Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
Accept-CH
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Permissions-Policy
X-Request-ID
X-Ua-Compatible
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
Accept-Ch
X-CDN
X-Check
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
X-Turbo-Charged-By
Cf-Apo-Via
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
X-UA-Device
EagleId
X-Server
X-Dispatcher
X-Vhost
X-Dns-Prefetch-Control
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Litespeed-Cache
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Allow
X-OneAgent-JS-Injection
Accept-CH-Lifetime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Cache-Lookup
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
Xkey
X-Akam-SW-Version
EagleEye-TraceId
X-Host
Surrogate-Control
X-Response-Time
Cf-Railgun
X-Readtime
X-Node
X-HW
X-Server-Id
X-LiteSpeed-Cache
X-Ruxit-JS-Agent
Request-Id
X-Country
X-Nginx-Cache-Status
X-Url
Cache-Tag
X-Content-Type
Content-Location
Accept-Ch-Lifetime
X-Nginx-Upstream-Cache-Status
X-Application-Context
X-Clacks-Overhead
X-NWS-LOG-UUID
Service-Worker-Allowed
X-Trace
Cross-Origin-Opener-Policy
Fastly-Restarts
X-Amz-Server-Side-Encryption
X-Country-Code
X-Rack-Cache
X-Times
X-Vname
X-PC
X-TtlSet
X-Midtier
X-Mcache
X-Edge
Rating
Surrogate-Key
Display
Pagespeed
X-Cache-TTL
X-Sol
X-Middleton-Display
X-Browser-Type
X-Server-Name
X-Cnection
X-Element-Page-Cache
X-Abt-Application-Version
X-Kinja
X-Kinja-Build
X-Oneagent-Js-Injection
X-GoogleNews-Bot
X-Kinja-Revision
Nginx-Cache
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-ESI
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Ser
Edge-Control
X-D2id
X-ECACHE
X-Ac
X-Vcap-Request-Id
Verso
X-MS-InvokeApp
X-Client-IP
X-Dw-Request-Base-Id
X-ARC
X-B3-TraceId
Response
X-Middleton-Response
X-CST
X-Amz-Rid
X-ORACLE-DMS-RID
X-Navigation-Version
X-Powered-CMS
X-Goog-Hash
X-Upstream
X-Wormhole-Sdk
X-Kinsta-Cache
X-Edge-Location-Klb
X-Erf-Bev-Bev-Is-Generated
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Ratelimit-Limit
X-Forwarded-For
X-Daa-Tunnel
X-Amzn-Trace-Id
X-NF-Request-ID
RTSS
X-Cache-Key
X-FastCGI-Cache
SPRequestDuration
SPIisLatency
X-Ratelimit-Remaining
X-Server-ID
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-SID
X-Mod-Pagespeed
Cache-Status
Edge-Cache-Tag
Public-Key-Pins
X-Ruxit-Js-Agent
X-Version
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Mg-S
X-Content-Digest
X-Ttl
X-SharePointHealthScore
SPRequestGuid
Realpath
S
Cross-Origin-Resource-Policy
AR-CACHE
X-Varnish-TTL
X-Fastly-Request-ID
X-MSEdge-Ref
X-Shield-Request-Id
X-T
Fastcgi-Cache
X-Cached
X-Ua-Device
X-Recruiting
X-Accel-Expires
Front-End-Https
X-Distributor
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
TP-Cache
X-TTL
X-Azure-Ref
Access-Control-Request-Method
X-Newrelic-App-Data
X-Request-Received
X-Request-Processing-Time
Count-Hit
