Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
X-XSS-Protection
Alt-Svc
Report-To
NEL
X-Xss-Protection
Referrer-Policy
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
P3p
X-FRAME-OPTIONS
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-Drupal-Dynamic-Cache
X-Request-ID
X-Ua-Compatible
Feature-Policy
Accept-CH-Lifetime
X-Content-Security-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Age
X-Cache-Group
X-Vhost
X-Proxy-Cache
X-Turbo-Charged-By
EagleId
Keep-Alive
X-Rq
X-Dispatcher
X-Via
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
Xkey
X-Varnish-Cache
X-WebKit-CSP
X-Litespeed-Cache
Grace
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Check
X-Dns-Prefetch-Control
X-Device
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-Node
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Country
X-LiteSpeed-Cache
X-Server-Id
X-Country-Code
Content-Location
X-Nginx-Cache-Status
Cache-Tag
X-Content-Type
X-Nginx-Upstream-Cache-Status
X-Url
Service-Worker-Allowed
Fastly-Restarts
X-Clacks-Overhead
X-Trace
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Application-Context
X-Times
X-Amz-Server-Side-Encryption
X-NWS-LOG-UUID
Surrogate-Key
X-Vname
X-TtlSet
X-PC
Rating
X-Edge
X-Mcache
X-Midtier
X-Server-Name
X-Cache-TTL
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Cnection
X-Powered-By-Plesk
X-Element-Page-Cache
X-Abt-Application-Version
X-Browser-Type
X-Kinja-Server
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-ESI
X-Server-ID
X-GitHub-Request-Id
Nginx-Cache
X-Vcap-Request-Id
X-ECACHE
X-Ac
Edge-Control
X-D2id
Verso
X-MS-InvokeApp
X-Ser
X-Oneagent-Js-Injection
X-Client-IP
X-Amz-Rid
X-ORACLE-DMS-RID
X-Ratelimit-Limit
X-Wormhole-Sdk
X-Middleton-Response
Response
X-Ratelimit-Remaining
X-FTR-Request-ID
X-Goog-Hash
X-ARC
X-CST
X-Powered-CMS
X-Navigation-Version
X-B3-TraceId
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-Kinsta-Cache
X-Edge-Location-Klb
X-Kraken-Loop-Name
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Upstream
X-Forwarded-For
Origin-Trial
X-Amzn-Trace-Id
SPIisLatency
X-FastCGI-Cache
SPRequestDuration
X-Mod-Pagespeed
X-Cache-Key
X-Content-Digest
Edge-Cache-Tag
RTSS
Cache-Status
Public-Key-Pins
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-Ezoic-Cdn
X-Version
X-SharePointHealthScore
SPRequestGuid
X-Daa-Tunnel
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-NF-Request-ID
X-Fastly-Request-ID
Realpath
X-Mg-S
X-ORACLE-DMS-ECID
X-Recruiting
X-MSEdge-Ref
X-T
S
X-Ttl
Front-End-Https
X-Shield-Request-Id
Fastcgi-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Distributor
X-Accel-Expires
X-TTL
Cross-Origin-Resource-Policy
X-Cached
AR-CACHE
X-Xrds-Location
X-Azure-Ref
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Nf-Request-Id
X-Varnish-TTL
X-Correlation-Id
X-Request-Received
