.Host
Odigeo-Trace-Id
MD5-Digest
Mail-Subject
L5d-Success-Class
Lang
X-Cache-NE
Content-Secure-Policy
X-Gdpr
X-Nyt-Route
X-Vdms-Version
X-ORCA-Accelerator
X-Proxied-Request
X-ScT
X-Section
X-TIM-N
X-Mvc-Supplant-Cachable
X-Mly-Id
AMP-Access-Control-Allow-Source-Origin
X-Proto
X-Rojux
X-Origin-Time
X-Platform-Server
X-Path
Mime-Version
X-INCAP-ABP
X-Cached-By
X-SIPLIST1
X-Slack-Backend
IsBot
L
X-Shield-Cache-Expires
X-Origin-Expires
NM-Fastcgi-Cache
X-SD-PageType
X-CacheTTL
X-PAYTM-SRV-ID
Web-Mar-Region
X-Cdn-Srv
Esi-Enabled
X-Thinkindot-L3
Wxu-Next-Hostname
X-Node-Id
X-Content-Length
X-Content-Age
Fastly-SSL
Wxu-Next-Commit
X-Service
X-Slack-Shared-Secret-Outcome
Gh-Request-Id
X-Clientip
X-NodeID
Gannett-Cam-Experience-Id
X-Cache-Id
X-Cache-Grace
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Device-Characteristics
X-Req
V-Age
X-B3-Trace-ID
X-Auto-Login
X-AK-Request-ID
TDXMobile
X-AB-Test
X-Policy
X-Accel-Expires-Debug
X-Org
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Server-Host
X-BBC-Edge-Cache-Status
X-SB
X-Core-Value
Platform
X-Cache-Aspx
X-Powered-By-VTEX-Cache
PFcat
Product
X-Bl-Debug
RNT-Machine
RNT-Time
Req-Svc-Chain
X-Op-Id-All
X-Platform
Origin-Agent-Cluster
X-Contensis-Viewer-Groups
X-Fmm-Version
Wxu-Next-Region
X-Origin-Response-Time
X-Loc
X-GeoIP-Country-Code
X-GeoIP
X-Esi-Check
X-Epic-Correlation-Id
Azure-InstanceId
Azure-RegionName
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Edge-Server
X-Micro-Cache
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-VTEX-Cache-Time
X-HS-Content-Campaign-Id
X-VTEX-Cache-Server
X-VG-WebCache
X-Irp-Debug
X-Viewer-Country
X-We-Are-Hiring
X-HN
X-Gzip
X-Wikidot-Static-Cache
X-Hash
X-Jobs
X-Wikidot-Backend
Azure-SiteName
X-Fastly-Backend
X-DefHash
X-DefElseHash
Cdn-Request-Time
Azure-SlotName
Cdn-Host
X-Mvc-Supplant-OutputCached
Cdncip
X-Var-Ttl
X-NMSegId
X-Date
Cdnsip
X-Varnish-Authentication
X-Depends
X-Varnish-Director
Azure-Version
X-Varnish-CookieHashed-On
CDCHOST
X-Varnish-CookieINHashed-On
X-Pad
X-Locale
Akamai-Mon-Iucid-Del
X-Acquia-Purge-Cdn-Unconfigured
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Fastly
X-SVT-ORM-VERSION
X-Pubstack
X-Ec-Custom-Error
X-V-Cache
X-Server-IP
X-CUA
X-Internal-TTL
X-VG-TLSProxy
X-Human
X-Vmg-Version
X-Scheme
X-Hnp-Log
X-UA-Device-Type
X-SVT-ORM-RULES
X-Geolocation
X-Request-Time
X-Request-Start
X-Sn-Servicetimems
