Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
X-XSS-Protection
Alt-Svc
Report-To
NEL
X-Xss-Protection
Referrer-Policy
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
P3p
X-Request-ID
X-FRAME-OPTIONS
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Feature-Policy
Accept-CH-Lifetime
X-Content-Security-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Age
X-Cache-Group
X-Vhost
X-Proxy-Cache
X-Turbo-Charged-By
EagleId
Keep-Alive
X-Rq
X-Via
X-Dispatcher
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
Xkey
X-Varnish-Cache
X-Litespeed-Cache
X-WebKit-CSP
Grace
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Check
X-Dns-Prefetch-Control
X-Device
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-Node
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Country
X-Server-Id
X-Country-Code
Content-Location
X-Nginx-Cache-Status
Cache-Tag
X-Content-Type
X-LiteSpeed-Cache
X-Nginx-Upstream-Cache-Status
X-Url
Service-Worker-Allowed
Fastly-Restarts
X-Clacks-Overhead
X-Trace
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Application-Context
X-Amz-Server-Side-Encryption
X-Times
Surrogate-Key
X-NWS-LOG-UUID
X-Vname
X-TtlSet
X-PC
Rating
X-Edge
X-Mcache
X-Midtier
X-Server-Name
X-Cache-TTL
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Cnection
X-Powered-By-Plesk
X-Element-Page-Cache
X-Abt-Application-Version
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Browser-Type
X-GitHub-Request-Id
X-ESI
X-Server-ID
Nginx-Cache
X-Vcap-Request-Id
X-ECACHE
X-D2id
X-Ac
Edge-Control
Verso
X-MS-InvokeApp
X-Ser
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-Client-IP
X-Amz-Rid
X-ORACLE-DMS-RID
Response
X-Middleton-Response
X-Wormhole-Sdk
X-Ratelimit-Remaining
X-Goog-Hash
X-FTR-Request-ID
X-ARC
X-CST
X-Powered-CMS
X-B3-TraceId
X-Navigation-Version
X-Ruxit-Js-Agent
X-Dw-Request-Base-Id
X-Kinsta-Cache
X-Edge-Location-Klb
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Upstream
X-Forwarded-For
Origin-Trial
X-Amzn-Trace-Id
SPIisLatency
X-FastCGI-Cache
SPRequestDuration
X-Mod-Pagespeed
X-Cache-Key
X-Content-Digest
Edge-Cache-Tag
RTSS
Cache-Status
Public-Key-Pins
AR-PoweredBy
AR-SID
AR-Request-ID
AR-ATIME
X-Ezoic-Cdn
X-NF-Request-ID
X-Version
X-SharePointHealthScore
SPRequestGuid
X-Daa-Tunnel
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Fastly-Request-ID
Realpath
X-Mg-S
X-ORACLE-DMS-ECID
X-Recruiting
X-MSEdge-Ref
Front-End-Https
S
X-T
X-Shield-Request-Id
X-Ttl
Fastcgi-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-Distributor
X-TTL
Cross-Origin-Resource-Policy
X-Cached
AR-CACHE
X-Xrds-Location
X-Azure-Ref
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Varnish-TTL
X-Request-Processing-Time
X-Request-Received
X-Correlation-Id
Akamai-GRN
X-HS-Content-Id
X-HS-Cache-Config
TP-Cache
X-HS-Hub-Id
