Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Accept-CH
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
Permissions-Policy
X-Drupal-Dynamic-Cache
X-Request-ID
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Accept-CH-Lifetime
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-AspNetMvc-Version
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-Amz-Id-2
X-Hacker
X-UA-Device
Cf-Apo-Via
X-Cache-Group
X-Turbo-Charged-By
X-Proxy-Cache
X-Age
Keep-Alive
X-Rq
EagleId
X-Via
X-Vhost
X-Dispatcher
X-Server
X-Check
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Litespeed-Cache
X-Varnish-Cache
Grace
X-OneAgent-JS-Injection
X-Server-Powered-By
X-WebKit-CSP
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
Allow
Xkey
X-Dns-Prefetch-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cache-Lookup
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
X-Akam-SW-Version
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-HW
X-Node
X-Server-Id
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Nginx-Cache-Status
X-Url
Content-Location
X-Country-Code
X-Content-Type
Cache-Tag
X-Nginx-Upstream-Cache-Status
X-Trace
Fastly-Restarts
Service-Worker-Allowed
X-Clacks-Overhead
Cross-Origin-Opener-Policy
X-Application-Context
X-NWS-LOG-UUID
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-LiteSpeed-Cache
X-Times
X-Vname
X-TtlSet
X-PC
Surrogate-Key
X-Edge
X-Midtier
X-Mcache
Rating
X-Server-Name
X-Cache-TTL
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Cnection
X-Element-Page-Cache
X-Browser-Type
X-Abt-Application-Version
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Exp-Variant
X-Exp-Id
X-ESI
X-GoogleNews-Bot
X-Cdn-Fetch
Nginx-Cache
Edge-Control
X-ECACHE
X-Vcap-Request-Id
Verso
X-D2id
X-Ac
X-Ser
X-MS-InvokeApp
X-Ruxit-Js-Agent
X-ORACLE-DMS-RID
X-Ratelimit-Limit
X-Client-IP
X-Amz-Rid
X-Middleton-Response
Response
X-ASPNET-VERSION
X-Wormhole-Sdk
X-Ratelimit-Remaining
X-CST
X-ARC
X-Powered-CMS
X-Dw-Request-Base-Id
X-Goog-Hash
X-B3-TraceId
X-Navigation-Version
X-Edge-Location-Klb
X-Kinsta-Cache
X-Server-ID
X-Kraken-Loop-Name
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Upstream
X-Server-Lifecycle-Phase
X-Forwarded-For
X-Amzn-Trace-Id
X-FastCGI-Cache
SPRequestDuration
SPIisLatency
X-Cache-Key
RTSS
X-Oneagent-Js-Injection
X-Mod-Pagespeed
X-Daa-Tunnel
Edge-Cache-Tag
Cache-Status
Public-Key-Pins
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
X-Content-Digest
X-Aspnetmvc-Version
X-Ezoic-Cdn
X-NF-Request-ID
X-Version
X-Ttl
Origin-Trial
SPRequestGuid
X-SharePointHealthScore
X-Mg-S
Realpath
S
X-FTR-Request-ID
X-MSEdge-Ref
X-Shield-Request-Id
X-T
X-Fastly-Request-ID
Fastcgi-Cache
X-ORACLE-DMS-ECID
X-Recruiting
Front-End-Https
Cross-Origin-Resource-Policy
AR-CACHE
X-Accel-Expires
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cached
X-Distributor
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Xrds-Location