Akamai-GRN
X-Request-Processing-Time
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Id
TP-Cache
X-Ua-Browser
X-Debug
X-Cdn
Cache-Tags
Count-Hit
X-Ismobilevalue
X-Cluster-Name
X-NGENIX-Cache
X-TraceId
X-Newrelic-App-Data
X-LLID
X-PressLabs-Stats
Server-Node
MicrosoftSharePointTeamServices
X-GUploader-UploadID
X-Aspnetmvc-Version
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
X-Frontend
X-Protected-By
Accept-Ch
X-HS-Combine-CSS
X-VARITI-CCR
X-Amz-Replication-Status
X-Hits
X-Goog-Metageneration
X-Request-Handler-Origin-Region
X-LB-Cache
X-Microsite
X-Page-Id
Payment
X-Ratelimit-Reset
X-FB-Debug
X-Unique-Id
Cleartype
X-DIS-Request-ID
X-Logged-In
X-Varnish-Server
X-Git-Hash
X-AppVersion
X-Hostname
X-Tt-Trace-Tag
X-Az
Content-Disposition
X-Activity-Id
X-Www-Served-By
X-Tt-Trace-Host
X-HP-Trace-Id
X-HP-Webp
X-Cambria-Cache-Control
X-Jurisdiction
X-Template
Host
X-Amz-Apigw-Id
X-Amzn-RequestId
Filterid
Amp-Access-Control-Allow-Source-Origin
X-Forwarded-Proto
X-App-Server
X-Fastcgi-Cache
X-Geo-Country
Version
X-Varnish-Ttl
X-Aspnet-Version
Accept-Charset
X-Load-Cache
X-ASPNET-VERSION
X-Envoy-Decorator-Operation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
Trailer
X-Source
X-WP-CF-Super-Cache-Cache-Control
Frame-Options
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Type
X-WP-CF-Super-Cache
X-Ah-Environment
Fastly-SWR
Access-Control-Allow-Method
X-Upgrade-Enabled
Fastly-SIE
Viewport
Section-Io-Cache
X-TT
X-Content-Options
X-Fb-Rlafr
X-HS-Prerendered
X-B3-Sampled
X-B
Server-Name
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Cache-Age
X-Language
X-Origin-Server
X-Grace
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend
X-Device-Type
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-Cache-Control
X-Buckets
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Rid
Retry-After
X-Px
MS-Author-Via
Content-MD5
X-Magnolia-Registration
X-Mobile
X-Request-Guid
X-Vcl-Version
TCN
X-EdgeConnect-Cache-Status
X-Trace-Id
X-Varnish-Grace
Protected
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Revision
X-Akamai-Edgescape
Healthy
X-WP-CF-Super-Cache-Active
X-Backend-Name
Cross-Origin-Embedder-Policy-Report-Only
Upgrade-Insecure-Requests
Charset
X-Proxy
SD-X-WS
X-Response-Served-From
X-Debug-Info
X-Instance
X-Original-Request-Id
X-Is-Bot
X-Tumblr-Pixel-1
X-Status
X-Rendered-As
X-ProcessESI
X-Tumblr-User
X-Tumblr-Pixel-0
X-NYM-Debug-Backend
X-RM-Cache-TTL
X-RemovedCookies
X-Tumblr-Pixel
X-ServerID
X-Cache-Time
X-FW-Version
X-CSRF-Token
X-Mg-Request-UUID
X-FW-Type
X-FW-Static
X-Adobe-Content
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Node-Name
X-Adobe-Loc
Access-Control-Request-Headers
NGB
X-UUID
X-FW-Dynamic
X-App-Environment
X-Rule
X-Storage
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Yottaa-Metrics
