Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
Accept-CH
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Permissions-Policy
X-Request-ID
X-Ua-Compatible
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-CDN
X-Check
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
Cf-Apo-Via
X-Turbo-Charged-By
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
X-UA-Device
EagleId
X-Server
X-Dispatcher
X-Vhost
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Dns-Prefetch-Control
Accept-CH-Lifetime
X-Varnish-Cache
X-Litespeed-Cache
Grace
X-Server-Powered-By
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Allow
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Cache-Lookup
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
Xkey
X-Akam-SW-Version
EagleEye-TraceId
X-Host
Surrogate-Control
X-Response-Time
Cf-Railgun
X-Readtime
X-Node
X-HW
X-Ruxit-JS-Agent
X-Server-Id
Request-Id
X-LiteSpeed-Cache
X-Country
X-Nginx-Cache-Status
X-Url
X-Content-Type
Cache-Tag
Content-Location
X-Nginx-Upstream-Cache-Status
X-Application-Context
X-NWS-LOG-UUID
X-Clacks-Overhead
Service-Worker-Allowed
Fastly-Restarts
X-Trace
Cross-Origin-Opener-Policy
X-Amz-Server-Side-Encryption
X-Country-Code
X-Rack-Cache
X-Times
X-PC
X-TtlSet
X-Vname
X-Mcache
X-Midtier
X-Edge
Rating
Surrogate-Key
Pagespeed
Display
X-Middleton-Display
X-Sol
X-Cache-TTL
X-Browser-Type
X-Server-Name
X-Cnection
X-Element-Page-Cache
X-Abt-Application-Version
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-ESI
X-Oneagent-Js-Injection
Nginx-Cache
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Ser
Edge-Control
X-ECACHE
Verso
X-Ac
X-D2id
X-Vcap-Request-Id
X-MS-InvokeApp
X-Client-IP
X-Dw-Request-Base-Id
X-ARC
X-B3-TraceId
Response
X-Middleton-Response
X-Amz-Rid
X-ORACLE-DMS-RID
X-CST
X-Goog-Hash
X-Powered-CMS
X-Navigation-Version
X-Upstream
X-Edge-Location-Klb
X-Kinsta-Cache
X-Server-ID
X-Wormhole-Sdk
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
Accept-Ch-Lifetime
X-Forwarded-For
X-Daa-Tunnel
X-Ratelimit-Limit
X-Amzn-Trace-Id
X-NF-Request-ID
X-Cache-Key
RTSS
X-FastCGI-Cache
SPRequestDuration
SPIisLatency
X-Ratelimit-Remaining
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-Mod-Pagespeed
Edge-Cache-Tag
Cache-Status
Public-Key-Pins
X-Version
X-Ruxit-Js-Agent
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Mg-S
X-Ttl
X-Content-Digest
SPRequestGuid
X-SharePointHealthScore
S
Cross-Origin-Resource-Policy
Realpath
X-Fastly-Request-ID
AR-CACHE
X-Shield-Request-Id
X-T
X-Varnish-TTL
X-MSEdge-Ref
Fastcgi-Cache
X-Cached
X-Ua-Device
X-Recruiting
X-Accel-Expires
Front-End-Https
X-Distributor
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
TP-Cache
X-TTL
Access-Control-Request-Method
X-Azure-Ref
X-Newrelic-App-Data
X-Request-Received
X-Request-Processing-Time
Arr-Disable-Session-Affinity
Count-Hit
X-Ua-Browser
X-Id
X-Debug