X-Azure-Ref
X-TTL
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-Varnish-TTL
TP-Cache
X-Request-Processing-Time
X-Request-Received
X-HS-Cache-Config
X-Ua-Browser
Count-Hit
X-HS-Content-Id
X-Id
X-HS-Hub-Id
X-Debug
X-Correlation-Id
X-LLID
Cache-Tags
X-Ismobilevalue
X-Cluster-Name
Server-Node
X-Content-Security-Policy-Report-Only
X-Newrelic-App-Data
X-PressLabs-Stats
X-Nf-Request-Id
MicrosoftSharePointTeamServices
Akamai-GRN
X-VARITI-CCR
X-NGENIX-Cache
Accept-Ch-Lifetime
X-GUploader-UploadID
X-Frontend
Accept-Ch
X-Varnish-Backend
X-Amz-Replication-Status
X-Protected-By
X-HS-Combine-CSS
X-Hits
X-Goog-Metageneration
Payment
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
X-Ratelimit-Reset
X-Unique-Id
X-LB-Cache
Cleartype
X-Git-Hash
X-Varnish-Server
X-Activity-Id
X-Logged-In
X-Www-Served-By
X-FB-Debug
X-Az
X-AppVersion
X-Tt-Trace-Tag
X-Hostname
X-Tt-Trace-Host
Content-Disposition
X-DIS-Request-ID
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
Host
X-Cambria-Cache-Control
Filterid
X-Forwarded-Proto
X-TraceId
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Template
Amp-Access-Control-Allow-Source-Origin
X-App-Server
X-Varnish-Ttl
X-Geo-Country
Frame-Options
X-Aspnet-Version
X-Fastcgi-Cache
Trailer
Version
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
Access-Control-Allow-Method
Accept-Charset
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Type
X-Load-Cache
Fastly-SWR
X-Upgrade-Enabled
X-Ah-Environment
Fastly-SIE
Section-Io-Cache
Viewport
X-Content-Options
X-Origin-Server
X-TT
X-Envoy-Decorator-Operation
X-Fb-Rlafr
X-B3-Sampled
X-TEC-API-ORIGIN
X-Grace
X-Cache-Control
X-B
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Source
MS-Author-Via
Retry-After
X-Rid
Content-MD5
Server-Name
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Device-Type
X-Cache-Age
X-Vcl-Version
X-Language
X-Cdn
X-Request-Guid
X-Px
X-HS-Prerendered
X-Magnolia-Registration
X-Buckets
X-Trace-Id
X-Mobile
X-Revision
TCN
Healthy
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-EdgeConnect-Cache-Status
X-Akamai-Edgescape
X-Varnish-Grace
X-WP-CF-Super-Cache-Active
Protected
X-Backend-Name
X-App-Environment
X-Debug-Info
X-Original-Request-Id
X-CSRF-Token
X-Status
X-RM-Cache-TTL
X-Response-Served-From
SD-X-WS
X-Instance
X-Rule
X-ServerID
X-Rendered-As
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-RemovedCookies
X-Is-Bot
X-Tumblr-User
X-Tumblr-Pixel-0
X-NYM-Debug-Backend
X-Origin-Cache
Cross-Origin-Embedder-Policy-Report-Only
GEO-INFO
X-ProcessESI
Charset
X-Adobe-Loc
X-FW-Hash
X-Framework
X-Edge-Location
NGB
X-Environment-Context
X-FW-Serve
X-Adobe-Content
X-FW-Dynamic
X-FW-Server
X-Mg-Request-UUID
X-L-Path
X-Node-Name
Upgrade-Insecure-Requests
X-Region
Access-Control-Request-Headers
X-FW-Version
X-FW-Type
X-FW-Static
X-Cache-Time
X-Storage
X-Cacheable-TTL
Cross-Origin-Window-Policy
X-UUID
