Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Accept-CH
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Permissions-Policy
X-Request-ID
X-Ua-Compatible
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
X-Check
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
Cf-Apo-Via
X-Turbo-Charged-By
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
X-UA-Device
EagleId
X-Server
X-Dispatcher
X-Vhost
X-Dns-Prefetch-Control
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
Accept-CH-Lifetime
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Litespeed-Cache
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Allow
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Cache-Lookup
X-OneAgent-JS-Injection
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
Xkey
X-Akam-SW-Version
EagleEye-TraceId
X-Host
Surrogate-Control
X-Response-Time
Cf-Railgun
X-Readtime
X-Node
X-Server-Id
X-HW
X-LiteSpeed-Cache
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Nginx-Cache-Status
X-Url
Cache-Tag
X-Content-Type
Content-Location
X-Nginx-Upstream-Cache-Status
X-Application-Context
X-NWS-LOG-UUID
X-Clacks-Overhead
Service-Worker-Allowed
Fastly-Restarts
X-Trace
Cross-Origin-Opener-Policy
X-Country-Code
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-Vname
X-PC
X-TtlSet
X-Midtier
X-Edge
X-Mcache
X-Oneagent-Js-Injection
Surrogate-Key
Rating
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Cache-TTL
X-Browser-Type
X-Server-Name
X-Abt-Application-Version
X-Cnection
X-Element-Page-Cache
X-ESI
Nginx-Cache
X-GoogleNews-Bot
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Powered-By-Plesk
X-GitHub-Request-Id
Edge-Control
X-Ser
Verso
X-ECACHE
X-D2id
X-Ac
X-Vcap-Request-Id
X-MS-InvokeApp
X-Client-IP
X-ORACLE-DMS-RID
X-ARC
X-Dw-Request-Base-Id
X-B3-TraceId
X-Middleton-Response
Response
X-Amz-Rid
X-CST
X-Powered-CMS
X-Navigation-Version
X-Goog-Hash
X-Kinsta-Cache
X-Edge-Location-Klb
X-Wormhole-Sdk
X-Upstream
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
Accept-Ch-Lifetime
X-Ratelimit-Limit
X-Daa-Tunnel
X-Forwarded-For
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
X-NF-Request-ID
X-Cache-Key
RTSS
SPIisLatency
SPRequestDuration
X-FastCGI-Cache
X-Ratelimit-Remaining
X-Server-ID
X-Mod-Pagespeed
AR-SID
AR-ATIME
AR-Request-ID
AR-PoweredBy
Edge-Cache-Tag
X-Ttl
Cache-Status
Public-Key-Pins
X-Version
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Mg-S
X-Content-Digest
SPRequestGuid
X-SharePointHealthScore
Realpath
S
Cross-Origin-Resource-Policy
AR-CACHE
X-Varnish-TTL
X-Shield-Request-Id
X-Fastly-Request-ID
X-T
X-MSEdge-Ref
Fastcgi-Cache
X-Cached
X-Ua-Device
X-Recruiting
X-Accel-Expires
X-Distributor
Front-End-Https
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Access-Control-Request-Method
TP-Cache
X-Azure-Ref
X-Request-Received
X-Newrelic-App-Data
X-Request-Processing-Time
Count-Hit
X-Ua-Browser