X-Id
Cache-Tags
X-Ua-Browser
X-Debug
Count-Hit
X-Cluster-Name
X-Ismobilevalue
X-NGENIX-Cache
X-LLID
X-Newrelic-App-Data
X-Nf-Request-Id
X-PressLabs-Stats
Server-Node
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
X-TraceId
X-Frontend
X-Protected-By
Accept-Ch
X-HS-Combine-CSS
X-VARITI-CCR
X-Amz-Replication-Status
X-Hits
X-Goog-Metageneration
X-Microsite
X-LB-Cache
X-Request-Handler-Origin-Region
X-Ratelimit-Reset
X-Page-Id
Payment
X-DIS-Request-ID
Cleartype
X-FB-Debug
X-Unique-Id
X-Git-Hash
X-Az
X-Varnish-Server
X-Activity-Id
X-Logged-In
X-AppVersion
X-Tt-Trace-Tag
Content-Disposition
X-Hostname
X-Tt-Trace-Host
X-Www-Served-By
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Cambria-Cache-Control
X-Template
Host
X-Amzn-RequestId
X-Amz-Apigw-Id
Amp-Access-Control-Allow-Source-Origin
Filterid
X-Forwarded-Proto
X-Fastcgi-Cache
X-App-Server
X-Geo-Country
Version
X-Aspnet-Version
X-Varnish-Ttl
Accept-Charset
X-ASPNET-VERSION
X-Load-Cache
X-Envoy-Decorator-Operation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-B3-TraceId-Primal
Trailer
Frame-Options
MRF-Tech
X-Source
Mrf-Cache-Status
X-WP-CF-Super-Cache-Cache-Control
X-Type
X-WP-CF-Super-Cache
X-Ah-Environment
Fastly-SWR
Access-Control-Allow-Method
Section-Io-Cache
X-Upgrade-Enabled
Viewport
Fastly-SIE
X-TT
X-Content-Options
X-HS-Prerendered
X-Fb-Rlafr
Server-Name
X-Origin-Server
X-B3-Sampled
X-B
X-TEC-API-ROOT
X-Cache-Age
X-TEC-API-ORIGIN
X-Language
X-Grace
X-TEC-API-VERSION
X-Cache-Control
X-Device-Type
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Expires
X-Buckets
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Rid
Retry-After
X-Px
MS-Author-Via
X-Cdn
Content-MD5
X-Magnolia-Registration
X-Mobile
X-Request-Guid
X-Vcl-Version
TCN
X-EdgeConnect-Cache-Status
X-Trace-Id
X-Varnish-Grace
X-Revision
X-Tec-Api-Root
X-Tec-Api-Version
Protected
X-Tec-Api-Origin
X-Akamai-Edgescape
X-WP-CF-Super-Cache-Active
Healthy
X-Backend-Name
Cross-Origin-Embedder-Policy-Report-Only
Upgrade-Insecure-Requests
X-Proxy
Charset
X-Original-Request-Id
X-Debug-Info
SD-X-WS
X-Response-Served-From
X-Instance
X-Status
X-RemovedCookies
X-Tumblr-Pixel
X-ServerID
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-ProcessESI
X-RM-Cache-TTL
X-Rendered-As
X-NYM-Debug-Backend
X-Tumblr-User
X-Is-Bot
X-Rule
X-Framework
X-FW-Server
X-FW-Static
X-FW-Type
X-Node-Name
X-FW-Serve
X-Storage
X-Cache-Time
X-FW-Dynamic
X-FW-Hash
X-Cacheable-TTL
X-App-Environment
NGB
X-UUID
X-CSRF-Token
X-Mg-Request-UUID
X-Adobe-Content
X-FW-Version
X-Adobe-Loc
Access-Control-Request-Headers
Ms-Operation-Id
Refresh
Cross-Origin-Window-Policy
X-RTag
X-Region
X-Yottaa-Optimizations
MS-CV
X-Edge-Location
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Debug-IsConnected
X-Yottaa-Metrics