Origin-Trial
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
MicrosoftSharePointTeamServices
X-LLID
X-Content-Security-Policy-Report-Only
X-Correlation-Id
Cache-Tags
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Cluster-Name
X-Frontend
X-VARITI-CCR
X-PressLabs-Stats
X-HS-Combine-CSS
X-Ismobilevalue
Accept-Ch
X-GUploader-UploadID
X-Varnish-Backend
X-Amz-Replication-Status
Payment
X-Hits
X-Protected-By
X-Goog-Metageneration
X-NGENIX-Cache
X-Request-Handler-Origin-Region
X-LB-Cache
X-Microsite
X-Unique-Id
X-Forwarded-Proto
Cleartype
X-Varnish-Server
X-FB-Debug
X-Activity-Id
Host
X-AppVersion
X-Az
X-Git-Hash
X-Logged-In
X-Www-Served-By
X-Ratelimit-Reset
Content-Disposition
X-Tt-Trace-Host
X-Tt-Trace-Tag
Filterid
X-Xrds-Location
X-Hostname
X-Page-Id
Akamai-GRN
X-App-Server
X-DIS-Request-ID
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Jurisdiction
X-HP-Webp
X-Cambria-Cache-Control
X-HP-Trace-Id
X-Template
X-Nf-Request-Id
X-FTR-Request-ID
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Geo-Country
X-Aspnet-Version
X-Fastcgi-Cache
Access-Control-Allow-Method
Frame-Options
X-ASPNET-VERSION
X-Origin-Server
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Load-Cache
X-Upgrade-Enabled
Retry-After
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
MS-Author-Via
X-Type
Viewport
X-Ah-Environment
Version
Fastly-SWR
X-Content-Options
Fastly-SIE
Section-Io-Cache
Accept-Charset
X-TT
X-Fb-Rlafr
X-Cache-Control
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Rid
X-TEC-API-ORIGIN
Content-MD5
X-B
X-B3-Sampled
Amp-Access-Control-Allow-Source-Origin
X-Grace
X-Varnish-Ttl
X-Envoy-Decorator-Operation
X-SRCache-Store-Status
X-Source
X-SRCache-Fetch-Status
X-Request-Guid
X-Vcl-Version
Trailer
X-Cdn
X-Trace-Id
X-Device-Type
X-Revision
X-Language
Server-Name
Healthy
X-Magnolia-Registration
X-Buckets
X-Origin-Cache
X-Webkit-CSP
X-Aspnetmvc-Version
X-RateLimit-Remaining
X-Cache-Age
X-Mobile
X-Px
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-CSRF-Token
X-WP-CF-Super-Cache-Active
X-Backend-Name
X-Amz-Meta-S3cmd-Attrs
X-Contextid
TCN
X-TraceId
X-Akamai-Edgescape
X-HS-Prerendered
X-Status
X-App-Environment
X-ProcessESI
X-Tumblr-Pixel-0
X-Tumblr-User
X-Rule
X-Environment-Context
X-L-Path
X-Instance
X-Debug-Info
X-RM-Cache-TTL
X-Proxy
X-Tumblr-Pixel-1
X-NYM-Debug-Backend
X-RemovedCookies
X-Tumblr-Pixel
Cross-Origin-Window-Policy
X-UUID
X-Varnish-Grace
X-HTML-Minification-Powered-By
X-FW-Static
X-Node-Name
X-Mg-Request-UUID
X-Webkit-Csp
X-Framework
NGB
Access-Control-Request-Headers
X-Storage
GEO-INFO
X-ServerID
X-Edge-Location
SD-X-WS
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-FW-Version
X-EdgeConnect-Cache-Status
X-FW-Type
X-Cacheable-TTL
MS-CV
X-Adobe-Loc
X-Cache-Time
Ms-Operation-Id
X-Adobe-Content
X-Debug-IsConnected
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Region
X-Proxy-Cache-Info