X-VServer
X-Gamma-Serve
X-Block-Status
X-Men
X-Varnishpool
X-Request-Host
X-Gen-Mode
X-Amz-Storage-Class
XM
X-Level-Front-Cache
X-Dispatcher-Server
Yak-Timeinfo
X-GeoIP-City
X-Generated-On
X-Location
X-Varnish-Beresp-Status
X-Cache-FS-Status
Release
Country-Code
Content-Style-Type
Content-Script-Type
Click-Count-Error
Debug
DSUID
Req-ID
Origin-CC
NGX
Click-Count-Action-Start
CDN-Uid
CDN-CachedAt
CDN-Cache
Canary
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-RequestCountryCode
ServerName
Origin-EX
Tube-Got-Eval
Tube-Get-Contents
Tube-Got-Results
Tube-Return
User-Cache-Control
X-CDN-Forward
X-Site-Version
X-Newrelic-Synthetics
X-LB-NoCache
X-Via-Edge
X-RID
X-External-Request-Id
X-HOST
XkeyRZ
X-IsAdmin
X-Destination
X-Via-CDN
Edge-Copy-Time
X-B-Cookie
X-Application
X-Via-SSL
X-Varnish-Hits
X-Pool
A
X-Cache-Bucket
Pramga
X-S-Cookie
X-Thanos
X-Bip
X-RateLimit-Limit
X-Proxy-CacheRZ
X-NGINX-Cache
Cache-Key
X-Cdn-Forward
Ssr
X-GEO
X-CACHE-GROUP
X-Cache-Date
X-Api-Version
X-Resp-Is-Stale
X-ZONE
Sid
X-Cs
X-Zen-Fury
X-Refresh
X-Oracle-Dms-Ecid
X-User
TP-L2-Cache
X-Optimistic-Header
X-HITS
X-Nananana
X-Servedbyhost
CloudFront-Viewer-Country
X-APP
X-Dc
Cdn-Requestid
X-VC-TTL
X-RequestId
GeoIP-Latitude
X-DC
Fastly-Drupal-HTML
X-Air-Pt
X-B3-Spanid
X-Tt-Logid
X-Via-Popv
X-HA-Backend
Proxy-Firewall
Server-ID
Ohc-Cache-HIT
X-Via-Popn
X-Via-Poph
C-Via
X-Webkit-Csp-Report-Only
X-Nc
X-Wa
X-LB-ID
X-Endurance-Cache-Level
Fastly-Drupal-Html
True-Client-Country-4JS
X-TH-Server
X-B3-Parentspanid
Sever-Int
Server-Hostname
X-LiteSpeed-Cache-Control
X-Vgn-Hpd-Reason
X-AIR-PT
Server-Ext
X-Test
Cdn
X-XRDS-LOCATION
X-Presslabs-Stats
X-LiteSpeed-Tag
X-VWS-Id
Is-Eu
Adler-Geo
X-Old-Content-Length
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-DynaTrace-JS-Agent
X-COUNTRY
X-AWS-Id
X-URL
HostName
X-Moov-T
WP-Super-Cache
X-LJ-Flow-ID
X-CS
X-Provided-By
X-Datadome
X-Nginx-Cache-Key
SID
GeoIp-Country-Code
X-Dispatcher-Number
X-CACHE-AGE
X-Srv
X-Parent-Response-Time
X-Zone
X-DataCenter
WZWS-RAY
X-HubSpot-Correlation-Id
X-Fpc
X-API-Version
X-Action
X-Oracle-Dms-Rid
T-Server
X-Custom-Header
X-NewRelic-App-Data
X-Geo-Header
X-Pass-Why
S-Rt
X-Litespeed-Cache-Control
Uri
True-Client-Ip
X-Vercel-Id
Location
X-Vercel-Cache
X-Cache-VC
X-Thinkindot-L1
X-ND-Cache
Cache-Tv-Group
N1-Cache
Vc-Max-Age
X-Cache-Server
True-Client-IP
SEZNAM-JOBS-OFFER
X-CMSURLCustom