X-Id
X-Ua-Browser
X-HS-Content-Id
X-Debug
Origin-Trial
X-HS-Cache-Config
X-HS-Hub-Id
Arr-Disable-Session-Affinity
MicrosoftSharePointTeamServices
Server-Node
X-LLID
X-Correlation-Id
X-Content-Security-Policy-Report-Only
Cache-Tags
X-Ismobilevalue
X-VARITI-CCR
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Frontend
X-HS-Combine-CSS
X-PressLabs-Stats
X-Cluster-Name
X-Varnish-Backend
X-GUploader-UploadID
X-Amz-Replication-Status
Payment
X-Hits
X-Protected-By
X-Goog-Metageneration
X-NGENIX-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-LB-Cache
X-Unique-Id
X-Forwarded-Proto
Cleartype
X-Varnish-Server
X-Www-Served-By
Host
X-Activity-Id
X-AppVersion
X-FB-Debug
X-Az
X-Ratelimit-Reset
X-Logged-In
X-Git-Hash
X-Tt-Trace-Tag
X-Tt-Trace-Host
Filterid
Content-Disposition
X-Xrds-Location
X-Hostname
X-Page-Id
Akamai-GRN
X-HP-Webp
X-HP-Trace-Id
X-Cambria-Cache-Control
X-App-Server
X-Jurisdiction
X-DIS-Request-ID
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Nf-Request-Id
X-Template
X-FTR-Request-ID
X-Geo-Country
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Aspnet-Version
X-Fastcgi-Cache
Frame-Options
X-ASPNET-VERSION
X-Origin-Server
Access-Control-Allow-Method
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Upgrade-Enabled
X-Goog-Stored-Content-Length
X-Load-Cache
MS-Author-Via
X-Type
Retry-After
Fastly-SWR
X-WP-CF-Super-Cache-Cache-Control
Fastly-SIE
Viewport
X-Ah-Environment
X-WP-CF-Super-Cache
Version
X-Content-Options
Section-Io-Cache
X-Cache-Control
Accept-Charset
X-TT
X-Fb-Rlafr
Content-MD5
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-B
X-B3-Sampled
X-TEC-API-ROOT
Amp-Access-Control-Allow-Source-Origin
X-Rid
X-Grace
X-Varnish-Ttl
X-SRCache-Fetch-Status
X-Source
X-SRCache-Store-Status
X-Envoy-Decorator-Operation
X-Vcl-Version
X-Request-Guid
X-Cdn
X-Trace-Id
X-Revision
Trailer
X-Language
X-Device-Type
Server-Name
Healthy
X-Buckets
X-Magnolia-Registration
X-Origin-Cache
X-Aspnetmvc-Version
X-Webkit-CSP
X-RateLimit-Remaining
X-Cache-Age
X-Px
X-Tec-Api-Version
X-Tec-Api-Root
X-Mobile
X-Tec-Api-Origin
X-WP-CF-Super-Cache-Active
X-CSRF-Token
X-Amz-Meta-S3cmd-Attrs
X-TraceId
X-Contextid
X-Backend-Name
X-Akamai-Edgescape
X-HS-Prerendered
TCN
X-RM-Cache-TTL
X-Status
X-App-Environment
X-Debug-Info
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Instance
X-RemovedCookies
X-NYM-Debug-Backend
X-ProcessESI
X-L-Path
X-Proxy
X-Environment-Context
X-Tumblr-User
X-Tumblr-Pixel
X-Varnish-Grace
Cross-Origin-Window-Policy
X-FW-Serve
X-FW-Type
X-UUID
X-FW-Version
X-Edge-Location
SD-X-WS
X-EdgeConnect-Cache-Status
X-Region
X-Proxy-Cache-Info
X-FW-Static
X-FW-Server
X-FW-Hash
X-Webkit-Csp
X-Node-Name
NGB
Access-Control-Request-Headers
X-FW-Dynamic
X-Storage
X-Rule
X-Framework
X-Debug-IsPreview
X-Cacheable-TTL
X-Adobe-Loc
X-Adobe-Content
X-Rendered-As
MS-CV
X-Cache-Time
X-Is-Bot
X-ServerID
GEO-INFO
