Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
Accept-CH
X-Runtime
X-DNS-Prefetch-Control
P3p
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Permissions-Policy
X-Content-Security-Policy
X-Ua-Compatible
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
Accept-Ch
X-Check
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
X-Turbo-Charged-By
Cf-Apo-Via
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
X-UA-Device
EagleId
X-Server
X-Dispatcher
X-Vhost
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-AH-Environment
X-Ws-Request-Id
X-Varnish-Cache
Accept-CH-Lifetime
Grace
X-Server-Powered-By
X-Pingback
X-Litespeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Allow
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Cache-Lookup
X-WebKit-CSP
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
Xkey
X-Akam-SW-Version
EagleEye-TraceId
X-Host
Surrogate-Control
X-Response-Time
Cf-Railgun
X-Readtime
X-LiteSpeed-Cache
X-Server-Id
X-Node
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Country
X-Nginx-Cache-Status
X-Url
X-Content-Type
Cache-Tag
Content-Location
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-NWS-LOG-UUID
X-Clacks-Overhead
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Trace
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Amz-Server-Side-Encryption
X-Country-Code
X-Rack-Cache
X-Times
X-Vname
X-PC
X-TtlSet
X-Edge
X-Mcache
X-Midtier
Rating
Surrogate-Key
X-Server-Name
Pagespeed
Display
X-Sol
X-Cache-TTL
X-Middleton-Display
X-Browser-Type
X-Cnection
X-Element-Page-Cache
X-Abt-Application-Version
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-ESI
X-Exp-Id
X-Cdn-Fetch
X-Kinja
Nginx-Cache
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Oneagent-Js-Injection
X-Ser
Edge-Control
X-ECACHE
X-D2id
Verso
X-Ac
X-Vcap-Request-Id
X-MS-InvokeApp
X-Client-IP
X-Dw-Request-Base-Id
X-ORACLE-DMS-RID
X-ARC
X-B3-TraceId
Response
X-Middleton-Response
X-Amz-Rid
X-CST
X-Powered-CMS
X-Navigation-Version
X-Goog-Hash
X-Upstream
X-Kinsta-Cache
X-Edge-Location-Klb
X-Wormhole-Sdk
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Daa-Tunnel
X-Forwarded-For
X-NF-Request-ID
X-Amzn-Trace-Id
X-Cache-Key
RTSS
X-Ratelimit-Limit
SPIisLatency
SPRequestDuration
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
X-Mod-Pagespeed
X-FastCGI-Cache
Edge-Cache-Tag
Cache-Status
X-Ratelimit-Remaining
X-ORACLE-DMS-ECID
X-Server-ID
Public-Key-Pins
X-Ttl
X-Version
X-Ezoic-Cdn
X-Mg-S
X-Content-Digest
X-Ruxit-Js-Agent
X-SharePointHealthScore
SPRequestGuid
X-Varnish-TTL
AR-CACHE
S
Realpath
Cross-Origin-Resource-Policy
X-Shield-Request-Id
X-MSEdge-Ref
X-T
Fastcgi-Cache
X-Fastly-Request-ID
X-Cached
X-Recruiting
X-Accel-Expires
Front-End-Https
X-Distributor
X-Ua-Device
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Access-Control-Request-Method
TP-Cache
X-Azure-Ref
X-Request-Processing-Time
X-Request-Received
