Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Permissions-Policy
X-Content-Security-Policy
X-Check
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-Ua-Compatible
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
X-Turbo-Charged-By
Cf-Apo-Via
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
Accept-CH
X-Age
EagleId
X-Server
X-Dispatcher
X-UA-Device
X-Vhost
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Dns-Prefetch-Control
Accept-CH-Lifetime
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Litespeed-Cache
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Pingback
Allow
X-Swift-CacheTime
X-Swift-SaveTime
X-Cache-Lookup
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Page-Speed
X-Device
X-Cloud-Trace-Context
X-Backend-Server
EagleEye-TraceId
X-Akam-SW-Version
X-Host
Surrogate-Control
X-Response-Time
Cf-Railgun
X-Readtime
Xkey
X-HW
X-LiteSpeed-Cache
X-Node
X-Server-Id
X-Ruxit-JS-Agent
Request-Id
X-Country
X-Url
X-Nginx-Cache-Status
X-NWS-LOG-UUID
X-Application-Context
Cache-Tag
X-Content-Type
Content-Location
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
Service-Worker-Allowed
X-Trace
X-Amz-Server-Side-Encryption
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Times
X-Rack-Cache
X-Country-Code
X-PC
X-TtlSet
X-Vname
X-Edge
X-Mcache
X-Midtier
Rating
Surrogate-Key
X-Server-Name
X-Browser-Type
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Cache-TTL
X-Cnection
X-Abt-Application-Version
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Element-Page-Cache
X-ESI
X-Oneagent-Js-Injection
Nginx-Cache
X-Ser
X-Powered-By-Plesk
X-GitHub-Request-Id
Edge-Control
X-D2id
Verso
X-Ac
X-ECACHE
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-ARC
X-MS-InvokeApp
X-Client-IP
X-B3-TraceId
X-Daa-Tunnel
X-CST
X-Amz-Rid
X-Goog-Hash
X-Navigation-Version
Response
X-Middleton-Response
X-Upstream
X-Powered-CMS
X-ORACLE-DMS-RID
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Server-ID
X-Kinsta-Cache
X-Edge-Location-Klb
X-NF-Request-ID
Accept-Ch-Lifetime
X-Ua-Device
X-Forwarded-For
X-Amzn-Trace-Id
X-Wormhole-Sdk
X-Cache-Key
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
RTSS
X-Ratelimit-Limit
X-Ttl
X-Ratelimit-Remaining
X-Mod-Pagespeed
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
Cache-Status
X-Version
Public-Key-Pins
X-Ruxit-Js-Agent
X-Mg-S
AR-CACHE
X-ORACLE-DMS-ECID
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
X-FastCGI-Cache
X-Content-Digest
S
Realpath
SPRequestGuid
X-SharePointHealthScore
X-MSEdge-Ref
X-Shield-Request-Id
Fastcgi-Cache
X-T
X-Cached
X-Recruiting
X-Fastly-Request-ID
X-Accel-Expires
X-Distributor
X-Varnish-TTL
Access-Control-Request-Method
X-Kong-Upstream-Latency
Front-End-Https
X-Kong-Proxy-Latency
X-Newrelic-App-Data
TP-Cache
X-Correlation-Id
Count-Hit
Arr-Disable-Session-Affinity
X-Debug
MicrosoftSharePointTeamServices
X-HS-Hub-Id