X-Proxy-Cache-Info
X-Datadog-Sampling-Priority
X-Yottaa-Metrics
X-Debug-IsPreview
X-Datadog-Trace-Id
X-Debug-IsConnected
X-Yottaa-Optimizations
X-Datadog-Sampled
X-RTag
X-Content-Powered-By
X-Proxy
X-Datadog-Parent-Id
Ms-Operation-Id
MS-CV
X-Contextid
X-G
Refresh
X-Ua-Device
X-Whom
OT-Force-Account-Verify
X-Lambda-Id
X-B3-Traceid
X-Amz-Meta-S3cmd-Attrs
Webserver
Section-Io-Id
Countrycode
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
Paypal-Debug-Id
X-FTR-Balancer
X-FTR-Cache-Status
X-User-Agent
DC
X-FTR-Expires
X-Reqid
X-Amzn-Remapped-Content-Length
X-Seen-By
X-HTML-Minification-Powered-By
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-VC
Front
X-ECache
X-TT-LOGID
Alternate-Protocol
X-Server-W
Priority
SRV
X-WebKit-CSP-Report-Only
X-Real-IP
X-DataDome
X-IPS-LoggedIn
X-B3-SpanId
X-WP-CF-Super-Cache-Cookies-Bypass
X-Time
Cross-Origin-Opener-Policy-Report-Only
Liferay-Portal
X-Akamai-Request-ID2
X-AB
Backend
X-Origin-CC
X-Origin-TTL
X-N
X-Rocket-Nginx-Serving-Static
X-Mode
X-Cache-Status-Check
WPO-Cache-Message
WPO-Cache-Status
Country
X-Hl-Ver
Onion-Location
Xet-Cookie
TWC-Connection-Speed
X-Redis-Cache
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Country
X-Rewrite-Enabled
TWC-Device-Class
X-Rn-Rsrv
X-Origin-Hint
X-Tumblr-Pixel-2
X-Say-TTL
Filters
Fastcgi-Useragent
Meta-Geo
X-Say-Cacheable
ServerID
X-SayCDN-TTL
Property-Id
Environment
X-SaId
Webcakes-App-Version
X-Format
X-JoinUs
X-FB-TRIP-ID
X-Cache-Host
X-Cache-Action
Webcakes-Region
TWC-Privacy
Web-Mar-Node
X-UPSTREAM-Address
X-RateLimit-Remaining
Webcakes-App-Name
X-Director
Expiry
X-DynaTrace
X-Tb
X-Soup
X-Skip-Cache
X-PHP-Host
X-Fetched-On
X-Labrador-Cache-Channel
X-Handled-By
X-Vcache
X-Hosted-By
X-Frame-Option
X-IPLB-Instance
X-Scope-Id
X-Detected-As
X-Nginx-Cache
DB-Nickname
X-Connection-Hash
X-Tncms
X-Varnish-Age
X-IPLB-Request-ID
X-R9-Blue-Green-Version
X-Accel-Version
X-Restarts
X-Cache-Expired-At
Mn-Server-Ip
X-Cms-Context
Uber-Trace-Id
X-Cluster-Node
X-Origin-Date
X-VC-Cache
From-Origin
X-Loop
X-ProxyCache-Status
Apigw-Requestid
X-Httpd
Atl-Traceid
X-Varnish-Beresp-Grace
X-ProxyCache-Key
X-Varnish-Cache-Hits
X-Logging-Id
X-Ms-Version
X-Adobe-Source
X-BYPASS-REASON
X-Ms-Request-Id
X-Web-Node
X-Forwarded-Host
X-Webstats-RespID
X-Auth-Group-Type
Url
ServedBy
X-Proxy-Build
Selected-Fe
X-Cluster
X-Timing-Wait
X-Tumblr-Pixel-3
X-Served-From
Ohc-File-Size
X-Fastly-Request-Id
X-Servername
X-Resp-Is-Stale
X-Zipkin-Id
X-Extlb
X-Origin
X-Cloudmap
Cross-Origin-Embedder-Policy
X-Routing-Service
X-Proxied
X-S
X-Webkit-CSP
X-Request-URI
X-Hit
Referer-Policy
N-Cache
Accept-Language
X-Azure-Ref-OriginShield
X-SRV
X-LSADC-Cache
X-HS-CF-Cache-Status
Surrogated-Key
X-Worker
X-Generated-By
X-RateLimit-Limit-Second
LB
X-RateLimit-Remaining-Second
X-Sucuri-Cache
X-Lagoon
X-Generation-Time
Xserver
X-App-Version
X-Cache-Hit
X-Xfnlog-Site