X-Id
X-Ua-Browser
Count-Hit
Arr-Disable-Session-Affinity
X-HS-Content-Id
X-HS-Hub-Id
X-Debug
X-HS-Cache-Config
X-TTL
Server-Node
MicrosoftSharePointTeamServices
X-Newrelic-App-Data
X-LLID
X-Content-Security-Policy-Report-Only
X-Correlation-Id
Origin-Trial
X-VARITI-CCR
Cache-Tags
X-PressLabs-Stats
X-Ismobilevalue
X-Frontend
X-HS-Combine-CSS
X-Cluster-Name
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-GUploader-UploadID
X-Varnish-Backend
Payment
X-Amz-Replication-Status
X-Hits
X-Protected-By
X-Goog-Metageneration
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-NGENIX-Cache
X-Unique-Id
X-Forwarded-Proto
Cleartype
X-FB-Debug
X-Varnish-Server
X-Activity-Id
Host
X-Xrds-Location
X-AppVersion
X-Az
X-Www-Served-By
X-Logged-In
X-Git-Hash
X-Ratelimit-Reset
Content-Disposition
X-Tt-Trace-Host
Filterid
X-Tt-Trace-Tag
X-Hostname
X-Page-Id
X-DIS-Request-ID
X-App-Server
Akamai-GRN
X-Cambria-Cache-Control
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Fastcgi-Cache
X-Template
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Geo-Country
X-Nf-Request-Id
Access-Control-Allow-Method
X-FTR-Request-ID
X-Origin-Server
Frame-Options
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Load-Cache
X-Goog-Generation
Retry-After
X-Upgrade-Enabled
X-Aspnet-Version
X-WP-CF-Super-Cache-Cache-Control
X-Type
X-WP-CF-Super-Cache
MS-Author-Via
Viewport
X-ASPNET-VERSION
X-Webkit-Csp
Fastly-SWR
Fastly-SIE
Version
Section-Io-Cache
Accept-Charset
X-Content-Options
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TT
Content-MD5
X-Fb-Rlafr
X-Cache-Control
X-B
X-B3-Sampled
X-Grace
X-Ah-Environment
X-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Amp-Access-Control-Allow-Source-Origin
X-Envoy-Decorator-Operation
X-Request-Guid
X-Source
X-Vcl-Version
X-RateLimit-Remaining
X-Trace-Id
X-Revision
X-Varnish-Ttl
X-Device-Type
Server-Name
X-Language
Trailer
Healthy
X-Cdn
X-Origin-Cache
X-Buckets
X-Magnolia-Registration
X-Cache-Age
X-Mobile
X-Px
X-Amz-Meta-S3cmd-Attrs
X-WP-CF-Super-Cache-Active
X-Contextid
X-Webkit-CSP
X-Aspnetmvc-Version
X-Backend-Name
X-Tec-Api-Origin
X-CSRF-Token
X-Tec-Api-Version
X-Tec-Api-Root
X-TraceId
X-Akamai-Edgescape
X-Status
X-Proxy
X-RM-Cache-TTL
X-App-Environment
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Environment-Context
X-Debug-Info
X-Instance
X-ProcessESI
X-Tumblr-User
X-RemovedCookies
X-Rule
X-Varnish-Grace
X-NYM-Debug-Backend
TCN
X-Tumblr-Pixel
X-L-Path
Access-Control-Request-Headers
GEO-INFO
Cross-Origin-Window-Policy
X-HTML-Minification-Powered-By
NGB
X-UUID
SD-X-WS
X-FW-Dynamic
X-Storage
X-Framework
X-FW-Type
X-Region
X-Proxy-Cache-Info
X-Mg-Request-UUID
X-Node-Name
X-FW-Static
X-FW-Version
X-FW-Server
X-FW-Hash
X-ServerID
X-FW-Serve
X-Datadog-Trace-Id
X-Cacheable-TTL
X-Edge-Location
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-RTag
MS-CV
X-Rendered-As
X-Datadog-Parent-Id