X-HS-Cache-Config
Origin-Trial
Arr-Disable-Session-Affinity
X-HS-Hub-Id
X-HS-Content-Id
X-Debug
X-Id
MicrosoftSharePointTeamServices
Server-Node
X-LLID
X-Content-Security-Policy-Report-Only
X-Correlation-Id
Cache-Tags
X-VARITI-CCR
X-TTL
Pinterest-Version
X-Ismobilevalue
X-Pinterest-Rid
Pinterest-Generated-By
X-Cluster-Name
X-HS-Combine-CSS
X-Frontend
X-PressLabs-Stats
Accept-Ch
X-GUploader-UploadID
X-Varnish-Backend
Payment
X-Amz-Replication-Status
X-Hits
X-Goog-Metageneration
X-Microsite
X-Request-Handler-Origin-Region
X-Protected-By
X-LB-Cache
X-NGENIX-Cache
X-Unique-Id
Cleartype
X-Git-Hash
X-Forwarded-Proto
Host
X-Logged-In
X-Varnish-Server
X-FB-Debug
X-Tt-Trace-Tag
Content-Disposition
X-Tt-Trace-Host
X-Www-Served-By
X-Ratelimit-Reset
X-Activity-Id
Filterid
X-AppVersion
X-Az
X-Hostname
X-Xrds-Location
X-Page-Id
X-DIS-Request-ID
X-HP-Trace-Id
X-Jurisdiction
X-Cambria-Cache-Control
X-HP-Webp
X-App-Server
X-Amzn-RequestId
X-Amz-Apigw-Id
Akamai-GRN
X-Template
X-Nf-Request-Id
X-Geo-Country
X-FTR-Request-ID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Aspnet-Version
X-Fastcgi-Cache
X-ASPNET-VERSION
Access-Control-Allow-Method
X-Origin-Server
Frame-Options
X-Goog-Stored-Content-Length
X-Load-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Upgrade-Enabled
X-Type
X-WP-CF-Super-Cache
MS-Author-Via
X-WP-CF-Super-Cache-Cache-Control
X-Ah-Environment
Retry-After
Viewport
Fastly-SWR
Fastly-SIE
Section-Io-Cache
Version
X-Content-Options
X-Fb-Rlafr
X-TT
Accept-Charset
Content-MD5
X-Cache-Control
X-B3-Sampled
X-Rid
X-Grace
X-B
Amp-Access-Control-Allow-Source-Origin
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Varnish-Ttl
X-Source
X-Envoy-Decorator-Operation
X-Vcl-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Request-Guid
X-Trace-Id
X-Cdn
X-Revision
Trailer
X-Device-Type
X-Language
Server-Name
X-Buckets
Healthy
X-Magnolia-Registration
X-RateLimit-Remaining
X-Webkit-CSP
X-Aspnetmvc-Version
X-Origin-Cache
X-Mobile
X-Cache-Age
X-Px
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-WP-CF-Super-Cache-Active
X-CSRF-Token
X-Backend-Name
X-Amz-Meta-S3cmd-Attrs
X-Contextid
TCN
X-Akamai-Edgescape
X-TraceId
X-HS-Prerendered
X-App-Environment
X-RM-Cache-TTL
X-Status
X-Instance
X-L-Path
X-NYM-Debug-Backend
X-Debug-Info
X-ProcessESI
X-Environment-Context
X-Varnish-Grace
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Rule
X-RemovedCookies
X-Proxy
X-Tumblr-User
X-Storage
X-ServerID
SD-X-WS
X-FW-Dynamic
X-FW-Hash
X-Edge-Location
NGB
X-Framework
X-HTML-Minification-Powered-By
X-FW-Serve
X-FW-Version
X-FW-Type
X-FW-Static
X-FW-Server
X-Mg-Request-UUID
GEO-INFO
X-Webkit-Csp
X-EdgeConnect-Cache-Status
X-Cacheable-TTL
X-Adobe-Loc
X-Adobe-Content
Access-Control-Request-Headers
Cross-Origin-Window-Policy
X-Content-Powered-By
X-Debug-IsPreview
X-UUID
X-Cache-Time
X-Rendered-As
X-Region
X-Proxy-Cache-Info
X-Debug-IsConnected