X-Datadog-Trace-Id
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
Refresh
X-Content-Powered-By
Cross-Origin-Window-Policy
X-Edge-Location
X-Whom
X-Yottaa-Optimizations
X-Region
X-Datadog-Parent-Id
X-Cacheable-TTL
GEO-INFO
X-Proxy-Cache-Info
X-RTag
OT-Force-Account-Verify
MS-CV
Ms-Operation-Id
X-G
X-L-Path
X-Lambda-Id
X-Environment-Context
X-Resp-Is-Stale
Section-Io-Id
X-Contextid
X-B3-Traceid
X-Reqid
X-Amzn-Remapped-Content-Length
Webserver
X-TT-LOGID
DC
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Countrycode
X-Hcs-Proxy-Type
X-User-Agent
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
X-Server-W
X-HTML-Minification-Powered-By
X-ECache
X-Origin-Cache
X-VC
Alternate-Protocol
X-Real-IP
Front
Cross-Origin-Opener-Policy-Report-Only
X-Time
SRV
Priority
X-WebKit-CSP-Report-Only
X-B3-SpanId
X-HS-CF-Cache-Status
X-DataDome
X-Seen-By
WPO-Cache-Message
Ohc-File-Size
WPO-Cache-Status
X-WP-CF-Super-Cache-Cookies-Bypass
Accept-Ch-Lifetime
X-Rocket-Nginx-Serving-Static
Liferay-Portal
X-Hl-Ver
X-Mode
X-Origin-TTL
X-Nginx-Cache
X-Origin-CC
Backend
Xet-Cookie
X-IPS-LoggedIn
Onion-Location
X-SaId
Fastcgi-Useragent
X-Akamai-Request-ID2
X-Tumblr-Pixel-3
X-Rewrite-Enabled
X-Rn-Rsrv
X-Say-Cacheable
X-SayCDN-TTL
X-Tumblr-Pixel-2
ServerID
Web-Mar-Node
X-Redis-Cache
X-RateLimit-Remaining
Meta-Geo
X-Say-TTL
Filters
X-UPSTREAM-Address
X-Cache-Host
X-Format
X-JoinUs
Uber-Trace-Id
X-Tb
X-R9-Blue-Green-Version
TWC-Privacy
X-IPLB-Instance
Webcakes-App-Version
X-IPLB-Request-ID
Webcakes-App-Name
TWC-Locale-Group
X-Hosted-By
X-Handled-By
X-Scope-Id
X-Connection-Hash
X-Director
Property-Id
X-Tncms
TWC-Connection-Speed
X-DynaTrace
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
X-Labrador-Cache-Channel
Webcakes-Region
X-PHP-Host
X-Cache-Status-Check
X-Detected-As
X-VC-Cache
X-Vcache
X-Restarts
X-Cache-Action
Expiry
X-Origin-Hint
X-Varnish-Age
X-Origin-Date
X-Accel-Version
X-AB
X-Cms-Context
X-Loop
X-Cluster-Node
X-Skip-Cache
X-N
Apigw-Requestid
Atl-Traceid
Mn-Server-Ip
X-Cache-Expired-At
From-Origin
X-Soup
Url
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Web-Node
X-Webstats-RespID
X-ProxyCache-Status
X-ProxyCache-Key
X-Ms-Version
X-BYPASS-REASON
X-Frame-Option
X-Servername
X-Logging-Id
X-Adobe-Source
X-Ms-Request-Id
X-Forwarded-Host
Country
Environment
ServedBy
X-FB-TRIP-ID
X-Httpd
X-Cluster
X-Routing-Service
X-Cloudmap
X-S
X-Served-From
X-Proxy-Build
X-Proxied
X-Auth-Group-Type
X-Fetched-On
X-Timing-Wait
X-Origin
X-Extlb
Selected-Fe
DB-Nickname
X-Zipkin-Id
Surrogated-Key
X-Azure-Ref-OriginShield
X-Hit
X-RateLimit-Limit-Second
X-Worker
X-RateLimit-Remaining-Second
Cross-Origin-Embedder-Policy
X-LSADC-Cache
X-CDN-Forward
X-SRV
X-Cache-Hit
Accept-Language
LB
X-Request-URI
X-Sucuri-Cache
X-Lagoon
Referer-Policy
X-Generation-Time