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Contexts
X-TA-CDN-Provider
VIX-Pulpo-Node
X-Drupal-Cache-Tags
X-Webkit-Csp
X-XRDS-Location
X-Wix-Request-Id
CF-IPCountry
X-Cdn-Origin
X-Sucuri-ID
Source
X-Oracle-Dms-Ecid
X-MP-GENERATED-AT
X-CDN-Forward
X-Tx-Id
X-NWS-UUID-VERIFY
Node
CDN-RequestId
X-Cache-Debug
X-F-Cache
X-RCS-CacheZone
X-VCT
X-NODE
Cache
X-Varnish-Beresp-Ttl
X-Mly-Id
X-Via-SSL
X-Via-Edge
X-Via-CDN
Edge-Copy-Time
X-Cache-Rule
X-Is-Tablet
X-Is-Supported-Browser
X-Tcp-Rtt
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Browser-Name
X-Geo-Region
X-Is-Mobile
X-Is-Desktop
X-INCAP-ABP
X-No-Session
X-Pad
X-Signature
Cache-Provider
Ohc-Cache-HIT
X-ElasticPress-Query
X-B-Cache
X-App-Name
X-Application
X-Cache-Info
Cluster
BehaviorPad-Version
X-Cache-Operation
X-Cache-NE
Candidate-Md5Url
X-B-Cookie
X-CGP
X-Bc-Bl
X-BCube-Filmed-By
X-Bl-Debug
X-Cache-Grace
X-Bug-Bounty
X-Backend-Instance
X-Conf
X-DPWN-IS-SECURE
X-Developer
X-Destination
X-Ec-GeoHdr
X-Eu-Site
X-Gdpr
X-FC-Vary-Parameters
X-External-Request-Id
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Content-Secure-Policy
X-Site-Version
X-D
X-Csrf-Jwt
Apple-News-Services-Request-Url
X-Access
Meta-Geo-Continent
Wxu-Next-Commit
Web-Mar-Region
MD5-Digest
Mail-Subject
L5d-Success-Class
Lang
Wxu-Next-Hostname
Ngx.Var.Host
We-Hiring
Producers
Redirect-Candidate
Rendered-Blocks
Sslversion
PFcat
Odigeo-Trace-Id
W
Origin
Wxu-Next-Region
X-A
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Fastly-SSL
Expect-Staple
X-GeoCode
DCR-Decision-By
DCR-Processing-Time-Ms
X-Aed
Fl-Custom-Application
X-AB-Test
Host-ID
X-A-Dam
X-A-Ccd
HA-Ipaddr
Ha-Gx-Prefs
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-Aicache-OS
X-Ec-Fail
X-HS-Content-Campaign-Id
X-Op-Id-All
X-Vdms-Version
X-ScT
X-Litespeed-Tag
X-Origin-Time
X-TIM-N
X-Org
X-Ig-Origin-Region
X-Nyt-Route
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Mvc-Supplant-Cachable
X-Section
X-Jobs
X-Ig-Push-State
X-VarnishDD-TTL
X-SD-PageType
X-Path
X-HN
X-Proxied-Request
X-GeoIP-Country-Code
X-Proto
X-Via-JSL
X-GeoCountry
Xc-Version
X-GeoIP-Region-Code
X-Platform-Server
X-S-Cookie
X-Geolocation
X-PAYTM-SRV-ID
X-Vtex-Remote-Cache
X-Rojux
X-Locale
X-NGINX-Cache
X-VC-TTL
X-SB
X-Thinkindot-L3
X-Scheme
X-Shield-Cache-Expires
X-Req
X-Request-Host
X-Request-Time
X-Accel-Expires-Debug
X-Varnish-Remaining-TTL
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
User-Agent
User-Cache-Control
V-Age
TDXMobile
X-Wikidot-Backend
X-Zen-Fury
RNT-Machine
RNT-Time
Server-Host
X-Wikidot-Static-Cache
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Varnish-CookieINHashed-On
X-Varnish-Director
X-Varnish-CookieHashed-On
X-Var-Ttl
X-V-Cache
X-AK-Request-ID
X-Varnishpool
X-Vmg-Version
X-VServer
X-Viewer-Country
X-Via-Fastly
X-VG-WebCache
X-User
X-BBC-Edge-Cache-Status
X-Gzip
X-DefHash
X-Dispatcher-Server
X-GoCache-CacheStatus
X-Ec-Custom-Error
X-DefElseHash