X-RTag
X-HTML-Minification-Powered-By
Ms-Operation-Id
X-Mg-Request-UUID
X-Debug-IsConnected
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-G
X-Content-Powered-By
X-Datadog-Trace-Id
DC
Protected
Charset
Upgrade-Insecure-Requests
X-Seen-By
X-Whom
Paypal-Debug-Id
X-User-Agent
Cross-Origin-Embedder-Policy-Report-Only
Countrycode
OT-Force-Account-Verify
Refresh
X-Original-Request-Id
X-Lambda-Id
X-Response-Served-From
Webserver
Front
Section-Io-Id
X-WebKit-CSP-Report-Only
X-VHOST
X-TT-LOGID
X-ECache
X-Amzn-Remapped-Content-Length
X-Reqid
Alternate-Protocol
X-VC
X-IPS-LoggedIn
SRV
X-B3-Traceid
X-Server-W
X-AB
X-Akamai-Request-ID2
X-N
Country
Priority
Backend
X-WP-CF-Super-Cache-Cookies-Bypass
X-Time
X-B3-SpanId
Liferay-Portal
X-Nginx-Cache
X-Real-IP
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Cache-Status-Check
X-Mode
Onion-Location
X-XRDS-Location
X-Origin-Hint
Meta-Geo
X-Hl-Ver
TWC-GeoIP-LatLong
X-Tumblr-Pixel-2
Filters
X-Rocket-Nginx-Serving-Static
X-UPSTREAM-Address
Fastcgi-Useragent
TWC-GeoIP-Country
Property-Id
X-Format
Environment
TWC-Locale-Group
Webcakes-Region
Webcakes-App-Name
X-Cache-Host
Webcakes-App-Version
X-FB-TRIP-ID
TWC-Privacy
TWC-Device-Class
TWC-Connection-Speed
X-JoinUs
ServerID
X-SaId
X-Rn-Rsrv
X-Rewrite-Enabled
DB-Nickname
Xet-Cookie
X-Tb
Mn-Server-Ip
Web-Mar-Node
Expiry
Uber-Trace-Id
From-Origin
X-Accel-Version
X-Redis-Cache
X-Say-TTL
X-Frame-Option
X-SayCDN-TTL
X-VC-Cache
X-Hosted-By
X-Request-URI
X-Restarts
X-Say-Cacheable
X-Scope-Id
X-Fetched-On
X-Skip-Cache
X-Cache-Action
X-Cluster-Node
X-Cache-Expired-At
X-Varnish-Age
X-Connection-Hash
Atl-Traceid
X-Varnish-Cache-Hits
X-R9-Blue-Green-Version
X-Fastly-Request-Id
X-PHP-Host
X-Soup
X-IPLB-Request-ID
X-Forwarded-Host
X-Vcache
X-Director
X-Cms-Context
X-Web-Node
Apigw-Requestid
X-Origin-Date
X-Httpd
X-Loop
X-IPLB-Instance
X-Logging-Id
X-Tncms
X-Labrador-Cache-Channel
X-Webstats-RespID
X-Varnish-Beresp-Grace
X-Proxy-Build
X-Handled-By
X-Cluster
X-BYPASS-REASON
X-Auth-Group-Type
Url
X-Adobe-Source
X-Servername
X-ProxyCache-Status
X-ProxyCache-Key
X-Timing-Wait
Selected-Fe
Cross-Origin-Embedder-Policy
X-Origin-TTL
X-Origin-CC
Accept-Language
X-Served-From
ServedBy
X-Routing-Service
X-Detected-As
X-Origin
X-Cloudmap
X-Proxied
X-Extlb
X-Zipkin-Id
X-DataDome
Referer-Policy
X-Hit
X-S
N-Cache
X-DynaTrace
X-Ms-Request-Id
X-Ms-Version
X-Generated-By
X-Tumblr-Pixel-3
X-Wix-Request-Id
X-Lagoon
X-SRV
WPO-Cache-Message
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-LSADC-Cache
WPO-Cache-Status
Xserver
X-Azure-Ref-OriginShield
X-Xfnlog-Site
Cross-Origin-Opener-Policy-Report-Only
Surrogated-Key
X-RateLimit-Limit-Second
X-Worker
X-RateLimit-Remaining-Second
X-CLOUD-TRACE-CONTEXT
Source
X-App-Version
LB
X-Sucuri-Cache
X-Generation-Time
X-NWS-UUID-VERIFY
X-RCS-CacheZone
CF-IPCountry
X-Cache-Debug
Ohc-File-Size
X-Via-JSL
X-VCT