X-Ua
X-Stale
Pics-Label
Resin-Trace
X-SERVER-NAME
X-TX-ID
GeoIP-Country-Code
Tcn
Powered-By
X-Datacenter
Serverhost
X-Varnish-Beresp-TTL
TWC-GeoIP-City
X-Dynatrace-Js-Agent
TWC-GeoIP-Region
X-Client-Ip
TWC-GeoIP-DMA
Cache-Hits
X-PERF
X-WA-Info
X-ApacheServer
X-Render-Time
Vix-Hermes-Req-Id
X-FPC
Sm-Log-Id
X-Service-Response-Time
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Srv
X-Fastly-Cache
X-Nitro-Cache
X-Cache-TTL-Remaining
X-Uri
X-APP-VERSION
X-Ckpd-Fst-Backend
Lb
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
X-Jungle-Id
Thinkindot-Control
X-Ion-Hop
X-Cdn-Cache-Status
Hostname
X-Ion-Healthy
On-Server
Cache-Contol
Log-Origin
Av-Poweredby
X-Fastly-Cache-Status
RewriteTeamHook
X-Debug-Service
RewriteTestHook
My-App
Server-Id
X-Udemy-Cache-App-Namespace
X-Air-Hostname
Cmsid
Cmstype
X-Air-Source
ServerHost
X-NC
X-Air-Trace-Id
X-WA
X-Vc
X-Ee-Request-Id
X-Ee-Request-Date
Store-Cloud-Cache
X-Amz-Meta-Opti
AKAMAI
Geoip-Latitude
Cf-Ipcountry
X-Up
X-Save-Cache
X-PHP-Backend
X-Lb-Id
X-Cms-Device
X-Vary-Devices
Time-Cloud-Cache
X-Ee-Generated-By
X-Ee-Origin
X-Correlation-ID
X-Cache-Ttl
X-Via-PopN
X-Oracle-DMS-ECID
X-Via-PopH
X-Fastly-Backend-Reqs
CacheControlHeader
Xkeylog
Xkey-La3
X-Ha-Backend
X-From
X-Via-PopV
X-Github-Request-Id
X-Proxy-Cache-La3
X-Esi
Magicmarker
X-VTEX-Cache-Backend-Connect-Time
X-Akamai-Pragma-Client-IP
X-VTEX-Cache-Backend-Header-Time
Cl-Cache
X-Info
X-App
X-VCL-Version
X-Sucuri-Id
Cloudfront-Viewer-Country
X-IAuth-Set-Uid
X-Limited
X-Requestid
X-ServedByHost
WWW-Authenticate
X-Geo
X-Traceid
WebServer
CountryCode
X-LAGOON
NtCoent-Length
X-MSEdge-Flight
X-MSEdge-Features
X-Dw-Trace-Id
X-CDN-Cache-Status
Warning
X-HS-Status
CDN
Reporter
X-Lb-Nocache
X-New
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Rollout
X-Wp-Cf-Super-Cache-Cache-Control
X-Acquia-Application-UUID
FSS-Cache
X-Serial
X-Pod
X-Akamai-Transformed
X-Wp-Cf-Super-Cache
X-Eligible
X-Check-Cacheable
X-Acquia-Site
X-V
X-Web-Server
X-Varnish-Hostname
X-BBC-Origin-Response-Status
Thinkindot-Cache-Type
Origin-Site
Epwk-X-Cache
X-Lsadc-Cache
X-Td-Header-From-No-Data
X-Akamai-ERPolicy
X-Platform-Router
X-Ramcache
X-Ms-Blob-Type
X-Platform-Processor
X-Platform-Cluster
CF-Cached-On
X-Forwarded-Site
X-Ms-Lease-Status
X-Tncms-Bot-Tier
X-Region-Sid
Machine
X-Orig-Cache-Control
X-Akamai-ERRuleID
Cneonction
Timeexpire
X-Elasticpress-Query