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Whom
X-Debug-IsPreview
X-Content-Powered-By
OT-Force-Account-Verify
X-G
X-Proxy-Cache-Info
GEO-INFO
X-Lambda-Id
X-L-Path
X-Environment-Context
X-Resp-Is-Stale
Section-Io-Id
X-Contextid
X-B3-Traceid
X-Reqid
X-Amzn-Remapped-Content-Length
X-TT-LOGID
Webserver
DC
X-CCDN-CacheTTL
Countrycode
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-User-Agent
X-Amz-Meta-S3cmd-Attrs
X-Server-W
Paypal-Debug-Id
X-HTML-Minification-Powered-By
X-Origin-Cache
X-ECache
X-VC
Alternate-Protocol
X-Real-IP
X-Time
Cross-Origin-Opener-Policy-Report-Only
Front
SRV
Priority
X-B3-SpanId
X-DataDome
X-HS-CF-Cache-Status
X-WebKit-CSP-Report-Only
X-Seen-By
WPO-Cache-Status
Ohc-File-Size
WPO-Cache-Message
Accept-Ch-Lifetime
X-WP-CF-Super-Cache-Cookies-Bypass
X-Hl-Ver
X-Rocket-Nginx-Serving-Static
Liferay-Portal
X-Nginx-Cache
X-Origin-CC
X-Mode
Xet-Cookie
X-Origin-TTL
Backend
Onion-Location
X-IPS-LoggedIn
X-JoinUs
Fastcgi-Useragent
ServerID
Web-Mar-Node
Meta-Geo
X-Cache-Host
Filters
X-Format
X-Rn-Rsrv
X-RateLimit-Remaining
X-Rewrite-Enabled
X-Tumblr-Pixel-3
X-Say-Cacheable
X-Say-TTL
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-SayCDN-TTL
X-Redis-Cache
X-SaId
X-Akamai-Request-ID2
X-Labrador-Cache-Channel
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-DynaTrace
X-Tb
Uber-Trace-Id
TWC-Privacy
X-Loop
X-VC-Cache
X-IPLB-Request-ID
X-Varnish-Age
X-Hosted-By
Property-Id
X-Connection-Hash
X-Handled-By
X-Detected-As
X-Cms-Context
X-N
Expiry
X-IPLB-Instance
X-Vcache
X-Cluster-Node
X-Tncms
X-Director
TWC-Locale-Group
X-Soup
X-Accel-Version
X-PHP-Host
X-Skip-Cache
Environment
X-AB
X-Restarts
X-Scope-Id
Webcakes-App-Version
Webcakes-Region
X-Cache-Action
X-Origin-Date
X-Cache-Status-Check
X-R9-Blue-Green-Version
X-Origin-Hint
Webcakes-App-Name
X-Varnish-Beresp-Grace
X-ProxyCache-Status
Mn-Server-Ip
From-Origin
X-Webstats-RespID
X-Forwarded-Host
X-Adobe-Source
X-Varnish-Cache-Hits
X-Web-Node
Atl-Traceid
X-Frame-Option
Country
X-BYPASS-REASON
X-Logging-Id
X-Ms-Request-Id
X-Ms-Version
Url
X-Cache-Expired-At
X-Servername
Apigw-Requestid
X-ProxyCache-Key
X-Httpd
X-Cluster
ServedBy
X-Auth-Group-Type
X-FB-TRIP-ID
X-Served-From
DB-Nickname
X-Proxy-Build
X-Zipkin-Id
X-Proxied
X-Cloudmap
X-Timing-Wait
X-S
Selected-Fe
X-Fetched-On
X-Origin
X-Routing-Service
X-Extlb
X-Azure-Ref-OriginShield
X-Hit
Surrogated-Key
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Worker
Cross-Origin-Embedder-Policy
X-CDN-Forward
LB
X-LSADC-Cache
X-SRV
Accept-Language
X-Cache-Hit
X-Request-URI
X-Lagoon
X-Sucuri-Cache
Referer-Policy
X-Generation-Time
N-Cache
X-Drupal-Cache-Tags
X-Fastly-Request-Id
X-Generated-By
X-Drupal-Cache-Contexts
X-Cdn-Origin
X-App-Version
X-Sucuri-ID
X-MP-GENERATED-AT
Xserver
CF-IPCountry
CDN-RequestId
X-Oracle-Dms-Ecid
X-XRDS-Location