X-Is-Bot
X-Datadog-Sampling-Priority
X-G
X-Node-Name
X-Datadog-Sampled
X-Datadog-Parent-Id
MS-CV
Ms-Operation-Id
X-RTag
X-Datadog-Trace-Id
Protected
DC
Upgrade-Insecure-Requests
X-Yottaa-Metrics
Charset
X-Yottaa-Optimizations
X-Seen-By
Paypal-Debug-Id
Webserver
X-Whom
X-User-Agent
Cross-Origin-Embedder-Policy-Report-Only
OT-Force-Account-Verify
Countrycode
X-Original-Request-Id
Refresh
X-Response-Served-From
X-Lambda-Id
Front
Section-Io-Id
X-Reqid
X-ECache
X-VHOST
X-WebKit-CSP-Report-Only
X-TT-LOGID
X-Amzn-Remapped-Content-Length
Alternate-Protocol
X-IPS-LoggedIn
SRV
X-VC
X-B3-Traceid
X-Akamai-Request-ID2
X-Server-W
X-AB
X-N
X-Cache-Status-Check
Country
Priority
X-WP-CF-Super-Cache-Cookies-Bypass
Backend
X-B3-SpanId
X-Time
Liferay-Portal
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Real-IP
X-Mode
Onion-Location
X-XRDS-Location
X-Rocket-Nginx-Serving-Static
Property-Id
X-Cache-Host
TWC-Connection-Speed
Fastcgi-Useragent
X-Rn-Rsrv
Webcakes-App-Version
X-UPSTREAM-Address
ServerID
X-FB-TRIP-ID
X-Origin-Hint
Environment
X-JoinUs
Meta-Geo
Webcakes-Region
X-Rewrite-Enabled
Webcakes-App-Name
TWC-GeoIP-LatLong
Filters
TWC-Locale-Group
X-SaId
X-Tumblr-Pixel-2
X-Hl-Ver
TWC-Privacy
X-Format
TWC-GeoIP-Country
TWC-Device-Class
Xet-Cookie
X-Connection-Hash
X-Hosted-By
X-Cache-Action
X-Frame-Option
Expiry
X-Cache-Expired-At
DB-Nickname
X-Skip-Cache
X-Cluster-Node
X-IPLB-Request-ID
X-Scope-Id
Uber-Trace-Id
From-Origin
X-Fetched-On
X-IPLB-Instance
Mn-Server-Ip
X-VC-Cache
X-Nginx-Cache
X-Origin-Date
X-Restarts
X-Say-Cacheable
X-Redis-Cache
X-Accel-Version
Web-Mar-Node
X-R9-Blue-Green-Version
X-SayCDN-TTL
X-Request-URI
X-Say-TTL
X-Labrador-Cache-Channel
X-Tb
X-BYPASS-REASON
X-ProxyCache-Status
X-Webstats-RespID
Apigw-Requestid
X-Varnish-Age
X-ProxyCache-Key
X-Web-Node
X-Fastly-Request-Id
X-Handled-By
X-Forwarded-Host
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Soup
X-PHP-Host
X-Director
X-Cms-Context
X-Origin-CC
X-Httpd
X-Origin-TTL
X-Cluster
X-Loop
Accept-Language
X-Vcache
X-Served-From
Cross-Origin-Embedder-Policy
X-Logging-Id
X-Adobe-Source
X-Auth-Group-Type
ServedBy
Atl-Traceid
X-Tncms
X-Proxied
X-Routing-Service
Url
X-Servername
X-Zipkin-Id
X-S
X-Extlb
X-Cloudmap
X-Detected-As
Referer-Policy
X-Hit
X-Generated-By
X-Ms-Version
X-Proxy-Build
X-Ms-Request-Id
X-Timing-Wait
Selected-Fe
N-Cache
X-DataDome
X-Origin
WPO-Cache-Message
X-Lagoon
X-Wix-Request-Id
X-Tumblr-Pixel-3
X-SRV
WPO-Cache-Status
VIX-Pulpo-Upstream-Status
X-LSADC-Cache
X-DynaTrace
VIX-Pulpo-Node
Xserver
X-Azure-Ref-OriginShield
Cross-Origin-Opener-Policy-Report-Only
X-Xfnlog-Site
Surrogated-Key
X-Worker
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Source
X-CLOUD-TRACE-CONTEXT
X-App-Version
X-NWS-UUID-VERIFY
X-Sucuri-Cache
LB
X-Generation-Time
Ohc-File-Size
CF-IPCountry
X-Cache-Debug
X-RCS-CacheZone
X-Via-JSL
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-F-Cache