X-Is-Bot
X-Datadog-Sampled
X-Debug-IsPreview
X-RTag
X-Datadog-Parent-Id
X-Rendered-As
X-Content-Powered-By
X-G
X-Yottaa-Optimizations
X-Yottaa-Metrics
Charset
DC
Upgrade-Insecure-Requests
Protected
X-Seen-By
Countrycode
Paypal-Debug-Id
X-Whom
X-User-Agent
Cross-Origin-Embedder-Policy-Report-Only
Refresh
OT-Force-Account-Verify
X-Original-Request-Id
X-Lambda-Id
X-Response-Served-From
Webserver
Front
Section-Io-Id
X-WebKit-CSP-Report-Only
X-TT-LOGID
X-Reqid
X-VHOST
X-ECache
Alternate-Protocol
X-Amzn-Remapped-Content-Length
SRV
X-VC
X-IPS-LoggedIn
X-B3-Traceid
X-Server-W
X-Cache-Status-Check
X-AB
X-Akamai-Request-ID2
X-N
X-WP-CF-Super-Cache-Cookies-Bypass
Backend
Country
Priority
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Liferay-Portal
X-Time
X-B3-SpanId
X-CCDN-CacheTTL
X-Nginx-Cache
X-Real-IP
X-XRDS-Location
X-Mode
Onion-Location
Property-Id
X-UPSTREAM-Address
Webcakes-Region
X-Tumblr-Pixel-2
X-Rocket-Nginx-Serving-Static
TWC-Device-Class
X-Cache-Host
TWC-Privacy
X-Format
Filters
Fastcgi-Useragent
X-SaId
ServerID
TWC-Locale-Group
X-JoinUs
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Environment
Webcakes-App-Version
X-Hl-Ver
Webcakes-App-Name
X-FB-TRIP-ID
X-Rn-Rsrv
TWC-Connection-Speed
Meta-Geo
X-Rewrite-Enabled
X-Origin-Hint
DB-Nickname
Mn-Server-Ip
Xet-Cookie
X-Accel-Version
Web-Mar-Node
X-Tb
Expiry
X-Request-URI
X-Skip-Cache
X-Origin-Date
X-IPLB-Request-ID
X-IPLB-Instance
X-Restarts
X-Scope-Id
X-SayCDN-TTL
X-Redis-Cache
X-R9-Blue-Green-Version
X-Say-Cacheable
X-Say-TTL
X-Hosted-By
X-Varnish-Age
X-Cache-Action
X-Cache-Expired-At
X-Connection-Hash
X-VC-Cache
X-Frame-Option
Atl-Traceid
Apigw-Requestid
X-Web-Node
X-Webstats-RespID
X-Fastly-Request-Id
X-Tncms
X-Varnish-Cache-Hits
X-Soup
X-Vcache
X-Varnish-Beresp-Grace
From-Origin
X-ProxyCache-Key
X-Forwarded-Host
X-Handled-By
X-ProxyCache-Status
X-Fetched-On
X-Director
X-BYPASS-REASON
X-Cluster-Node
X-Cms-Context
X-Labrador-Cache-Channel
Uber-Trace-Id
X-Logging-Id
X-Loop
X-PHP-Host
X-Proxy-Build
Selected-Fe
X-Auth-Group-Type
X-Adobe-Source
X-Servername
X-Timing-Wait
Url
X-Httpd
X-Served-From
ServedBy
Cross-Origin-Embedder-Policy
Accept-Language
X-Origin-TTL
X-Origin-CC
X-Origin
X-Detected-As
X-Extlb
X-S
X-Zipkin-Id
X-Cluster
X-Proxied
X-Cloudmap
X-Routing-Service
X-Hit
X-DataDome
Referer-Policy
N-Cache
X-Generated-By
X-DynaTrace
X-SRV
X-Tumblr-Pixel-3
X-Wix-Request-Id
WPO-Cache-Status
X-Lagoon
X-Ms-Version
WPO-Cache-Message
X-Ms-Request-Id
X-LSADC-Cache
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Xserver
X-Azure-Ref-OriginShield
Surrogated-Key
X-Xfnlog-Site
Cross-Origin-Opener-Policy-Report-Only
X-RateLimit-Remaining-Second
X-Worker
X-RateLimit-Limit-Second
Source
X-CLOUD-TRACE-CONTEXT
X-NWS-UUID-VERIFY
X-App-Version
X-Generation-Time
X-Sucuri-Cache
LB
X-Cache-Debug
X-RCS-CacheZone
CF-IPCountry
Ohc-File-Size
X-Via-JSL