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Fastly-Request-Id
X-Generated-By
N-Cache
X-Cdn-Origin
X-App-Version
X-Sucuri-ID
X-MP-GENERATED-AT
Xserver
X-Oracle-Dms-Ecid
CDN-RequestId
CF-IPCountry
X-URL
X-XRDS-Location
Ohc-Cache-HIT
X-Xfnlog-Site
X-Tx-Id
Node
X-TA-CDN-Provider
X-F-Cache
X-VC-TTL
X-AIR-PT
VIX-Pulpo-Node
Cache
VIX-Pulpo-Upstream-Status
X-Mly-Id
X-Via-Edge
X-Wix-Request-Id
X-Via-CDN
X-Via-SSL
Edge-Copy-Time
Source
X-Cache-Rule
X-NODE
X-Cache-Debug
X-UA
X-INCAP-ABP
X-Varnish-Beresp-Ttl
Cache-Provider
X-RCS-CacheZone
X-Pad
X-VCT
X-Site-Version
X-GEO
X-Locale
X-ElasticPress-Query
Rendered-Blocks
X-Ec-GeoHdr
X-AB-Test
X-Backend-Instance
X-Developer
X-DPWN-IS-SECURE
Expect-Staple
X-Ec-Fail
X-FC-Vary-Parameters
X-Eu-Site
Fastly-Backend-Name
X-Destination
X-External-Request-Id
Redirect-Candidate
Producers
Fastly-GeoIP-CountryCode
X-Vtex-Remote-Cache
Sslversion
Xc-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Cache-NE
X-Application
X-Cache-Grace
X-Bug-Bounty
X-BCube-Filmed-By
X-Bc-Bl
BehaviorPad-Version
X-Bl-Debug
X-Browser-Name
X-Cache-Operation
X-Cached-By
DCR-Decision-By
X-D
X-Debug-Cache-Fetch
X-Debug-Cache-Store
DCR-Processing-Time-Ms
Candidate-Md5Url
X-Aed
Cluster
X-CGP
X-Conf
X-Aicache-OS
X-Csrf-Jwt
X-Access
X-Gdpr
X-Slack-Shared-Secret-Outcome
X-Op-Id-All
X-Tcp-Rtt
X-Origin-Time
X-Path
X-Slack-Backend
X-PAYTM-SRV-ID
X-Nyt-Route
X-A
Fastly-SSL
HA-Ipaddr
Ha-Gx-Prefs
Origin
We-Hiring
X-A-Ccd
Host-ID
L5d-Success-Class
X-NWS-UUID-VERIFY
X-ScT
MD5-Digest
X-Proxied-Request
Ngx.Var.Host
Meta-Geo-Continent
X-S-Cookie
X-Rojux
X-Proto
X-SD-PageType
Odigeo-Trace-Id
X-Platform-Server
Web-Mar-Region
Lang
Mail-Subject
X-Section
X-A-Dam
X-Mvc-Supplant-Cachable
X-HS-Content-Campaign-Id
X-GeoIP-Region-Code
X-A-Dcw
X-Ig-Origin-Region
X-VarnishDD-TTL
X-GeoIP-Country-Code
X-Vdms-Version
X-Urbn-Site-Id
X-Urbn-Context-Path
Fl-Custom-Application
X-A-Wwc
X-HN
X-A-Dgt
X-Geolocation
X-GeoCountry
X-Geo-Region
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
PFcat
X-B-Cookie
X-Ig-Push-State
X-GeoCode
Locale
X-No-Session
Server-Host
TDXMobile
X-B-Cache
X-Auto-Login
Wxu-Next-Commit
RNT-Machine
Req-Svc-Chain
Wxu-Next-Region
X-Accel-Expires-Debug
Thinkindot-CacheControl-Type
User-Cache-Control
Wxu-Next-Hostname
X-AK-Request-ID
X-App-Name
Thinkindot-CacheControl
X-Amz-Storage-Class
V-Age
X-Akamai-Device-Characteristics
RNT-Time
X-Fmm-Version
X-SB
X-Request-Host
X-Scheme
X-Shield-Cache-Expires
X-Thinkindot-L3
X-Signature
X-Req
X-Powered-By-VTEX-Cache
X-Org
X-NodeID
X-Origin-Expires
X-Platform
X-Policy
X-User
X-Varnish-CookieHashed-On
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Zen-Fury
X-VServer
X-Viewer-Country
X-Varnish-Director
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VG-WebCache
X-Via-Fastly
X-Node-Id
X-Mvc-Supplant-OutputCached
X-Core-Value