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Cdn-Origin
Node
X-Proxy-Cache-Status
X-F-Cache
X-HS-CF-Cache-Status
CDN-RequestId
X-Is-Tablet
X-MP-GENERATED-AT
X-Tcp-Rtt
X-Browser-Name
X-Geo-Region
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Desktop
X-Urbn-Context-Path
X-Cache-Hit
Locale
X-NODE
X-Urbn-Site-Id
X-No-Session
X-Upstream-Ht
X-UA
X-Tx-Id
X-Upstream-Ct
X-Signature
X-B-Cache
X-Sucuri-ID
X-Varnish-Beresp-Ttl
X-ElasticPress-Query
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-TA-CDN-Provider
X-FTR-Balancer
X-Litespeed-Tag
X-ShardId
X-Alternate-Cache-Key
X-Cache-Rule
X-ShopId
Cache
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Cache-Operation
Apple-News-Services-Request-Url
X-BCube-Filmed-By
Wxu-Next-Commit
Fl-Custom-Application
Wxu-Next-Hostname
MD5-Digest
X-VarnishDD-TTL
Lang
X-HN
Meta-Geo-Continent
Fastly-GeoIP-CountryCode
PFcat
Ngx.Var.Host
X-Section
Expect-Staple
X-Proxied-Request
BehaviorPad-Version
Cluster
Fastly-Backend-Name
X-Jobs
Wxu-Next-Region
X-Nyt-Route
Apple-News-Services-Parsed-Url
Cache-Provider
X-Access
X-Op-Id-All
X-App-Name
X-Ig-Origin-Region
X-Aed
Apple-News-Services-Host
Host-ID
User-Agent
Mail-Subject
X-Bc-Bl
X-Backend-Instance
W
X-Vdms-Version
Apple-News-Services-Handled
We-Hiring
X-Ig-Push-State
Candidate-Md5Url
X-D
X-TIM-N
X-Debug-Cache-Fetch
X-Aicache-OS
X-Origin-Time
DCR-Processing-Time-Ms
X-Ec-GeoHdr
X-A-Dgt
Odigeo-Trace-Id
AMP-Access-Control-Allow-Source-Origin
DCR-Decision-By
X-Debug-Cache-Store
X-Developer
X-Ec-Fail
X-DPWN-IS-SECURE
X-A-Dam
Rendered-Blocks
Origin
X-A-Ccd
X-ScT
X-A-Dcw
X-Cache-Info
X-Gdpr
Redirect-Candidate
X-Mly-Id
X-Vtex-Remote-Cache
Producers
X-Platform-Server
X-Org
X-Cache-NE
X-ORCA-Accelerator
Content-Secure-Policy
X-A-Wwc
X-Rojux
Sslversion
Xc-Version
X-GeoCode
X-A
X-PAYTM-SRV-ID
X-AB-Test
X-Path
X-Conf
X-GeoCountry
Mime-Version
X-Locale
X-INCAP-ABP
Web-Mar-Region
Server-Host
Origin-Agent-Cluster
Platform
X-SD-PageType
Product
NM-Fastcgi-Cache
X-Shield-Cache-Expires
IsBot
L
L5d-Success-Class
Req-Svc-Chain
RNT-Machine
Thinkindot-CacheControl-Type
X-Request-Time
V-Age
Thinkindot-CacheControl
TDXMobile
RNT-Time
X-Scheme
X-SB
X-Req
X-Cdn-Srv
X-Fmm-Version
X-FC-Vary-Parameters
X-Node-Id
X-NMSegId
X-Generated-On
X-Gamma-Serve
X-NodeID
X-Fastly-Backend
X-Origin-Expires
X-Edge-Server
X-Epic-Correlation-Id
X-Esi-Check
X-Eu-Site
X-GeoIP
X-GeoIP-City
X-Mvc-Supplant-Cachable
X-Level-Front-Cache
X-Loc
X-Location
X-Micro-Cache
X-Irp-Debug
X-HS-Content-Campaign-Id
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-GoCache-CacheStatus
X-Gzip
X-Hash
X-Dispatcher-Server
X-Origin-Response-Time
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
X-Bl-Debug
X-Bug-Bounty
X-Cache-Grace
X-Cache-Aspx
X-Auto-Login
X-Amz-Storage-Class
X-AK-Request-ID
X-Proto
X-Akamai-Device-Characteristics
X-Amz-Meta-Cb-Modifiedtime
X-Powered-By-VTEX-Cache
X-Cache-Id
X-Cached-By
X-Date