X-Proxy-Cache-Status
Node
X-Cdn-Origin
CDN-RequestId
X-HS-CF-Cache-Status
X-VCT
X-Browser-Name
X-Geo-Region
X-Tcp-Rtt
X-Is-Mobile
X-Is-Tablet
X-Is-Desktop
X-Is-Supported-Browser
X-MP-GENERATED-AT
X-No-Session
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Cache-Hit
X-NODE
X-Varnish-Beresp-Ttl
X-B-Cache
X-Tx-Id
X-Signature
X-Upstream-Ht
X-UA
X-Upstream-Ct
X-Sucuri-ID
X-ElasticPress-Query
X-FTR-Balancer
X-FTR-Cache-Status
X-TA-CDN-Provider
X-Litespeed-Tag
X-FTR-Backend-Server
X-FTR-Expires
X-Country-Code-Real
X-FTR-Backend
X-Cache-Rule
X-Cache-Operation
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Alternate-Cache-Key
X-GeoCode
X-Op-Id-All
Fl-Custom-Application
Ha-Gx-Prefs
X-GeoCountry
Fastly-GeoIP-CountryCode
DCR-Processing-Time-Ms
Expect-Staple
Fastly-Backend-Name
X-Gdpr
HA-Ipaddr
X-Eu-Site
Lang
Mail-Subject
X-ORCA-Accelerator
X-FC-Vary-Parameters
X-Proto
X-Rojux
Host-ID
X-Proxied-Request
L5d-Success-Class
DCR-Decision-By
Content-Secure-Policy
Apple-News-Services-Host
X-Nyt-Route
X-Vtex-Remote-Cache
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Xc-Version
X-Mly-Id
X-Ig-Push-State
X-Mvc-Supplant-Cachable
Cache
X-Ig-Origin-Region
Apple-News-Services-Request-Url
Candidate-Md5Url
X-HN
X-ScT
Cluster
X-Section
X-TIM-N
BehaviorPad-Version
X-Vdms-Version
X-VarnishDD-TTL
Cache-Provider
MD5-Digest
Meta-Geo-Continent
X-PAYTM-SRV-ID
X-Bug-Bounty
X-Platform-Server
Wxu-Next-Region
X-Cache-Info
X-Cache-NE
X-Jobs
X-Conf
Wxu-Next-Hostname
X-CGP
X-A
X-A-Ccd
X-App-Name
X-AB-Test
X-Aicache-OS
X-Access
X-Backend-Instance
X-Bc-Bl
X-BCube-Filmed-By
X-A-Dam
X-A-Dcw
X-A-Wwc
X-Path
X-Csrf-Jwt
X-Ec-Fail
X-DPWN-IS-SECURE
X-Developer
Producers
X-Ec-GeoHdr
PFcat
Ngx.Var.Host
X-Org
Odigeo-Trace-Id
Origin
Redirect-Candidate
Rendered-Blocks
X-Origin-Time
X-D
We-Hiring
Wxu-Next-Commit
W
X-Debug-Cache-Fetch
Sslversion
User-Agent
X-Debug-Cache-Store
X-Aed
X-A-Dgt
AMP-Access-Control-Allow-Source-Origin
Mime-Version
X-Locale
X-INCAP-ABP
X-NGINX-Cache
X-Request-Time
X-Scheme
X-Shield-Cache-Expires
X-SD-PageType
Web-Mar-Region
X-SB
X-Accel-Expires-Debug
X-Policy
X-Amz-Storage-Class
X-Auto-Login
X-B3-Trace-ID
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Device-Characteristics
X-SIPLIST1
X-Powered-By-VTEX-Cache
X-AK-Request-ID
X-Req
X-Slack-Shared-Secret-Outcome
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Product
Platform
X-Varnish-Director
NM-Fastcgi-Cache
X-Varnish-Remaining-TTL
Origin-Agent-Cluster
X-Varnish-Authentication
Req-Svc-Chain
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Pad
X-Thinkindot-L3
Server-Host
X-Var-Ttl
RNT-Machine
RNT-Time
X-Slack-Backend
X-Platform
X-Loc
X-Level-Front-Cache
X-Edge-Server
X-Dispatcher-Server
X-Location
X-DefElseHash
X-DefHash
X-Depends
X-Epic-Correlation-Id
X-Esi-Check
X-GeoIP-City
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-GeoIP
X-Gzip