X-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Request-Received
X-Request-Processing-Time
X-Content-Security-Policy-Report-Only
Server-Node
X-Azure-Ref
X-LLID
X-Ua-Browser
X-VARITI-CCR
X-HS-Combine-CSS
X-Frontend
X-PressLabs-Stats
X-Cluster-Name
Cache-Tags
X-Ismobilevalue
X-Ah-Environment
X-Hits
Accept-Ch
Payment
X-Amz-Replication-Status
X-GUploader-UploadID
X-Varnish-Backend
X-LB-Cache
X-Goog-Metageneration
X-TTL
X-Forwarded-Proto
X-Microsite
X-Request-Handler-Origin-Region
X-Protected-By
X-Fastcgi-Cache
X-Git-Hash
X-Unique-Id
X-Logged-In
Cleartype
X-FB-Debug
Filterid
Origin-Trial
X-Varnish-Server
X-Az
Host
X-AppVersion
X-Activity-Id
Content-Disposition
X-Ratelimit-Reset
X-Www-Served-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-App-Server
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Hostname
X-NGENIX-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Page-Id
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-DIS-Request-ID
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Geo-Country
X-Varnish-Ttl
X-Cambria-Cache-Control
Access-Control-Allow-Method
X-Origin-Server
X-Aspnet-Version
Retry-After
Akamai-GRN
X-Load-Cache
X-ASPNET-VERSION
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Xrds-Location
X-Template
X-Upgrade-Enabled
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Fastly-SIE
Fastly-SWR
MS-Author-Via
Section-Io-Cache
Accept-Charset
X-TT
Viewport
X-Type
X-Content-Options
X-Fb-Rlafr
X-Cache-Control
Frame-Options
X-B3-Sampled
Version
X-B
X-Grace
Content-MD5
X-Nf-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Request-Guid
X-Trace-Id
X-Revision
X-Vcl-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cdn
X-Envoy-Decorator-Operation
Healthy
X-Device-Type
X-Origin-Cache
X-RateLimit-Remaining
X-Magnolia-Registration
X-Rid
X-Amz-Meta-S3cmd-Attrs
X-Source
X-Contextid
X-CSRF-Token
X-Webkit-CSP
X-Aspnetmvc-Version
TCN
Server-Name
X-Cache-Age
X-Px
X-WP-CF-Super-Cache-Active
X-Backend-Name
X-Mobile
X-Language
X-Proxy
X-Buckets
X-RM-Cache-TTL
DC
X-Akamai-Edgescape
X-App-Environment
X-L-Path
X-Environment-Context
X-Debug-Info
X-Rule
Access-Control-Request-Headers
X-Status
X-Framework
X-Mg-Request-UUID
X-Varnish-Grace
X-Tumblr-Pixel-0
X-Cacheable-TTL
Cross-Origin-Window-Policy
X-Adobe-Loc
NGB
X-Seen-By
X-HTML-Minification-Powered-By
X-Storage
X-Adobe-Content
X-Content-Powered-By
X-Tumblr-Pixel-1
X-FW-Static
X-FW-Server
X-Instance
X-FW-Type
X-G
X-Tumblr-Pixel
X-FW-Version
X-UUID
X-Proxy-Cache-Info
X-EdgeConnect-Cache-Status
X-ServerID
X-FW-Dynamic
X-FW-Hash
X-Tumblr-User
X-Region
X-FW-Serve
X-NYM-Debug-Backend
X-Datadog-Sampling-Priority
Trailer
Ms-Operation-Id
MS-CV
GEO-INFO
X-Tec-Api-Version
X-RTag
X-Rendered-As
X-Datadog-Sampled
X-Debug-IsConnected
X-Node-Name
X-Datadog-Parent-Id
X-Tec-Api-Root
X-Is-Bot
X-Tec-Api-Origin
X-Debug-IsPreview
X-Datadog-Trace-Id
X-ProcessESI
X-RemovedCookies