X-Csrf-Jwt
X-DefElseHash
X-DefHash
X-Depends
X-Core-Value
X-Content-Length
X-CGP
X-SIPLIST1
X-Clientip
X-Contensis-Viewer-Groups
X-Content-Age
X-Accel-Expires-Debug
CDCHOST
X-Varnish-Authentication
X-V-Cache
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Director
Azure-InstanceId
Azure-RegionName
Cdn-Host
Cdn-Request-Time
Azure-Version
Azure-SlotName
Azure-SiteName
X-Service
X-Varnish-Remaining-TTL
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-We-Are-Hiring
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Vmg-Version
X-Viewer-Country
X-Varnishpool
X-VG-WebCache
X-Via-Fastly
X-Slack-Backend
Cdncip
X-Thinkindot-L3
Esi-Enabled
Fastly-SSL
Debug
Content-Style-Type
Cdnsip
Gannett-Cam-Experience-Id
X-Slack-Shared-Secret-Outcome
HA-Ipaddr
Content-Script-Type
Ha-Gx-Prefs
X-Pad
X-Site-Version
Akamai-Mon-Iucid-Del
X-Block-Status
CDN-PullZone
X-VG-TLSProxy
X-Cache-FS-Status
X-Men
X-Policy
X-Pool
DSUID
X-Internal-TTL
Origin-EX
X-Var-Ttl
X-Acquia-Purge-Cdn-Unconfigured
Origin-CC
Country-Code
X-Mvc-Supplant-OutputCached
X-Sn-Servicetimems
X-CacheTTL
X-Gen-Mode
CDN-Uid
XM
Yak-Timeinfo
X-Ec-Custom-Error
X-VServer
X-Geolocation
X-HITS
Req-ID
CDN-RequestCountryCode
X-Server-IP
X-Platform
Gh-Request-Id
CDN-RequestPullSuccess
CDN-RequestPullCode
ServerName
NGX
Tube-Return
Tube-Got-Results
Tube-Got-Eval
Pramga
User-Cache-Control
Click-Count-Error
X-UA-Device-Type
Tube-Get-Contents
X-Request-Host
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
Canary
X-Human
X-Request-Start
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Click-Count-Action-Start
X-Hnp-Log
X-Tb-Optimization-Total-Bytes-Saved
X-URL
X-CDN-Forward
X-B-Cookie
X-Newrelic-Synthetics
X-Via-Edge
Release
X-Thanos
X-Varnish-Hits
X-Proxy-CacheRZ
X-Pubstack
X-IsAdmin
Edge-Copy-Time
X-Varnish-Beresp-Status
X-RID
Cache-Key
X-CUA
XkeyRZ
X-Via-CDN
X-RateLimit-Limit
X-Via-SSL
X-Cache-Bucket
X-Application
X-HOST
X-Bip
X-LB-NoCache
X-External-Request-Id
X-NGINX-Cache
Ssr
A
X-Cache-Date
X-Destination
X-S-Cookie
X-CACHE-GROUP
X-Cdn-Forward
X-Resp-Is-Stale
X-GEO
Sid
X-Api-Version
X-ZONE
X-User
X-Refresh
X-Zen-Fury
X-APP
X-Cs
CloudFront-Viewer-Country
X-Servedbyhost
TP-L2-Cache
X-Nananana
X-Optimistic-Header
X-Dc
Cdn-Requestid
Fastly-Drupal-HTML
X-VC-TTL
Ohc-Cache-HIT
X-DC
X-Oracle-Dms-Ecid
X-Air-Pt
GeoIP-Latitude
X-RequestId
X-HA-Backend
X-Via-Popn
X-Via-Poph
X-Via-Popv
C-Via
X-Tt-Logid
X-B3-Spanid
Proxy-Firewall
Server-ID
X-Endurance-Cache-Level
Fastly-Drupal-Html
X-Nc
X-Wa
True-Client-Country-4JS
X-TH-Server
X-Vgn-Hpd-Reason
X-CACHE-AGE
X-LB-ID
X-AIR-PT
Server-Ext
Sever-Int
Server-Hostname
X-LiteSpeed-Cache-Control
X-B3-Parentspanid
X-Test
X-Webkit-Csp-Report-Only
X-CS
X-LiteSpeed-Tag
X-Presslabs-Stats
X-XRDS-LOCATION
X-SERVER-NAME
Cdn
X-Old-Content-Length
X-Moov-Xdn-Version
X-Moov-Xdn-Caching-Status
X-Moov-T
WP-Super-Cache
X-VWS-Id
X-COUNTRY
X-LJ-Flow-ID
X-AWS-Id
Is-Eu