X-Content-Powered-By
X-Debug-IsConnected
X-Is-Bot
X-Adobe-Content
X-Debug-IsPreview
X-Adobe-Loc
X-HS-Prerendered
Ms-Operation-Id
X-EdgeConnect-Cache-Status
X-G
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Time
DC
Upgrade-Insecure-Requests
Protected
Charset
X-Seen-By
Countrycode
Paypal-Debug-Id
X-User-Agent
Webserver
X-Whom
OT-Force-Account-Verify
Refresh
X-Lambda-Id
Cross-Origin-Embedder-Policy-Report-Only
Front
Section-Io-Id
X-WebKit-CSP-Report-Only
X-Original-Request-Id
X-Response-Served-From
X-VC
X-TT-LOGID
X-Reqid
X-Amzn-Remapped-Content-Length
Alternate-Protocol
SRV
X-IPS-LoggedIn
X-VHOST
X-ECache
X-Akamai-Request-ID2
X-AB
Priority
X-Server-W
Country
X-Cache-Status-Check
X-N
X-Fastly-Request-Id
X-B3-Traceid
X-B3-SpanId
X-WP-CF-Super-Cache-Cookies-Bypass
X-Time
Backend
Liferay-Portal
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Real-IP
X-Mode
Onion-Location
X-Hl-Ver
Filters
Fastcgi-Useragent
X-SaId
TWC-Connection-Speed
X-Origin-Hint
TWC-GeoIP-Country
TWC-Device-Class
ServerID
X-Rewrite-Enabled
Property-Id
X-Tumblr-Pixel-2
X-Rn-Rsrv
Meta-Geo
X-JoinUs
X-FB-TRIP-ID
X-Format
Webcakes-App-Name
Xet-Cookie
Webcakes-App-Version
X-Cache-Host
Environment
TWC-Privacy
TWC-GeoIP-LatLong
Webcakes-Region
TWC-Locale-Group
X-UPSTREAM-Address
Expiry
Web-Mar-Node
From-Origin
DB-Nickname
Uber-Trace-Id
X-Tb
Mn-Server-Ip
X-Rocket-Nginx-Serving-Static
X-Redis-Cache
X-Skip-Cache
X-Scope-Id
X-IPLB-Request-ID
X-IPLB-Instance
X-Frame-Option
X-Hosted-By
X-SayCDN-TTL
X-Origin-Date
X-Restarts
X-R9-Blue-Green-Version
X-Say-Cacheable
X-Say-TTL
X-Accel-Version
X-Request-URI
X-Varnish-Age
X-VC-Cache
X-Cache-Expired-At
X-Cache-Action
X-Connection-Hash
X-Cluster-Node
X-Fetched-On
X-Tncms
Apigw-Requestid
X-Web-Node
X-Webstats-RespID
X-Vcache
X-Varnish-Cache-Hits
Atl-Traceid
X-Soup
X-Varnish-Beresp-Grace
X-PHP-Host
X-Httpd
X-Labrador-Cache-Channel
Accept-Language
X-Handled-By
X-Director
X-Forwarded-Host
X-Cms-Context
X-BYPASS-REASON
X-ProxyCache-Status
X-Loop
X-Logging-Id
X-ProxyCache-Key
X-Adobe-Source
X-Auth-Group-Type
X-Cluster
X-Timing-Wait
X-Proxy-Build
X-Served-From
X-Servername
Selected-Fe
Url
ServedBy
X-Origin-CC
X-Origin-TTL
Cross-Origin-Embedder-Policy
X-Extlb
X-Cloudmap
X-Origin
X-Detected-As
X-Nginx-Cache
X-S
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Hit
X-Wix-Request-Id
X-Generated-By
Referer-Policy
X-SRV
X-Ms-Version
X-DynaTrace
N-Cache
VIX-Pulpo-Node
X-Lagoon
X-Ms-Request-Id
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-3
X-DataDome
X-LSADC-Cache
WPO-Cache-Message
WPO-Cache-Status
Xserver
X-XRDS-Location
X-Xfnlog-Site
X-Azure-Ref-OriginShield
Surrogated-Key
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Worker
Source
Cross-Origin-Opener-Policy-Report-Only
X-App-Version
X-NWS-UUID-VERIFY
LB
X-Sucuri-Cache
CF-IPCountry
X-Cache-Debug
X-CLOUD-TRACE-CONTEXT
X-RCS-CacheZone
X-Generation-Time
X-Via-JSL
Ohc-File-Size
X-VCT