SD-X-WS
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Time
X-User-Agent
Paypal-Debug-Id
Upgrade-Insecure-Requests
Countrycode
Charset
Webserver
Protected
Front
X-Whom
X-Edge-Location
OT-Force-Account-Verify
X-HS-Prerendered
X-Lambda-Id
X-TT-LOGID
X-FTR-Request-ID
Refresh
Section-Io-Id
X-VHOST
X-ECache
X-VC
X-IPS-LoggedIn
X-WebKit-CSP-Report-Only
X-N
X-Akamai-Request-ID2
X-AB
X-Cache-Status-Check
Country
X-Reqid
Priority
X-B3-Traceid
X-Time
Alternate-Protocol
X-Fastly-Request-Id
Backend
X-Amzn-Remapped-Content-Length
Xet-Cookie
X-Response-Served-From
X-Original-Request-Id
X-B3-SpanId
X-TraceId
SRV
X-Server-W
X-WP-CF-Super-Cache-Cookies-Bypass
Cross-Origin-Embedder-Policy-Report-Only
Liferay-Portal
X-Hl-Ver
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Mode
X-Real-IP
Onion-Location
ServerID
X-Origin-Date
X-Auth-Group-Type
X-Accel-Version
X-Rewrite-Enabled
X-FB-TRIP-ID
X-Frame-Option
From-Origin
Environment
Fastcgi-Useragent
X-Tb
Filters
X-Cache-Host
X-Scope-Id
X-SaId
X-Rn-Rsrv
X-UPSTREAM-Address
Meta-Geo
X-Fetched-On
X-VC-Cache
X-Web-Node
X-JoinUs
TWC-Device-Class
X-ProxyCache-Key
X-Skip-Cache
TWC-Connection-Speed
Property-Id
TWC-GeoIP-Country
X-Hosted-By
X-R9-Blue-Green-Version
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-SayCDN-TTL
X-Say-TTL
Accept-Language
X-Webstats-RespID
Atl-Traceid
X-Restarts
X-Request-URI
X-Nginx-Cache
X-ProxyCache-Status
Webcakes-App-Version
X-Say-Cacheable
X-Cache-Action
X-BYPASS-REASON
X-Logging-Id
X-Varnish-Cache-Hits
X-Director
X-Cluster-Node
X-IPLB-Instance
X-IPLB-Request-ID
X-Origin-Hint
X-Format
Webcakes-Region
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
X-Served-From
X-Loop
VIX-Pulpo-Node
X-Adobe-Source
X-Forwarded-Host
Apigw-Requestid
X-Handled-By
X-Httpd
X-Vcache
X-PHP-Host
DB-Nickname
X-Labrador-Cache-Channel
X-Varnish-Beresp-Grace
Mn-Server-Ip
X-Varnish-Age
Uber-Trace-Id
X-Redis-Cache
X-Wix-Request-Id
Web-Mar-Node
X-Tncms
X-Soup
X-Generated-By
X-Origin-TTL
X-Origin-CC
X-Tumblr-Pixel-2
X-Cluster
X-Timing-Wait
X-Cms-Context
X-Proxy-Build
Selected-Fe
X-NODE
ServedBy
X-Origin
Expiry
Url
X-Connection-Hash
X-Zipkin-Id
X-Servername
X-Detected-As
X-Proxied
X-Routing-Service
X-S
X-Via-JSL
X-Cloudmap
X-Extlb
X-DataDome
Referer-Policy
X-SRV
X-LSADC-Cache
X-Rocket-Nginx-Serving-Static
X-Lagoon
X-XRDS-Location
Xserver
Cross-Origin-Embedder-Policy
X-DynaTrace
N-Cache
LB
X-Hit
X-Ms-Version
X-Ms-Request-Id
X-Webkit-Csp
X-Xfnlog-Site
CF-IPCountry
X-NWS-UUID-VERIFY
X-Tumblr-Pixel-3
WPO-Cache-Message
WPO-Cache-Status
X-Azure-Ref-OriginShield
Source
X-VCT
X-Cache-Debug
Surrogated-Key
X-Upstream-Ct
X-Upstream-Ht
X-RCS-CacheZone
X-Proxy-Cache-Status
CDN-RequestId
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-UA
X-App-Version
X-Worker
X-Sucuri-Cache
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
X-RID
X-Browser-Name
X-Is-Tablet
X-Tcp-Rtt
X-Generation-Time