HostName
X-DynaTrace-JS-Agent
GeoIp-Country-Code
Adler-Geo
X-Dispatcher-Number
X-Datadome
X-Provided-By
SID
X-Nginx-Cache-Key
X-Srv
X-Zone
X-Parent-Response-Time
X-HubSpot-Correlation-Id
WZWS-RAY
X-DataCenter
X-Fpc
X-API-Version
X-Action
X-NewRelic-App-Data
T-Server
X-Custom-Header
X-Geo-Header
S-Rt
X-Litespeed-Cache-Control
X-Pass-Why
X-ND-Cache
Location
X-Cache-VC
X-Vercel-Id
X-Thinkindot-L1
X-Vercel-Cache
True-Client-IP
Uri
Cache-Tv-Group
X-Oracle-Dms-Rid
N1-Cache
SEZNAM-JOBS-OFFER
X-CMSURLCustom
X-Cache-Server
True-Client-Ip
Vc-Max-Age
Pics-Label
Resin-Trace
X-Datacenter
X-PERF
Cache-Hits
X-Stale
X-ApacheServer
X-TX-ID
X-Ua
Serverhost
TWC-GeoIP-City
Tcn
Powered-By
TWC-GeoIP-DMA
TWC-GeoIP-Region
X-Client-Ip
X-Varnish-Beresp-TTL
X-Dynatrace-Js-Agent
X-FPC
X-WA-Info
X-Render-Time
Vix-Hermes-Req-Id
GeoIP-Country-Code
X-Service-Response-Time
Sm-Log-Id
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Fastly-Cache
X-Cache-TTL-Remaining
Hostname
Srv
X-Ckpd-Fst-Backend
X-Uri
X-Nitro-Cache
Lb
X-APP-VERSION
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
X-Vc
Av-Poweredby
X-Debug-Service
X-Cdn-Cache-Status
RewriteTeamHook
Thinkindot-Control
Cache-Contol
X-Jungle-Id
On-Server
X-Ion-Hop
X-Fastly-Cache-Status
RewriteTestHook
X-Ion-Healthy
Log-Origin
X-Air-Trace-Id
X-Air-Hostname
My-App
X-Air-Source
Cmsid
Server-Id
X-Udemy-Cache-App-Namespace
X-WA
ServerHost
X-NC
Cmstype
X-Ee-Request-Date
X-Cms-Device
X-Amz-Meta-Opti
X-Ee-Origin
X-PHP-Backend
X-From
X-Ee-Generated-By
Geoip-Latitude
Store-Cloud-Cache
X-Save-Cache
Cf-Ipcountry
AKAMAI
X-Up
X-Vary-Devices
X-Lb-Id
X-Ee-Request-Id
Time-Cloud-Cache
X-Correlation-ID
X-Cache-Ttl
X-Ha-Backend
X-Github-Request-Id
X-Via-PopH
X-Oracle-DMS-ECID
X-Via-PopV
Xkeylog
X-Via-PopN
CacheControlHeader
X-Fastly-Backend-Reqs
Xkey-La3
X-Proxy-Cache-La3
X-Esi
WebServer
Cl-Cache
Magicmarker
X-Info
X-VTEX-Cache-Backend-Header-Time
X-VTEX-Cache-Backend-Connect-Time
X-Akamai-Pragma-Client-IP
X-VCL-Version
X-App
X-Sucuri-Id
X-IAuth-Set-Uid
X-Requestid
X-Geo
X-ServedByHost
X-Traceid
X-Limited
Cloudfront-Viewer-Country
WWW-Authenticate
CountryCode
X-Dw-Trace-Id
NtCoent-Length
X-MSEdge-Flight
X-CDN-Cache-Status
X-MSEdge-Features
Warning
X-LAGOON
X-HS-Status
CDN
Reporter
X-Lb-Nocache
Origin-Site
X-Akamai-Transformed
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-Acquia-Application-UUID
X-Serial
X-Pod
X-New
X-Acquia-Application-Trace
X-Eligible
X-Check-Cacheable
FSS-Cache
X-Acquia-Site
X-Acquia-Purge-Tags
X-Rollout
X-V
X-Td-Header-From-No-Data
X-Lsadc-Cache
X-Varnish-Hostname
Machine
X-Web-Server
Thinkindot-Cache-Type
X-BBC-Origin-Response-Status
CF-Cached-On
X-Elasticpress-Query
Timeexpire
Cneonction
X-Akamai-ERPolicy
X-Orig-Cache-Control
X-Forwarded-Site
X-Akamai-ERRuleID
X-Tncms-Bot-Tier
X-Ms-Lease-Status
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-Ramcache
X-Ms-Blob-Type
X-Region-Sid