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-VCT
Node
X-F-Cache
X-Cdn-Origin
CDN-RequestId
X-Proxy-Cache-Status
X-HS-CF-Cache-Status
X-Is-Desktop
X-Browser-Name
X-Geo-Region
X-Tcp-Rtt
X-Is-Mobile
X-Is-Tablet
X-MP-GENERATED-AT
X-Is-Supported-Browser
Locale
X-No-Session
X-NODE
X-Urbn-Site-Id
X-Cache-Hit
X-Urbn-Context-Path
X-UA
X-B-Cache
X-Signature
X-Upstream-Ht
X-Varnish-Beresp-Ttl
X-Upstream-Ct
X-Tx-Id
X-Sucuri-ID
X-ElasticPress-Query
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Expires
X-TA-CDN-Provider
X-Litespeed-Tag
X-Country-Code-Real
X-FTR-Backend
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Cache-Rule
X-ShopId
X-ShardId
X-Cache-Operation
Cache
X-Alternate-Cache-Key
X-TIM-N
Apple-News-Services-Parsed-Url
X-VarnishDD-TTL
X-Op-Id-All
X-ORCA-Accelerator
Apple-News-Services-Request-Url
X-ScT
X-Section
Apple-News-Services-Host
Apple-News-Services-Handled
MD5-Digest
X-Vtex-Remote-Cache
Xc-Version
Lang
L5d-Success-Class
Host-ID
X-Vdms-Version
X-Rojux
Ha-Gx-Prefs
X-Path
Fastly-Backend-Name
X-Origin-Time
Expect-Staple
Cluster
DCR-Decision-By
DCR-Processing-Time-Ms
X-PAYTM-SRV-ID
X-Platform-Server
X-Proto
X-Org
Fl-Custom-Application
Content-Secure-Policy
X-Proxied-Request
BehaviorPad-Version
Fastly-GeoIP-CountryCode
Candidate-Md5Url
Cache-Provider
HA-Ipaddr
Rendered-Blocks
X-Bc-Bl
X-GeoCode
X-BCube-Filmed-By
X-Bug-Bounty
X-Cache-Info
X-Backend-Instance
X-App-Name
X-GeoCountry
X-Access
X-Aed
X-Aicache-OS
X-Cache-NE
X-CGP
X-Eu-Site
X-Debug-Cache-Store
X-Ec-GeoHdr
X-Developer
X-DPWN-IS-SECURE
X-Debug-Cache-Fetch
X-FC-Vary-Parameters
X-Gdpr
X-Conf
X-Csrf-Jwt
X-D
X-HN
X-AB-Test
Sslversion
X-Ec-Fail
User-Agent
X-Nyt-Route
Wxu-Next-Hostname
Redirect-Candidate
Producers
Ngx.Var.Host
Odigeo-Trace-Id
Origin
PFcat
X-Mvc-Supplant-Cachable
X-Mly-Id
X-A-Dcw
X-Ig-Origin-Region
X-A-Dgt
X-A-Wwc
X-Ig-Push-State
X-A-Dam
Wxu-Next-Region
X-A
X-Jobs
X-A-Ccd
Meta-Geo-Continent
Wxu-Next-Commit
AMP-Access-Control-Allow-Source-Origin
X-INCAP-ABP
X-Locale
Mime-Version
X-Varnish-Director
X-Varnish-Remaining-TTL
Mail-Subject
X-Varnish-CookieINHashed-On
X-GoCache-CacheStatus
X-Gzip
X-GeoIP-Region-Code
X-Varnishpool
Platform
X-Slack-Shared-Secret-Outcome
X-Accel-Expires-Debug
Origin-Agent-Cluster
X-Edge-Server
X-Amz-Meta-Cb-Modifiedtime
X-Scheme
Gh-Request-Id
Gannett-Cam-Experience-Id
X-Irp-Debug
X-Auto-Login
V-Age
X-SD-PageType
X-Amz-Storage-Class
L
X-Akamai-Device-Characteristics
IsBot
X-HS-Content-Campaign-Id
X-Varnish-CookieHashed-On
X-AK-Request-ID
X-Date
Thinkindot-CacheControl-Type
X-Viewer-Country
Thinkindot-CacheControl
TDXMobile
X-VTEX-Cache-Server
X-Vmg-Version
X-Fmm-Version
Web-Mar-Region
X-Epic-Correlation-Id
X-Esi-Check
X-Via-Fastly
W
X-Fastly-Backend
We-Hiring
X-Shield-Cache-Expires
X-Gamma-Serve
X-SIPLIST1
Req-Svc-Chain
X-Slack-Backend
X-Wikidot-Backend
X-Level-Front-Cache
X-GeoIP-Country-Code