X-Content-Length
X-CUA
X-Date
X-DefElseHash
X-Content-Age
X-Clientip
X-Block-Status
X-BBC-Edge-Cache-Status
X-Cache-Id
X-Cache-Info
X-CacheTTL
X-DefHash
X-Dispatcher-Server
X-Human
X-Hnp-Log
X-Jobs
X-Loc
X-Micro-Cache
X-Gzip
X-GoCache-CacheStatus
X-Epic-Correlation-Id
X-Ec-Custom-Error
X-Esi-Check
X-Fastly-Backend
X-Gen-Mode
X-B3-Trace-ID
X-Amz-Meta-Cb-Modifiedtime
Azure-InstanceId
Azure-RegionName
Gannett-Cam-Experience-Id
Gh-Request-Id
L
Origin-Agent-Cluster
Azure-SiteName
Platform
Azure-SlotName
Cdnsip
Product
Cdncip
CDCHOST
Azure-Version
X-Ua-Device
Akamai-Mon-Iucid-Del
X-Alternate-Cache-Key
X-ShardId
X-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Contensis-Viewer-Groups
X-Cache-Aspx
X-VG-TLSProxy
X-Depends
X-Cache-Date
Canary
X-Cdn-Srv
X-Varnish-Beresp-Status
X-We-Are-Hiring
X-Cache-FS-Status
X-UA-Device-Type
Req-ID
X-IsAdmin
X-Internal-TTL
X-Pubstack
X-Request-Start
X-Level-Front-Cache
X-HITS
X-Litespeed-Tag
X-NMSegId
X-Origin-Response-Time
X-Men
X-Location
X-Request-Time
X-Hash
X-Edge-Server
X-SVT-ORM-VERSION
X-TIM-N
Cdn-Host
X-V-Cache
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-GeoIP
X-GeoIP-City
X-Server-IP
X-Generated-On
X-Gamma-Serve
X-Varnish-Authentication
X-Vmg-Version
X-Acquia-Purge-Cdn-Unconfigured
Debug
X-TH-Server
Country-Code
Content-Style-Type
DSUID
ServerName
Origin-EX
NM-Fastcgi-Cache
W
Origin-CC
NGX
Content-Secure-Policy
Tube-Get-Contents
Release
Click-Count-Action-Start
Cdn-Request-Time
Tube-Return
Tube-Got-Eval
Yak-Timeinfo
Content-Script-Type
Click-Count-Error
Tube-Got-Results
XM
X-Via-JSL
X-Service
Mime-Version
CDN-Cache
CDN-RequestPullSuccess
X-RID
CDN-RequestPullCode
X-LB-NoCache
X-Vgn-Hpd-Reason
CDN-Uid
X-Irp-Debug
X-Tb-Optimization-Total-Bytes-Saved
X-NGINX-Cache
X-Pool
X-Thanos
User-Agent
X-SIPLIST1
CDN-CachedAt
CDN-RequestCountryCode
Ssr
IsBot
CDN-PullZone
X-Bip
CDN-EdgeStorageId
X-HOST
X-CACHE-GROUP
X-Var-Ttl
X-Old-Content-Length
X-Moov-Xdn-Version
X-Moov-T
X-Varnish-Hits
X-Moov-Xdn-Caching-Status
Fastly-Drupal-HTML
X-Varnishpool
Sid
Pramga
GeoIP-Latitude
N1-Cache
X-Api-Version
X-HubSpot-Correlation-Id
X-DC
X-Cs
X-Refresh
CloudFront-Viewer-Country
X-ORCA-Accelerator
X-RequestId
X-Proxy-Cache-Status
X-Servedbyhost
X-ZONE
X-Action
Esi-Enabled
X-APP
X-Nc
X-Wa
X-LiteSpeed-Tag
C-Via
X-Vercel-Id
X-Vercel-Cache
X-Thinkindot-L1
X-Cache-VC
Server-ID
Location
X-Upstream-Ht
X-Via-Popv
TWC-GeoIP-Region
TWC-GeoIP-DMA
Cache-Hits
TWC-GeoIP-City
X-HA-Backend
X-Upstream-Ct
X-Via-Poph
X-Via-Popn
X-LiteSpeed-Cache-Control
X-CACHE-AGE
X-LB-ID
X-Dc
Cdn-Requestid
X-Cache-Bucket
X-Webkit-CSP
X-Newrelic-Synthetics
AMP-Access-Control-Allow-Source-Origin
XkeyRZ
X-Parent-Response-Time
X-Proxy-CacheRZ
X-CS
X-NewRelic-App-Data
X-Nananana
X-B3-Parentspanid
A
Cache-Key
X-DynaTrace-JS-Agent
X-B3-Spanid
X-Tt-Logid
X-Presslabs-Stats