X-Proxy-Cache-Status
X-Drupal-Cache-Tags
X-F-Cache
X-Drupal-Cache-Contexts
Node
X-Cdn-Origin
X-Is-Mobile
X-Is-Tablet
X-Is-Supported-Browser
X-Tcp-Rtt
X-Is-Desktop
X-Geo-Region
X-Browser-Name
X-MP-GENERATED-AT
X-Urbn-Context-Path
X-No-Session
Locale
CDN-RequestId
X-HS-CF-Cache-Status
X-Urbn-Site-Id
X-Varnish-Beresp-Ttl
X-Upstream-Ht
X-Signature
X-UA
X-Upstream-Ct
X-B-Cache
AMP-Access-Control-Allow-Source-Origin
X-NODE
X-Litespeed-Tag
X-Cache-Hit
X-Sucuri-ID
X-RateLimit-Limit
X-TA-CDN-Provider
X-Tx-Id
X-ElasticPress-Query
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
X-NGINX-Cache
X-Shopify-Stage
X-Cache-Rule
Cache
X-Cache-Operation
X-ScT
L5d-Success-Class
Apple-News-Services-Parsed-Url
Lang
Apple-News-Services-Request-Url
Mail-Subject
MD5-Digest
BehaviorPad-Version
Cluster
Apple-News-Services-Host
Fastly-GeoIP-CountryCode
Fl-Custom-Application
DCR-Processing-Time-Ms
X-Jobs
Fastly-Backend-Name
Apple-News-Services-Handled
X-Section
X-Ig-Push-State
Expect-Staple
Candidate-Md5Url
HA-Ipaddr
Content-Secure-Policy
X-TIM-N
Ha-Gx-Prefs
DCR-Decision-By
Host-ID
X-Proto
X-Bc-Bl
X-Backend-Instance
X-FC-Vary-Parameters
X-Eu-Site
X-Ec-GeoHdr
X-BCube-Filmed-By
X-App-Name
X-Origin-Time
X-Aed
X-Access
X-Aicache-OS
X-PAYTM-SRV-ID
X-Path
X-Mvc-Supplant-Cachable
X-Ec-Fail
X-Bug-Bounty
X-Debug-Cache-Store
X-Developer
X-Debug-Cache-Fetch
X-D
X-Csrf-Jwt
X-Conf
X-Op-Id-All
X-ORCA-Accelerator
X-Cache-NE
X-Cache-Info
X-DPWN-IS-SECURE
X-Org
X-CGP
X-Gdpr
X-Mly-Id
X-Proxied-Request
Sslversion
X-Nyt-Route
User-Agent
W
X-Ig-Origin-Region
Rendered-Blocks
Redirect-Candidate
Odigeo-Trace-Id
Ngx.Var.Host
X-Rojux
Origin
Producers
PFcat
We-Hiring
X-HN
X-A-Dcw
X-A-Dam
X-A-Dgt
X-GeoCode
X-AB-Test
X-A-Wwc
X-A-Ccd
X-A
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-Platform-Server
X-GeoCountry
Meta-Geo-Continent
Cache-Provider
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-VarnishDD-TTL
X-Vdms-Version
X-Locale
Xc-Version
X-FTR-Backend
X-FTR-Expires
X-Vtex-Remote-Cache
X-Country-Code-Real
X-RID
Mime-Version
X-INCAP-ABP
X-VTEX-Cache-Time
X-Accel-Expires-Debug
X-Site-Version
X-Policy
Web-Mar-Region
X-AK-Request-ID
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Bl-Debug
X-Auto-Login
X-Amz-Storage-Class
V-Age
X-Akamai-Device-Characteristics
X-Amz-Meta-Cb-Modifiedtime
X-Platform
X-Powered-By-VTEX-Cache
X-We-Are-Hiring
Req-Svc-Chain
NM-Fastcgi-Cache
X-Wikidot-Backend
Product
X-Request-Time
Platform
X-Req
RNT-Machine
Thinkindot-CacheControl
X-Wikidot-Static-Cache
TDXMobile
X-Cache-Aspx
RNT-Time
Server-Host
Origin-Agent-Cluster
X-Origin-Response-Time
X-Gamma-Serve
X-Generated-On
X-GeoIP
X-GeoIP-City
X-Mvc-Supplant-OutputCached
X-Fmm-Version
X-Fastly-Backend
X-NMSegId
X-Service
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Irp-Debug
X-Level-Front-Cache
X-Loc
X-Location
X-Micro-Cache
X-HS-Content-Campaign-Id
X-GoCache-CacheStatus
X-Gzip
X-Hash