X-We-Are-Hiring
RNT-Machine
X-VTEX-Cache-Time
X-VG-WebCache
X-Generated-On
Server-Host
RNT-Time
X-GeoIP-City
X-Wikidot-Static-Cache
Fastly-SSL
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-V-Cache
X-DefElseHash
X-Cdn-Srv
Azure-SlotName
Azure-Version
X-Request-Time
Canary
X-B3-Trace-ID
X-CacheTTL
X-Mvc-Supplant-OutputCached
X-Req
X-Clientip
X-Origin-Response-Time
X-Origin-Expires
X-Powered-By-VTEX-Cache
X-Platform
X-Policy
X-Service
X-Core-Value
X-NodeID
X-Contensis-Viewer-Groups
X-Thinkindot-L3
X-Content-Age
X-Content-Length
X-Node-Id
X-Micro-Cache
X-Cached-By
Cdncip
X-Depends
X-Cache-Aspx
Content-Script-Type
X-BBC-Edge-Cache-Status
Cdnsip
X-Dispatcher-Server
X-Location
X-Bl-Debug
Content-Style-Type
X-Cache-Grace
X-Loc
X-SB
X-Var-Ttl
Debug
CDCHOST
X-DefHash
Cdn-Request-Time
X-Cache-Id
Cdn-Host
X-Varnish-Authentication
X-Pad
X-Site-Version
Akamai-Mon-Iucid-Del
X-Ec-Custom-Error
X-SVT-ORM-RULES
X-CUA
X-Tb-Optimization-Total-Bytes-Saved
X-Pool
X-Cache-FS-Status
X-Acquia-Purge-Cdn-Unconfigured
X-HITS
X-Sn-Servicetimems
X-UA-Device-Type
X-Block-Status
X-Bip
X-Thanos
X-SVT-ORM-VERSION
X-VG-TLSProxy
X-Varnish-Beresp-Status
Product
Country-Code
DSUID
X-Men
Click-Count-Error
Click-Count-Action-Start
User-Cache-Control
X-Internal-TTL
X-Geolocation
X-Hash
X-Hnp-Log
X-Human
CDN-Uid
CDN-RequestPullSuccess
X-Request-Start
X-Request-Host
X-NMSegId
X-Pubstack
CDN-Cache
CDN-CachedAt
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
X-VServer
Esi-Enabled
Req-ID
ServerName
Release
Pramga
XM
X-Gen-Mode
X-Server-IP
Tube-Return
Tube-Got-Results
Tube-Got-Eval
Tube-Get-Contents
Yak-Timeinfo
X-GeoIP
Origin-EX
Origin-CC
NM-Fastcgi-Cache
NGX
X-URL
X-CDN-Forward
X-Via-SSL
X-Via-Edge
X-S-Cookie
A
XkeyRZ
X-Via-CDN
Edge-Copy-Time
X-Proxy-CacheRZ
X-Varnish-Hits
X-NGINX-Cache
X-RID
X-Cache-Bucket
X-External-Request-Id
X-Newrelic-Synthetics
X-IsAdmin
X-Cache-Date
X-LB-NoCache
X-HOST
Ssr
X-Application
Cache-Key
X-RateLimit-Limit
X-B-Cookie
X-Destination
X-Cdn-Forward
X-Resp-Is-Stale
X-CACHE-GROUP
X-GEO
X-ZONE
X-Api-Version
Sid
X-User
X-Refresh
X-Zen-Fury
X-Oracle-Dms-Ecid
X-Optimistic-Header
X-Nananana
CloudFront-Viewer-Country
X-Servedbyhost
X-APP
TP-L2-Cache
X-Cs
Cdn-Requestid
X-Dc
X-VC-TTL
Fastly-Drupal-HTML
X-DC
X-RequestId
GeoIP-Latitude
X-Air-Pt
Ohc-Cache-HIT
X-Via-Popv
Proxy-Firewall
X-Via-Popn
X-Via-Poph
X-B3-Spanid
X-HA-Backend
C-Via
X-Tt-Logid
Server-ID
X-TH-Server
X-Vgn-Hpd-Reason
X-LB-ID
X-Wa
Fastly-Drupal-Html
X-Endurance-Cache-Level
X-Nc
True-Client-Country-4JS
X-CACHE-AGE
X-LiteSpeed-Cache-Control
X-AIR-PT
X-Test
X-B3-Parentspanid
Sever-Int
X-CS
Server-Hostname
Server-Ext
X-Webkit-Csp-Report-Only
Cdn
X-SERVER-NAME
X-XRDS-LOCATION
X-Presslabs-Stats
X-LiteSpeed-Tag
X-Moov-T
Adler-Geo
X-Moov-Xdn-Caching-Status
X-LJ-Flow-ID
X-Old-Content-Length
X-DynaTrace-JS-Agent
X-Moov-Xdn-Version
WP-Super-Cache
X-COUNTRY
Is-Eu
HostName