X-URL
X-Xfnlog-Site
Ohc-Cache-HIT
X-Tx-Id
Source
X-F-Cache
X-TA-CDN-Provider
Node
X-Mly-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-AIR-PT
X-VC-TTL
Cache
X-Via-SSL
X-Via-CDN
Edge-Copy-Time
X-Wix-Request-Id
X-Via-Edge
X-Cache-Debug
X-Cache-Rule
X-NODE
X-UA
X-INCAP-ABP
X-Varnish-Beresp-Ttl
Cache-Provider
X-Site-Version
X-RCS-CacheZone
X-VCT
X-Pad
X-Locale
X-ElasticPress-Query
X-GEO
X-FC-Vary-Parameters
Expect-Staple
Fastly-Backend-Name
X-Gdpr
Fastly-GeoIP-CountryCode
X-External-Request-Id
X-Ec-Fail
X-Cache-Grace
BehaviorPad-Version
X-Eu-Site
Fastly-SSL
X-Ec-GeoHdr
X-DPWN-IS-SECURE
X-Geolocation
X-GeoIP-Region-Code
Fl-Custom-Application
X-Bc-Bl
X-HN
X-SD-PageType
X-GeoIP-Country-Code
X-GeoCode
X-Vdms-Version
Producers
X-GeoCountry
X-Geo-Region
X-Developer
Xc-Version
X-Application
Apple-News-Services-Host
Locale
X-Debug-Cache-Fetch
X-D
Apple-News-Services-Handled
X-B-Cookie
X-Conf
Cluster
X-Backend-Instance
X-Csrf-Jwt
Sslversion
X-Debug-Cache-Store
X-Cache-NE
X-Cache-Operation
DCR-Decision-By
X-Destination
X-VarnishDD-TTL
X-Cached-By
Redirect-Candidate
Apple-News-Services-Parsed-Url
X-Vtex-Remote-Cache
Rendered-Blocks
Apple-News-Services-Request-Url
DCR-Processing-Time-Ms
X-Aicache-OS
X-Platform-Server
Mail-Subject
MD5-Digest
Meta-Geo-Continent
X-Tcp-Rtt
X-Proto
X-PAYTM-SRV-ID
X-NWS-UUID-VERIFY
L5d-Success-Class
X-Op-Id-All
Lang
X-Origin-Time
X-Path
X-Proxied-Request
X-Slack-Shared-Secret-Outcome
X-S-Cookie
X-Rojux
Odigeo-Trace-Id
X-A-Ccd
X-ScT
X-A-Dam
X-Section
X-A-Dcw
X-Slack-Backend
X-A
Origin
Ngx.Var.Host
X-CGP
X-Nyt-Route
X-Is-Mobile
Web-Mar-Region
X-Bug-Bounty
PFcat
X-Is-Supported-Browser
X-Bl-Debug
X-Is-Desktop
X-Aed
X-HS-Content-Campaign-Id
We-Hiring
X-Ig-Origin-Region
X-Ig-Push-State
X-Is-Tablet
X-Urbn-Site-Id
X-BCube-Filmed-By
X-Mvc-Supplant-Cachable
X-AB-Test
X-A-Wwc
X-A-Dgt
Candidate-Md5Url
Host-ID
X-Urbn-Context-Path
X-Access
Ha-Gx-Prefs
X-Browser-Name
HA-Ipaddr
X-No-Session
X-BBC-Edge-Cache-Status
V-Age
X-AK-Request-ID
X-Akamai-Device-Characteristics
X-Amz-Meta-Cb-Modifiedtime
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Accel-Expires-Debug
X-Amz-Storage-Class
X-App-Name
Server-Host
X-Auto-Login
X-B-Cache
TDXMobile
Thinkindot-CacheControl
User-Cache-Control
Thinkindot-CacheControl-Type
X-B3-Trace-ID
X-Esi-Check
X-SB
X-Request-Time
X-Scheme
X-Shield-Cache-Expires
X-Thinkindot-L3
X-Signature
X-Request-Host
X-Req
X-Org
X-NodeID
X-Origin-Expires
X-Platform
X-Powered-By-VTEX-Cache
X-Policy
X-User
X-Varnish-CookieHashed-On
X-VTEX-Cache-Server
X-VServer
X-VTEX-Cache-Time
X-Wikidot-Backend
X-Zen-Fury
X-Wikidot-Static-Cache
X-Vmg-Version
X-Viewer-Country
X-Varnish-Director
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VG-WebCache
X-Via-Fastly
X-Node-Id
X-Mvc-Supplant-OutputCached
X-Date
X-CUA