X-PERF
HostName
X-Zone
X-ApacheServer
X-COUNTRY
X-Webkit-Csp
X-WA-Info
X-Endurance-Cache-Level
SID
WP-Super-Cache
X-DataCenter
X-Ua
X-Render-Time
Fastly-Drupal-Html
X-Srv
X-Webkit-Csp-Report-Only
Proxy-Firewall
X-Fpc
X-Nitro-Cache
X-Uri
X-Litespeed-Cache-Control
X-Ion-Hop
Uri
RewriteTeamHook
GeoIp-Country-Code
X-Oracle-Dms-Rid
Cache-Contol
X-Jungle-Id
X-Ion-Healthy
RewriteTestHook
X-API-Version
X-Cdn-Forward
My-App
Cmstype
Log-Origin
TP-L2-Cache
Cmsid
True-Client-IP
True-Client-Country-4JS
Server-Ext
X-Up
X-Datadome
True-Client-Ip
Resin-Trace
Server-Hostname
Sever-Int
X-Optimistic-Header
X-Service-Response-Time
Sm-Log-Id
X-From
GeoIP-Country-Code
X-CLOUD-TRACE-CONTEXT
CacheControlHeader
X-Test
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
X-SERVER-NAME
Adler-Geo
X-Stale
X-Udemy-Cache-App-Namespace
SEZNAM-JOBS-OFFER
Cdn
Is-Eu
Tcn
X-Datacenter
X-Dispatcher-Number
X-Dynatrace-Js-Agent
X-Varnish-Beresp-TTL
X-Pass-Why
X-Client-Ip
WZWS-RAY
X-Nginx-Cache-Key
X-FPC
X-RateLimit-Limit
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Srv
X-APP-VERSION
Lb
X-Air-Pt
X-Air-Hostname
T-Server
Hostname
X-Geo-Header
X-Air-Trace-Id
X-Air-Source
X-Debug-Service
X-Fastly-Cache-Status
X-Custom-Header
X-VWS-Id
X-TX-ID
X-AWS-Id
X-LJ-Flow-ID
Server-Id
Origin-Site
X-Varnish-Hostname
X-SRCache-Key
X-ND-Cache
X-Provided-By
X-Vc
AKAMAI-GRN
X-App
Serverhost
Vc-Max-Age
X-Correlation-ID
Cf-Ipcountry
X-CMSURLCustom
X-Akamai-Pragma-Client-IP
X-Cache-Server
NtCoent-Length
X-Fastly-Backend-Reqs
X-VCL-Version
Edge-Cache
X-Lb-Id
X-Cache-Ttl
X-Html-Minification-Powered-By
Pics-Label
WebServer
X-Oracle-DMS-ECID
X-NC
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Ha-Backend
ServerHost
YJS-ID
X-WA
X-Esi
X-XRDS-LOCATION
Machine
X-Sigma-Backend
X-Rocket-Build-Number
Powered-By
X-Forwarded-Site
Epwk-X-Cache
Pragrma
X-Sigma
X-Cdn-Cache-Status
S-Rt
Geoip-Latitude
X-LAGOON
Av-Poweredby
X-Requestid
Vix-Hermes-Req-Id
X-Region-Sid
X-Traceid
Cloudfront-Viewer-Country
Cache-Tv-Group
Ms-Author-Via
X-Cache-TTL-Remaining
X-ServedByHost
Nord-Request-ID
WWW-Authenticate
CountryCode
X-Proxy-Cache-La3
X-Fastly-Cache
Warning
X-Sucuri-Id
X-MSEdge-Features
MIME-Version
X-HS-Status
Xkeylog
Xkey-La3
X-MSEdge-Flight
X-Ckpd-Fst-Backend
Thinkindot-Control
FSS-Cache
Reporter
X-Lb-Nocache
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
On-Server
X-Check-Cacheable
X-IAuth-Set-Uid
X-Serial
X-Td-Header-From-No-Data
X-Tncms-Bot-Tier
X-Web-Server
X-Dw-Trace-Id
DataCenter
Coldstone-Viewer-Country
Datacenter
Coldstone-Viewer-Currency
Coldstone-Viewer-Country-Region-Name
Cneonction
Timeexpire
X-Orig-Cache-Control
X-Mg-Cache
X-Elasticpress-Query
Thinkindot-Cache-Type
X-BBC-Origin-Response-Status
X-Cdn-Request-ID
X-VTEX-Cache-Backend-Connect-Time
X-VTEX-Cache-Backend-Header-Time
X-Lsadc-Cache