X-Hnp-Log
X-Core-Value
X-Human
X-CUA
X-Date
Req-Svc-Chain
X-Edge-Server
X-GeoIP
X-Gen-Mode
X-Generated-On
X-GEO
X-Gamma-Serve
X-Fmm-Version
X-Epic-Correlation-Id
X-Esi-Check
X-Fastly-Backend
X-GeoIP-City
X-Irp-Debug
X-Content-Length
X-Origin-Expires
X-B3-Trace-ID
X-Block-Status
X-Cache-Date
X-NodeID
X-Platform
X-Auto-Login
X-Powered-By-VTEX-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Amz-Storage-Class
X-Policy
X-Node-Id
X-NMSegId
X-Location
X-Loc
X-Level-Front-Cache
X-Content-Age
X-Micro-Cache
X-Clientip
X-Mvc-Supplant-OutputCached
X-Cached-By
X-CacheTTL
X-Cdn-Srv
X-Akamai-Device-Characteristics
X-Cache-Id
Cdn-Request-Time
Mime-Version
NM-Fastcgi-Cache
Cdn-Host
Canary
CDCHOST
L
Gh-Request-Id
Content-Style-Type
Content-Script-Type
Debug
Cdnsip
Gannett-Cam-Experience-Id
Cdncip
Azure-Version
Origin-Agent-Cluster
Pramga
Azure-RegionName
Azure-SlotName
Product
Azure-SiteName
Azure-InstanceId
Platform
X-ShardId
X-Sorting-Hat-PodId
X-UA
X-Shopify-Stage
Akamai-Mon-Iucid-Del
X-Proxy-Cache-Status
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-COUNTRY
X-ShopId
X-Sorting-Hat-ShopId
X-HITS
Req-ID
Click-Count-Error
X-Contensis-Viewer-Groups
Click-Count-Action-Start
X-Depends
X-Internal-TTL
CDN-Uid
X-Pool
CDN-PullZone
CDN-EdgeStorageId
X-Cache-Aspx
X-Cache-FS-Status
CDN-CachedAt
X-Bip
X-Hash
CDN-RequestPullSuccess
CDN-Cache
CDN-RequestPullCode
X-IsAdmin
CDN-RequestCountryCode
X-Origin-Response-Time
Country-Code
Tube-Get-Contents
X-UA-Device-Type
X-Varnish-Authentication
Tube-Got-Eval
Tube-Got-Results
X-Thanos
X-Pubstack
X-Varnish-Beresp-Status
X-AIR-PT
Yak-Timeinfo
Release
XM
X-We-Are-Hiring
X-VG-TLSProxy
ServerName
Origin-EX
Tube-Return
IsBot
X-SIPLIST1
X-Acquia-Purge-Cdn-Unconfigured
X-Server-IP
DSUID
X-Sn-Servicetimems
X-Request-Start
Origin-CC
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
NGX
X-URL
Ssr
X-RID
X-HOST
X-Service
X-Tb-Optimization-Total-Bytes-Saved
X-Men
X-LB-NoCache
X-Varnish-Hits
X-ORCA-Accelerator
Fastly-Drupal-HTML
X-Upstream-Ct
X-Upstream-Ht
Esi-Enabled
X-CACHE-GROUP
X-DC
X-ZONE
X-VHOST
Sid
X-Vgn-Hpd-Reason
X-TH-Server
GeoIP-Latitude
X-HubSpot-Correlation-Id
X-Api-Version
X-Cache-Bucket
X-Cs
X-Servedbyhost
X-Refresh
CloudFront-Viewer-Country
X-RequestId
Cdn-Requestid
X-Moov-T
X-Old-Content-Length
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
XkeyRZ
X-Nc
X-Wa
A
Cache-Key
X-Proxy-CacheRZ
X-Newrelic-Synthetics
X-Tt-Logid
C-Via
X-B3-Spanid
X-APP
Server-ID
X-Via-Popn
X-B3-Parentspanid
X-CACHE-AGE
X-Via-Poph
X-Via-Popv
X-NewRelic-App-Data
X-HA-Backend
X-Nananana
N1-Cache
X-Parent-Response-Time
X-LiteSpeed-Cache-Control
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-Action
X-LB-ID
AMP-Access-Control-Allow-Source-Origin
X-CS
X-LiteSpeed-Tag
X-Presslabs-Stats
X-Dc
Location
X-Vercel-Cache
HostName
X-DynaTrace-JS-Agent
X-Vercel-Id
X-Cache-VC
X-Endurance-Cache-Level
Proxy-Firewall
X-Thinkindot-L1