X-Geo-Region
X-Urbn-Site-Id
X-XRDS-LOCATION
X-Urbn-Context-Path
Node
X-CLOUD-TRACE-CONTEXT
Locale
X-Signature
X-B-Cache
X-F-Cache
X-Drupal-Cache-Tags
X-Cdn-Origin
X-RateLimit-Limit
X-Sucuri-ID
X-No-Session
X-Drupal-Cache-Contexts
Ohc-File-Size
Cross-Origin-Opener-Policy-Report-Only
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Tx-Id
X-MP-GENERATED-AT
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Varnish-Beresp-Ttl
X-Locale
X-Cdn-Forward
X-Cache-Rule
X-Cache-Operation
TDXMobile
Thinkindot-CacheControl
X-AK-Request-ID
Redirect-Candidate
Producers
X-Backend-Instance
X-Aicache-OS
Rendered-Blocks
Sslversion
Thinkindot-CacheControl-Type
X-A-Ccd
X-BCube-Filmed-By
X-A-Dam
X-A-Dcw
X-A
X-App-Name
X-A-Dgt
We-Hiring
X-Bc-Bl
X-A-Wwc
X-Aed
Mail-Subject
Candidate-Md5Url
BehaviorPad-Version
Cdncip
Cdnsip
Content-Secure-Policy
Azure-Version
Azure-SlotName
A
Azure-InstanceId
Azure-RegionName
Azure-SiteName
DCR-Decision-By
DCR-Processing-Time-Ms
Meta-Geo-Continent
MD5-Digest
Ngx.Var.Host
Odigeo-Trace-Id
Origin
X-Bug-Bounty
Lang
Expect-Staple
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Gannett-Cam-Experience-Id
Origin-Agent-Cluster
X-Debug-Cache-Store
X-Proxied-Request
X-Proto
X-Proxy-CacheRZ
X-Request-Time
X-Rojux
X-Platform-Server
X-Path
X-Nyt-Route
X-Mvc-Supplant-OutputCached
X-Origin-Expires
X-Origin-Response-Time
X-Origin-Time
X-ScT
X-Shield-Cache-Expires
X-Vtex-Remote-Cache
X-Vmg-Version
X-We-Are-Hiring
Xc-Version
XkeyRZ
X-Vdms-Version
X-Varnish-Remaining-TTL
X-TIM-N
X-Thinkindot-L3
X-Varnish-Authentication
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Mvc-Supplant-Cachable
X-Mly-Id
X-Developer
X-DefHash
X-DPWN-IS-SECURE
X-Ec-Fail
X-Ec-GeoHdr
X-DefElseHash
X-Debug-Cache-Fetch
X-Cache-NE
X-Cache-Info
X-Conf
X-Contensis-Viewer-Groups
X-D
X-Epic-Correlation-Id
X-FC-Vary-Parameters
X-INCAP-ABP
X-Ig-Push-State
X-Internal-TTL
X-Jobs
X-Loc
X-Ig-Origin-Region
X-GeoIP-City
X-Gdpr
X-GeoCode
X-GeoCountry
X-GeoIP
X-Cache-Aspx
X-Depends
AMP-Access-Control-Allow-Source-Origin
X-Site-Version
X-NGINX-Cache
X-Cache-Hit
X-Newrelic-Synthetics
Mime-Version
X-Gamma-Serve
X-Fastly-Backend
X-Ec-Custom-Error
X-Edge-Server
X-Esi-Check
X-Generated-On
X-Fmm-Version
X-GeoIP-Country-Code
X-Level-Front-Cache
X-Location
X-Micro-Cache
X-Org
X-Irp-Debug
X-Human
X-GoCache-CacheStatus
X-Gzip
X-Hash
X-HS-Content-Campaign-Id
X-GeoIP-Region-Code
X-Content-Age
X-Acquia-Purge-Cdn-Unconfigured
X-Amz-Meta-Cb-Modifiedtime
X-Amz-Storage-Class
X-Auto-Login
X-Accel-Expires-Debug
Web-Mar-Region
Tube-Got-Eval
Tube-Got-Results
Tube-Return
V-Age
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-CacheTTL
X-Cdn-Srv
X-Clientip
X-Core-Value
X-Cached-By
X-Cache-Id
X-Bl-Debug
X-Cache-Bucket
X-Cache-Grace
X-Date
X-Platform
Cache-Provider
Ha-Gx-Prefs
HA-Ipaddr
L
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Wikidot-Static-Cache
Yak-Timeinfo