X-Esi-Check
X-Epic-Correlation-Id
X-Cdn-Srv
X-Clientip
X-Contensis-Viewer-Groups
X-Content-Age
X-CacheTTL
X-Cached-By
X-Cache-Id
X-SB
X-Origin-Expires
X-Content-Length
X-Core-Value
X-Dispatcher-Server
X-Edge-Server
X-Node-Id
X-NodeID
X-Depends
X-Date
X-DefElseHash
X-DefHash
X-Cache-Grace
Thinkindot-CacheControl-Type
Esi-Enabled
X-V-Cache
X-Varnish-CookieINHashed-On
Canary
X-Pad
X-Slack-Backend
Azure-SlotName
Fastly-SSL
Azure-Version
X-Var-Ttl
CDCHOST
X-Shield-Cache-Expires
Content-Style-Type
Cdncip
Cdn-Request-Time
X-Scheme
Debug
Cdnsip
Content-Script-Type
X-VG-WebCache
Cdn-Host
Azure-SiteName
X-Thinkindot-L3
X-Viewer-Country
X-SD-PageType
X-Slack-Shared-Secret-Outcome
X-Varnish-Remaining-TTL
IsBot
L
X-VTEX-Cache-Server
X-Vmg-Version
X-Varnish-Director
X-Varnish-Authentication
X-Varnish-CookieHashed-On
Azure-InstanceId
Azure-RegionName
Gannett-Cam-Experience-Id
X-SIPLIST1
X-Via-Fastly
X-Varnishpool
Gh-Request-Id
Akamai-Mon-Iucid-Del
CDN-Uid
X-Thanos
X-Acquia-Purge-Cdn-Unconfigured
CDN-RequestPullSuccess
Click-Count-Action-Start
X-Tb-Optimization-Total-Bytes-Saved
X-SVT-ORM-VERSION
X-CUA
X-Gen-Mode
X-VG-TLSProxy
X-Ec-Custom-Error
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Men
CDN-Cache
X-Block-Status
X-Bip
CDN-RequestCountryCode
CDN-PullZone
X-Cache-FS-Status
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestPullCode
Click-Count-Error
X-Human
X-Pubstack
X-Internal-TTL
DSUID
X-UA-Device-Type
Tube-Get-Contents
Country-Code
X-Hnp-Log
Req-ID
Release
Origin-CC
X-Varnish-Beresp-Status
NGX
Origin-EX
X-Request-Start
X-Server-IP
Pramga
X-Request-Host
Tube-Got-Eval
ServerName
X-Pool
Tube-Got-Results
Tube-Return
XM
User-Cache-Control
Yak-Timeinfo
X-COUNTRY
Sid
XkeyRZ
X-Proxy-CacheRZ
X-LB-NoCache
A
X-Newrelic-Synthetics
X-Varnish-Hits
X-Geolocation
Cache-Key
X-HITS
X-VServer
Ssr
X-Cache-Bucket
X-CDN-Forward
X-Cdn-Forward
X-URL
X-B-Cookie
Edge-Copy-Time
X-S-Cookie
X-Via-CDN
X-Application
X-Destination
X-IsAdmin
X-Via-SSL
X-Cache-Date
X-HOST
X-External-Request-Id
X-Api-Version
X-Via-Edge
TP-L2-Cache
X-Resp-Is-Stale
X-CACHE-GROUP
X-GEO
X-Cs
X-Optimistic-Header
Cdn-Requestid
X-Dc
X-APP
X-Nananana
X-Refresh
X-User
X-Zen-Fury
X-XRDS-LOCATION
Ohc-Cache-HIT
X-ZONE
CloudFront-Viewer-Country
X-Servedbyhost
Fastly-Drupal-HTML
X-VC-TTL
X-RequestId
X-Air-Pt
Proxy-Firewall
Server-ID
X-DC
GeoIP-Latitude
C-Via
Fastly-Drupal-Html
X-Endurance-Cache-Level
X-B3-Spanid
True-Client-Country-4JS
X-Via-Popv
X-Tt-Logid
X-Via-Poph
X-Via-Popn
X-HA-Backend
X-AIR-PT
X-LiteSpeed-Cache-Control
Server-Ext
X-Vgn-Hpd-Reason
X-Nc
X-Wa
Server-Hostname
X-LB-ID
X-TH-Server
X-CACHE-AGE
X-Test
Sever-Int
X-LJ-Flow-ID
X-DynaTrace-JS-Agent
X-AWS-Id
X-VWS-Id
X-Zone
X-B3-Parentspanid
WP-Super-Cache
Is-Eu
X-Webkit-Csp-Report-Only
X-Datadome
X-NewRelic-App-Data
HostName
GeoIp-Country-Code
Adler-Geo
X-CS
X-Provided-By
Cdn
X-LiteSpeed-Tag
X-Presslabs-Stats
X-Old-Content-Length