X-Ua
TWC-GeoIP-Region
TWC-GeoIP-DMA
TWC-GeoIP-City
Cache-Hits
X-Optimistic-Header
Fastly-Drupal-Html
SID
X-Zone
X-Srv
GeoIp-Country-Code
Server-Hostname
WP-Super-Cache
X-DataCenter
TP-L2-Cache
Sever-Int
Server-Ext
X-Fpc
True-Client-Country-4JS
X-Litespeed-Cache-Control
X-API-Version
Cdn
X-ApacheServer
X-Test
X-PERF
Adler-Geo
X-WA-Info
X-Render-Time
X-Air-Pt
True-Client-IP
X-Dispatcher-Number
Uri
Is-Eu
X-Nitro-Cache
X-Uri
True-Client-Ip
SEZNAM-JOBS-OFFER
Resin-Trace
WZWS-RAY
X-Nginx-Cache-Key
X-Datadome
RewriteTeamHook
X-Ssense-Gql
X-LJ-Flow-ID
X-Ssense-Shipping-Surcharge-Enabled
Cache-Contol
X-Ion-Hop
RewriteTestHook
X-Jungle-Id
X-Datacenter
X-AWS-Id
X-CLOUD-TRACE-CONTEXT
X-VWS-Id
GeoIP-Country-Code
X-Ion-Healthy
Sm-Log-Id
X-SERVER-NAME
X-Service-Response-Time
X-Geo-Header
Log-Origin
My-App
Tcn
X-Custom-Header
X-Provided-By
Cmsid
Cmstype
T-Server
X-Dynatrace-Js-Agent
X-Client-Ip
X-Pass-Why
X-Varnish-Beresp-TTL
X-From
X-RateLimit-Limit
X-Up
X-ND-Cache
X-FPC
X-Stale
X-Srcache-Store-Status
X-Srcache-Fetch-Status
CacheControlHeader
X-Udemy-Cache-App-Namespace
X-Oracle-Dms-Rid
X-CMSURLCustom
Serverhost
Hostname
X-Cache-Server
Lb
X-APP-VERSION
Srv
Vc-Max-Age
S-Rt
Pics-Label
X-Fastly-Cache-Status
X-Debug-Service
Av-Poweredby
X-TX-ID
Cache-Tv-Group
X-Air-Trace-Id
X-Air-Source
X-Lb-Id
X-Air-Hostname
Server-Id
Powered-By
X-App
X-Cdn-Cache-Status
X-Vc
X-Via-PopH
X-Via-PopN
X-Ha-Backend
X-Via-PopV
X-Correlation-ID
X-Fastly-Backend-Reqs
X-Cache-TTL-Remaining
Vix-Hermes-Req-Id
Cf-Ipcountry
X-Akamai-Pragma-Client-IP
X-Cache-Ttl
X-Oracle-DMS-ECID
X-Fastly-Cache
X-WA
X-Ckpd-Fst-Backend
X-Html-Minification-Powered-By
Origin-Site
X-LAGOON
ServerHost
X-NC
X-XRDS-LOCATION
X-Esi
X-Proxy-Cache-La3
X-VCL-Version
Xkey-La3
X-SRCache-Key
Epwk-X-Cache
Xkeylog
Thinkindot-Control
On-Server
X-Varnish-Hostname
NtCoent-Length
Geoip-Latitude
X-Traceid
Cloudfront-Viewer-Country
X-Requestid
Edge-Cache
WebServer
X-ServedByHost
WWW-Authenticate
CountryCode
Pragrma
X-Vary-Devices
X-Save-Cache
X-Amz-Meta-Opti
X-PHP-Backend
Time-Cloud-Cache
X-Sucuri-Id
Store-Cloud-Cache
X-MSEdge-Features
X-Ee-Request-Date
X-Ee-Origin
X-Ee-Generated-By
AKAMAI
X-HS-Status
X-MSEdge-Flight
Warning
X-Ee-Request-Id
X-Cms-Device
X-Serial
X-Region-Sid
X-Forwarded-Site
X-Cdn-Request-ID
Machine
YJS-ID
X-Wp-Cf-Super-Cache-Cache-Control
X-VTEX-Cache-Backend-Header-Time
X-Wp-Cf-Super-Cache
X-Akamai-Transformed
X-Pod
FSS-Cache
X-IAuth-Set-Uid
X-Check-Cacheable
X-Lb-Nocache
X-VTEX-Cache-Backend-Connect-Time
Ms-Author-Via
Reporter
Magicmarker
Cl-Cache
X-Info
X-Sigma-Backend
Yjs-Id
X-Sigma
X-Rocket-Build-Number
X-Ms-Blob-Type
X-Mg-Cache
X-Ms-Lease-Status
X-Limited
X-Akamai-ERPolicy
Timeexpire
X-Akamai-ERRuleID
X-Orig-Cache-Control
X-BBC-Origin-Response-Status
X-Dw-Trace-Id
Cneonction
X-Web-Server
X-Elasticpress-Query
X-Td-Header-From-No-Data
Thinkindot-Cache-Type
X-Tncms-Bot-Tier
X-Lsadc-Cache