Apple-News-Services-Handled
Apple-News-Services-Host
L5d-Success-Class
User-Agent
X-CGP
X-Csrf-Jwt
X-Eu-Site
X-Section
X-Akamai-Device-Characteristics
X-Access
W
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Wikidot-Backend
X-Pad
X-SIPLIST1
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-Scheme
X-Service
Tube-Get-Contents
X-Policy
X-Pool
X-Powered-By-VTEX-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VG-WebCache
X-Viewer-Country
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Varnishpool
X-Varnish-Director
X-Tb-Optimization-Total-Bytes-Saved
X-UA-Device-Type
X-V-Cache
X-Var-Ttl
X-PAYTM-SRV-ID
X-NMSegId
Origin-CC
Click-Count-Action-Start
IsBot
Click-Count-Error
Content-Style-Type
Content-Script-Type
X-ElasticPress-Query
Server-Host
NM-Fastcgi-Cache
RNT-Time
Cdn-Request-Time
RNT-Machine
Req-Svc-Chain
Cdn-Host
Host-ID
Cluster
Release
Product
Cache
Debug
Platform
Canary
Cache-Key
Esi-Enabled
Gh-Request-Id
DSUID
Origin-EX
Akamai-Mon-Iucid-Del
CDN-PullZone
Fastly-SSL
CDCHOST
CDN-CachedAt
X-CUA
CDN-RequestCountryCode
XM
CDN-EdgeStorageId
X-Dispatcher-Server
CDN-RequestPullSuccess
X-Men
X-SB
X-SD-PageType
X-Server-IP
X-Request-Start
X-Request-Host
X-Node-Id
X-Pubstack
X-Req
Country-Code
X-Hnp-Log
X-Gen-Mode
X-VG-TLSProxy
CDN-RequestPullCode
X-Via-Fastly
PFcat
CDN-Uid
X-Thanos
Ssr
X-Varnish-Beresp-Status
NGX
CDN-Cache
X-HN
X-NodeID
X-Content-Length
X-AB-Test
X-Bip
X-Op-Id-All
X-VarnishDD-TTL
User-Cache-Control
ServerName
X-Optimistic-Header
Pramga
Fl-Custom-Application
Req-ID
X-ORCA-Accelerator
X-Cache-FS-Status
X-Block-Status
X-HS-CF-Cache-Status
X-Litespeed-Tag
X-HOST
TP-L2-Cache
X-VServer
X-Varnish-Hits
X-CACHE-GROUP
X-LB-NoCache
Sid
X-Oracle-Dms-Ecid
X-Api-Version
X-Cache-Date
X-Dc
X-TA-CDN-Provider
X-Geolocation
X-Refresh
X-Cs
X-GEO
X-IsAdmin
X-Destination
X-Nananana
X-LiteSpeed-Cache-Control
True-Client-Country-4JS
X-S-Cookie
X-B-Cookie
X-External-Request-Id
X-Application
X-Servedbyhost
CloudFront-Viewer-Country
X-APP
Proxy-Firewall
X-HITS
X-VWS-Id
Fastly-Drupal-HTML
X-AWS-Id
X-LJ-Flow-ID
X-DC
Sever-Int
Edge-Copy-Time
X-Via-CDN
X-Via-Edge
X-Test
C-Via
X-RequestId
X-Zen-Fury
Server-Hostname
Server-Ext
X-Via-SSL
GeoIP-Latitude
X-LiteSpeed-Tag
X-Provided-By
X-Zone
X-B3-Spanid
Adler-Geo
X-Via-Popn
X-HA-Backend
X-Via-Poph
Is-Eu
X-Webkit-Csp-Report-Only
X-Via-Popv
X-Air-Pt
X-Endurance-Cache-Level
X-CDN-Forward
Cdn-Requestid
X-User
X-Nc
Server-ID
X-Wa
Fastly-Drupal-Html
X-LB-ID
X-Nginx-Cache-Key
X-ZONE
X-B3-Parentspanid
X-Dispatcher-Number
X-AIR-PT
Ohc-Cache-HIT
HostName
WZWS-RAY
S-Rt
X-DynaTrace-JS-Agent
X-Tt-Logid
X-VC-TTL
X-Presslabs-Stats
Cdn
X-COUNTRY
Cache-Tv-Group
X-URL
X-Custom-Header
T-Server
X-Geo-Header
X-Parent-Response-Time
X-CS
X-TH-Server
X-Pass-Why
SID
WP-Super-Cache
X-ND-Cache
GeoIp-Country-Code
X-HubSpot-Correlation-Id
X-Srv
X-CACHE-AGE
X-Fpc
Resin-Trace
X-FTR-Cache-Status
X-Cache-Server