X-AWS-Id
X-VWS-Id
SID
X-Dispatcher-Number
X-Provided-By
X-Datadome
GeoIp-Country-Code
X-Nginx-Cache-Key
X-Zone
X-Srv
X-Parent-Response-Time
X-HubSpot-Correlation-Id
X-Fpc
X-DataCenter
WZWS-RAY
X-API-Version
X-Action
X-Geo-Header
X-Oracle-Dms-Rid
X-NewRelic-App-Data
X-Custom-Header
T-Server
S-Rt
X-Litespeed-Cache-Control
X-Pass-Why
Uri
Location
X-Vercel-Id
X-Vercel-Cache
X-Thinkindot-L1
X-Cache-VC
X-ND-Cache
Cache-Tv-Group
N1-Cache
X-Cache-Server
X-CMSURLCustom
SEZNAM-JOBS-OFFER
True-Client-IP
Vc-Max-Age
True-Client-Ip
Pics-Label
Resin-Trace
X-Stale
X-TX-ID
TWC-GeoIP-Region
X-PERF
X-ApacheServer
Cache-Hits
X-Ua
TWC-GeoIP-City
TWC-GeoIP-DMA
Tcn
X-Datacenter
Serverhost
Powered-By
X-Varnish-Beresp-TTL
X-Client-Ip
X-Dynatrace-Js-Agent
X-WA-Info
GeoIP-Country-Code
X-FPC
X-Render-Time
Vix-Hermes-Req-Id
Sm-Log-Id
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Service-Response-Time
X-Cache-TTL-Remaining
X-Uri
X-Nitro-Cache
Srv
X-Ckpd-Fst-Backend
Hostname
Lb
X-APP-VERSION
X-Fastly-Cache
X-Ssense-Gql
X-Vc
X-Ssense-Shipping-Surcharge-Enabled
Cache-Contol
X-Fastly-Cache-Status
X-Debug-Service
Av-Poweredby
X-Ion-Healthy
X-Cdn-Cache-Status
Log-Origin
X-Ion-Hop
X-Jungle-Id
Thinkindot-Control
RewriteTeamHook
RewriteTestHook
On-Server
X-Air-Source
X-WA
X-Air-Trace-Id
X-Air-Hostname
X-NC
My-App
Cmstype
Cmsid
ServerHost
X-Udemy-Cache-App-Namespace
Server-Id
X-Ee-Origin
X-Up
Time-Cloud-Cache
X-Ee-Request-Date
X-Vary-Devices
Cf-Ipcountry
AKAMAI
Store-Cloud-Cache
X-Lb-Id
X-Ee-Request-Id
X-Amz-Meta-Opti
X-Ee-Generated-By
X-Cms-Device
X-Save-Cache
X-PHP-Backend
X-From
Geoip-Latitude
X-Cache-Ttl
X-Correlation-ID
X-Fastly-Backend-Reqs
X-Via-PopH
CacheControlHeader
X-Via-PopN
X-Ha-Backend
X-Via-PopV
WebServer
X-Github-Request-Id
X-Oracle-DMS-ECID
Xkey-La3
Xkeylog
X-Proxy-Cache-La3
X-Esi
X-Akamai-Pragma-Client-IP
X-Info
X-VTEX-Cache-Backend-Connect-Time
X-VTEX-Cache-Backend-Header-Time
X-VCL-Version
Magicmarker
Cl-Cache
X-App
X-Sucuri-Id
X-Traceid
X-Requestid
Cloudfront-Viewer-Country
X-Geo
WWW-Authenticate
X-ServedByHost
X-Limited
X-IAuth-Set-Uid
CountryCode
X-MSEdge-Features
X-MSEdge-Flight
X-HS-Status
Warning
X-CDN-Cache-Status
X-Dw-Trace-Id
X-LAGOON
NtCoent-Length
CDN
Reporter
X-Lb-Nocache
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
FSS-Cache
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-New
X-Rollout
X-Eligible
X-Check-Cacheable
X-Acquia-Site
X-Akamai-Transformed
X-Pod
Origin-Site
X-Serial
X-V
X-Web-Server
X-Varnish-Hostname
Thinkindot-Cache-Type
X-BBC-Origin-Response-Status
X-Td-Header-From-No-Data
X-Lsadc-Cache
Epwk-X-Cache
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-Ramcache
Machine
CF-Cached-On
X-Region-Sid
X-Forwarded-Site
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Akamai-ERRuleID
X-Orig-Cache-Control
X-Akamai-ERPolicy
Timeexpire
X-Tncms-Bot-Tier
Cneonction
X-Elasticpress-Query