X-HS-Content-Campaign-Id
X-Fmm-Version
X-Generated-On
X-Micro-Cache
X-Date
X-Service
X-Origin-Response-Time
X-Cached-By
X-Cache-Id
X-Cache-Grace
X-VG-WebCache
X-Bl-Debug
X-Cache-Aspx
X-Origin-Expires
X-Cdn-Srv
X-Content-Length
X-Core-Value
X-Mvc-Supplant-OutputCached
X-Content-Age
X-Contensis-Viewer-Groups
X-NodeID
X-NMSegId
X-BBC-Edge-Cache-Status
TDXMobile
Gannett-Cam-Experience-Id
X-VTEX-Cache-Time
Azure-Version
Cdnsip
Debug
Cdncip
Gh-Request-Id
X-Vmg-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Content-Style-Type
CDCHOST
Esi-Enabled
Content-Script-Type
Fastly-SSL
X-We-Are-Hiring
Azure-RegionName
X-Viewer-Country
X-VTEX-Cache-Server
Cdn-Host
L
IsBot
X-Via-Fastly
Canary
Cdn-Request-Time
Akamai-Mon-Iucid-Del
X-COUNTRY
X-Site-Version
CDN-EdgeStorageId
XM
X-Cache-FS-Status
X-Wikidot-Static-Cache
X-CUA
CDN-Cache
X-HITS
X-Geolocation
CDN-CachedAt
X-CacheTTL
X-Block-Status
CDN-RequestCountryCode
Click-Count-Action-Start
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-Uid
X-VServer
X-Clientip
Click-Count-Error
X-Node-Id
X-Pubstack
CDN-PullZone
X-Bip
X-Pool
X-Acquia-Purge-Cdn-Unconfigured
User-Cache-Control
X-Human
X-Gen-Mode
X-UA-Device-Type
X-Thanos
X-Tb-Optimization-Total-Bytes-Saved
X-Irp-Debug
X-Internal-TTL
X-V-Cache
X-Fastly-Backend
Pramga
X-Gamma-Serve
X-Hash
X-Hnp-Log
Origin-CC
Release
X-Varnish-Beresp-Status
Origin-EX
X-Varnishpool
X-GoCache-CacheStatus
Tube-Got-Results
Tube-Return
X-Ec-Custom-Error
NGX
X-Server-IP
Tube-Got-Eval
X-Sn-Servicetimems
X-Wikidot-Backend
X-VG-TLSProxy
Tube-Get-Contents
V-Age
X-URL
X-CDN-Forward
X-External-Request-Id
X-S-Cookie
X-IsAdmin
Cache-Key
Edge-Copy-Time
X-Cache-Date
X-Via-Edge
X-Men
A
X-Via-CDN
X-LB-NoCache
X-B-Cookie
X-Application
X-Via-SSL
X-Destination
Yak-Timeinfo
Country-Code
X-HOST
XkeyRZ
X-Request-Start
X-Request-Host
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Varnish-Hits
X-RateLimit-Limit
Req-ID
ServerName
Ssr
X-RID
DSUID
X-Cache-Bucket
X-Proxy-CacheRZ
X-Newrelic-Synthetics
X-CACHE-GROUP
X-GEO
X-Cdn-Forward
X-Resp-Is-Stale
X-Api-Version
Sid
X-Zen-Fury
X-Refresh
X-User
X-Oracle-Dms-Ecid
X-Nananana
X-Optimistic-Header
X-ZONE
X-Cs
X-Servedbyhost
X-APP
CloudFront-Viewer-Country
TP-L2-Cache
X-VC-TTL
Fastly-Drupal-HTML
X-Dc
Cdn-Requestid
Ohc-Cache-HIT
X-DC
X-Presslabs-Stats
X-Air-Pt
GeoIP-Latitude
X-RequestId
X-B3-Spanid
X-Tt-Logid
Proxy-Firewall
Server-ID
C-Via
X-Vgn-Hpd-Reason
X-Nc
X-Via-Poph
X-Via-Popv
X-Via-Popn
X-HA-Backend
X-Wa
X-Endurance-Cache-Level
Fastly-Drupal-Html
X-CACHE-AGE
True-Client-Country-4JS
Server-Ext
X-TH-Server
X-Webkit-Csp-Report-Only
Server-Hostname
X-Test
X-B3-Parentspanid
X-LB-ID
Sever-Int
X-AIR-PT
X-LiteSpeed-Cache-Control
X-XRDS-LOCATION
Cdn
X-CS
X-LiteSpeed-Tag
X-VWS-Id
X-SERVER-NAME
X-DynaTrace-JS-Agent
X-LJ-Flow-ID
WP-Super-Cache
GeoIp-Country-Code
Is-Eu
HostName
X-Old-Content-Length
X-Moov-T
Adler-Geo