X-Oracle-Dms-Ecid
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Nginx-Cache-Key
X-Dispatcher-Number
X-HubSpot-Correlation-Id
WZWS-RAY
X-Parent-Response-Time
X-Srv
T-Server
S-Rt
X-Geo-Header
X-DataCenter
X-Custom-Header
X-Fpc
SID
X-API-Version
X-Pass-Why
X-ND-Cache
True-Client-IP
X-Action
Cache-Tv-Group
X-Litespeed-Cache-Control
X-CMSURLCustom
Location
X-Vercel-Id
Vc-Max-Age
X-Cache-VC
X-Thinkindot-L1
X-Vercel-Cache
X-Cache-Server
N1-Cache
Tcn
Uri
True-Client-Ip
Resin-Trace
SEZNAM-JOBS-OFFER
Pics-Label
X-TX-ID
X-Stale
Powered-By
X-SERVER-NAME
TWC-GeoIP-Region
X-PERF
Serverhost
X-FPC
X-ApacheServer
X-Ua
TWC-GeoIP-DMA
TWC-GeoIP-City
Cache-Hits
X-Datacenter
Vix-Hermes-Req-Id
X-Client-Ip
X-Varnish-Beresp-TTL
X-Dynatrace-Js-Agent
X-Ckpd-Fst-Backend
X-Fastly-Cache
GeoIP-Country-Code
X-WA-Info
X-Cache-TTL-Remaining
X-Render-Time
Sm-Log-Id
X-Service-Response-Time
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Hostname
On-Server
Thinkindot-Control
Srv
X-Nitro-Cache
Lb
X-Uri
X-Oracle-Dms-Rid
X-APP-VERSION
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
X-Ion-Hop
Av-Poweredby
RewriteTestHook
X-Air-Source
X-Fastly-Cache-Status
X-Ion-Healthy
X-Air-Trace-Id
X-Debug-Service
X-Cdn-Cache-Status
X-Air-Hostname
X-WA
Log-Origin
ServerHost
RewriteTeamHook
X-Jungle-Id
X-NC
Cache-Contol
X-Lb-Id
Server-Id
Cmstype
Geoip-Latitude
Cmsid
AKAMAI
X-PHP-Backend
X-Udemy-Cache-App-Namespace
My-App
X-Amz-Meta-Opti
X-Vc
X-Up
X-Fastly-Backend-Reqs
X-From
X-Ee-Request-Date
X-Proxy-Cache-La3
Time-Cloud-Cache
X-Cms-Device
Xkeylog
Xkey-La3
Cf-Ipcountry
X-Via-PopV
X-Ee-Generated-By
Store-Cloud-Cache
X-Ee-Origin
X-Ha-Backend
X-Vary-Devices
X-Via-PopH
X-Via-PopN
X-Save-Cache
X-Ee-Request-Id
X-Cache-Ttl
X-Correlation-ID
CacheControlHeader
X-Github-Request-Id
Cl-Cache
X-VTEX-Cache-Backend-Header-Time
X-Info
Magicmarker
X-Oracle-DMS-ECID
X-VTEX-Cache-Backend-Connect-Time
X-Geo
X-Esi
X-ServedByHost
Cloudfront-Viewer-Country
X-App
X-Requestid
X-Akamai-Pragma-Client-IP
X-VCL-Version
X-Sucuri-Id
WebServer
X-Limited
X-IAuth-Set-Uid
X-Traceid
X-CDN-Cache-Status
WWW-Authenticate
CDN
CountryCode
NtCoent-Length
X-New
X-HS-Status
X-Rollout
X-LAGOON
X-V
X-Eligible
X-Dw-Trace-Id
X-MSEdge-Flight
Warning
X-MSEdge-Features
X-CSRF-TOKEN
Cneonction
Reporter
Machine
X-Akamai-Transformed
X-Pod
Origin-Site
X-Forwarded-Site
X-Wp-Cf-Super-Cache-Cache-Control
X-Region-Sid
X-Wp-Cf-Super-Cache
X-Serial
X-Lb-Nocache
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Check-Cacheable
FSS-Cache
X-Acquia-Application-Trace
X-Td-Header-From-No-Data
Thinkindot-Cache-Type
X-Platform-Router
X-Akamai-ERPolicy
X-Web-Server
X-Platform-Processor
X-Varnish-Hostname
X-Lsadc-Cache
X-Orig-Cache-Control
X-Ramcache
X-BBC-Origin-Response-Status
X-Tncms-Bot-Tier
X-Platform-Cluster
CF-Cached-On
X-Ms-Lease-Status
X-Elasticpress-Query
Pragrma
X-Ms-Blob-Type
Server-Info
Timeexpire
X-Akamai-ERRuleID