X-FTR-Balancer
X-CMSURLCustom
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Expires
X-API-Version
Vc-Max-Age
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Vgn-Hpd-Reason
X-DataCenter
X-Moov-T
X-Datadome
X-Oracle-Dms-Rid
X-Old-Content-Length
X-NewRelic-App-Data
True-Client-IP
Pics-Label
Vix-Hermes-Req-Id
Powered-By
SEZNAM-JOBS-OFFER
True-Client-Ip
Uri
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Cache-VC
X-Varnish-Beresp-TTL
X-Vercel-Cache
X-Thinkindot-L1
X-Fastly-Cache
Location
X-Vercel-Id
Thinkindot-Control
X-Ckpd-Fst-Backend
X-Action
X-SERVER-NAME
On-Server
X-FPC
X-TX-ID
GeoIP-Country-Code
Serverhost
X-Resp-Is-Stale
X-Dynatrace-Js-Agent
X-APP-VERSION
X-Client-Ip
ServerHost
Srv
N1-Cache
X-Cache-TTL-Remaining
Tcn
X-Stale
AKAMAI
X-Litespeed-Cache-Control
X-Amz-Meta-Opti
X-PHP-Backend
X-PERF
X-Air-Trace-Id
Server-Id
X-Debug-Service
Hostname
X-Cdn-Cache-Status
X-Fastly-Cache-Status
X-Air-Hostname
X-Datacenter
X-ApacheServer
X-Air-Source
Av-Poweredby
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
X-WA-Info
Cl-Cache
Magicmarker
X-WA
X-NC
X-Info
X-Nitro-Cache
X-Service-Response-Time
Sm-Log-Id
X-Vc
TWC-GeoIP-DMA
Cache-Hits
TWC-GeoIP-City
TWC-GeoIP-Region
X-Save-Cache
X-Vary-Devices
X-Lb-Id
X-Ee-Request-Id
X-Uri
X-Udemy-Cache-App-Namespace
X-Render-Time
X-Cms-Device
X-Ee-Request-Date
Xkeylog
X-Proxy-Cache-La3
X-Geo
X-Fastly-Backend-Reqs
Store-Cloud-Cache
Xkey-La3
X-Ee-Generated-By
Time-Cloud-Cache
X-Ee-Origin
X-Cache-Ttl
X-Via-PopV
X-V
X-Via-PopN
X-Ha-Backend
X-Oracle-DMS-ECID
X-IAuth-Set-Uid
X-Ua
X-Via-PopH
Log-Origin
RewriteTestHook
RewriteTeamHook
X-Ion-Healthy
Geoip-Latitude
X-CDN-Cache-Status
X-Jungle-Id
Cache-Contol
X-Ion-Hop
X-VTEX-Cache-Backend-Header-Time
X-Akamai-Pragma-Client-IP
X-Github-Request-Id
X-VTEX-Cache-Backend-Connect-Time
CDN
X-Esi
My-App
X-ServedByHost
X-Limited
Cmsid
X-Rollout
Cmstype
X-VCL-Version
Cloudfront-Viewer-Country
X-App
X-New
X-Eligible
Cf-Ipcountry
X-Up
WWW-Authenticate
X-From
X-Region-Sid
Lb
X-Traceid
WebServer
X-Forwarded-Site
X-Requestid
Machine
X-Correlation-ID
CountryCode
Cneonction
X-Dw-Trace-Id
X-MSEdge-Flight
X-MSEdge-Features
CacheControlHeader
Pragrma
X-Lb-Nocache
X-LAGOON
Server-Info
Warning
X-Cdn-Request-ID
X-Check-Cacheable
X-Acquia-Site
X-Acquia-Application-Trace
X-EC-Lua
Reporter
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-HS-Status
X-Ftr-Request-Id
FSS-Cache
X-Serial
Thinkindot-Cache-Type
X-Td-Header-From-No-Data
X-Web-Server
Edge-Cache
X-Pod
X-Akamai-Transformed
X-Git-Commit
X-Sucuri-Id
X-Container-Uri
Permission-Policy
Ngx
X-Elasticpress-Query
X-BBC-Origin-Response-Status
X-Platform-Processor
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Timeexpire
X-Ms-Blob-Type
X-SRCache-Key
X-Ms-Lease-Status
X-Varnish-Hostname
X-Ramcache
X-Platform-Cluster
X-Orig-Cache-Control
X-Tncms-Bot-Tier
X-Platform-Router
X-Fastly-Cache-Hits
CF-Cached-On