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-AWS-Id
X-Dispatcher-Number
X-Nginx-Cache-Key
X-Datadome
X-Provided-By
X-Srv
X-Zone
X-Parent-Response-Time
WZWS-RAY
X-DataCenter
X-Fpc
X-HubSpot-Correlation-Id
SID
X-API-Version
X-Action
T-Server
X-NewRelic-App-Data
X-Geo-Header
X-Custom-Header
S-Rt
X-Litespeed-Cache-Control
X-Pass-Why
X-Thinkindot-L1
Location
X-Vercel-Cache
X-Vercel-Id
X-Cache-VC
True-Client-IP
X-ND-Cache
Cache-Tv-Group
N1-Cache
Vc-Max-Age
True-Client-Ip
Uri
SEZNAM-JOBS-OFFER
X-CMSURLCustom
X-Cache-Server
Resin-Trace
Pics-Label
X-Stale
X-TX-ID
Powered-By
TWC-GeoIP-Region
TWC-GeoIP-City
Tcn
X-ApacheServer
X-PERF
X-Datacenter
TWC-GeoIP-DMA
X-Ua
Serverhost
X-Varnish-Beresp-TTL
Cache-Hits
X-Client-Ip
X-Dynatrace-Js-Agent
GeoIP-Country-Code
X-FPC
X-Render-Time
Vix-Hermes-Req-Id
X-Service-Response-Time
Sm-Log-Id
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Hostname
Srv
X-Cache-TTL-Remaining
X-Uri
X-WA-Info
X-APP-VERSION
Lb
X-Fastly-Cache
X-Oracle-Dms-Rid
X-Nitro-Cache
X-Ckpd-Fst-Backend
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
RewriteTestHook
X-Cdn-Cache-Status
Thinkindot-Control
X-Debug-Service
X-Jungle-Id
X-Ion-Healthy
X-Ion-Hop
X-Fastly-Cache-Status
On-Server
X-Vc
Av-Poweredby
Log-Origin
RewriteTeamHook
Cache-Contol
X-Air-Trace-Id
X-NC
Server-Id
X-WA
My-App
ServerHost
X-Udemy-Cache-App-Namespace
X-Lb-Id
X-Air-Source
X-Air-Hostname
Cf-Ipcountry
X-Ee-Request-Id
X-Ee-Request-Date
Cmsid
Cmstype
X-Ee-Origin
X-From
X-Ee-Generated-By
X-Up
X-Cms-Device
X-PHP-Backend
Time-Cloud-Cache
Geoip-Latitude
X-Save-Cache
X-Amz-Meta-Opti
AKAMAI
Store-Cloud-Cache
X-Vary-Devices
X-Cache-Ttl
X-Correlation-ID
X-Proxy-Cache-La3
X-Fastly-Backend-Reqs
X-Ha-Backend
Xkeylog
X-Via-PopN
CacheControlHeader
X-Github-Request-Id
X-Via-PopV
X-Via-PopH
Xkey-La3
X-Oracle-DMS-ECID
X-Esi
X-VCL-Version
Cl-Cache
X-Info
X-VTEX-Cache-Backend-Header-Time
CountryCode
X-App
Magicmarker
X-Akamai-Pragma-Client-IP
X-VTEX-Cache-Backend-Connect-Time
X-Sucuri-Id
X-ServedByHost
X-Traceid
WebServer
X-Geo
Cloudfront-Viewer-Country
X-IAuth-Set-Uid
X-Requestid
WWW-Authenticate
X-Limited
X-HS-Status
X-MSEdge-Flight
X-MSEdge-Features
X-LAGOON
X-Dw-Trace-Id
Warning
X-CDN-Cache-Status
CDN
X-New
X-Acquia-Application-Trace
Reporter
X-Wp-Cf-Super-Cache
X-Lb-Nocache
NtCoent-Length
X-Acquia-Purge-Tags
FSS-Cache
X-Acquia-Application-UUID
Origin-Site
X-Rollout
X-Serial
X-Akamai-Transformed
X-Pod
X-Eligible
X-Acquia-Site
X-Wp-Cf-Super-Cache-Cache-Control
X-Check-Cacheable
X-V
X-Td-Header-From-No-Data
X-Lsadc-Cache
Thinkindot-Cache-Type
X-BBC-Origin-Response-Status
X-Varnish-Hostname
X-Web-Server
X-Ms-Lease-Status
X-Platform-Processor
X-Platform-Router
X-Ramcache
X-Platform-Cluster
CF-Cached-On
Machine
X-Region-Sid
X-Ms-Blob-Type
X-Tncms-Bot-Tier
X-Orig-Cache-Control
X-Forwarded-Site
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Cneonction
Timeexpire
X-Elasticpress-Query