X-DefElseHash
X-DefHash
X-Ec-Custom-Error
X-Dispatcher-Server
X-Core-Value
X-Content-Length
X-Cache-Info
X-Cache-Date
X-CacheTTL
X-Clientip
X-Content-Age
X-Epic-Correlation-Id
RNT-Time
X-Jobs
X-Human
X-Level-Front-Cache
X-Loc
X-Micro-Cache
X-Location
X-Hnp-Log
X-Gzip
X-Fmm-Version
X-Fastly-Backend
X-Gen-Mode
X-Generated-On
X-GoCache-CacheStatus
X-Block-Status
X-Cache-Id
L
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-InstanceId
Cdnsip
Origin-Agent-Cluster
Gh-Request-Id
Azure-Version
Content-Style-Type
Content-Script-Type
Cdncip
CDCHOST
Canary
Gannett-Cam-Experience-Id
Debug
Product
Platform
Req-Svc-Chain
RNT-Machine
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Ua-Device
Akamai-Mon-Iucid-Del
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-ShopId
X-Alternate-Cache-Key
X-ShardId
X-V-Cache
X-Gamma-Serve
X-Cache-FS-Status
X-Men
X-Cache-Aspx
X-UA-Device-Type
X-GeoIP-City
X-Bip
Cdn-Request-Time
X-GeoIP
X-Hash
X-Internal-TTL
X-IsAdmin
X-Edge-Server
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Pubstack
X-Contensis-Viewer-Groups
X-Server-IP
X-Request-Start
X-Cdn-Srv
X-Pool
X-NMSegId
X-HITS
X-Litespeed-Tag
X-Depends
X-Origin-Response-Time
X-Thanos
X-TIM-N
Cdn-Host
X-We-Are-Hiring
Tube-Got-Eval
NM-Fastcgi-Cache
NGX
Click-Count-Action-Start
Tube-Return
Release
Yak-Timeinfo
Req-ID
XM
Origin-EX
Origin-CC
X-TH-Server
Tube-Got-Results
Content-Secure-Policy
Country-Code
X-Varnish-Beresp-Status
X-Varnish-Authentication
Click-Count-Error
W
Tube-Get-Contents
X-VG-TLSProxy
X-Acquia-Purge-Cdn-Unconfigured
DSUID
ServerName
Mime-Version
X-Via-JSL
X-Service
X-Irp-Debug
X-LB-NoCache
CDN-PullZone
X-HOST
X-Vgn-Hpd-Reason
Ssr
CDN-RequestCountryCode
CDN-RequestPullSuccess
X-NGINX-Cache
CDN-RequestPullCode
CDN-Uid
X-RID
X-SIPLIST1
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
X-Tb-Optimization-Total-Bytes-Saved
IsBot
User-Agent
Fastly-Drupal-HTML
X-Moov-Xdn-Version
X-Moov-Xdn-Caching-Status
X-Varnishpool
X-Var-Ttl
X-CACHE-GROUP
X-Old-Content-Length
X-Varnish-Hits
X-Moov-T
Sid
N1-Cache
Pramga
GeoIP-Latitude
X-HubSpot-Correlation-Id
X-Api-Version
X-DC
X-Proxy-Cache-Status
X-ZONE
X-RequestId
X-Cs
X-Servedbyhost
X-ORCA-Accelerator
X-Refresh
CloudFront-Viewer-Country
X-APP
X-Nc
Esi-Enabled
X-Action
X-Wa
Cache-Hits
X-Via-Poph
X-Upstream-Ht
TWC-GeoIP-DMA
X-Upstream-Ct
X-Via-Popn
C-Via
X-Via-Popv
X-LiteSpeed-Tag
Server-ID
X-Thinkindot-L1
X-Vercel-Cache
X-Vercel-Id
TWC-GeoIP-City
X-Cache-VC
Location
X-HA-Backend
TWC-GeoIP-Region
X-Dc
X-CACHE-AGE
Cdn-Requestid
X-Cache-Bucket
X-LiteSpeed-Cache-Control
X-LB-ID
X-Webkit-CSP
X-Newrelic-Synthetics
Cache-Key
X-Parent-Response-Time
X-B3-Parentspanid
A
X-CS
X-Nananana
AMP-Access-Control-Allow-Source-Origin
XkeyRZ
X-Proxy-CacheRZ
X-NewRelic-App-Data
X-Tt-Logid
X-DynaTrace-JS-Agent
X-B3-Spanid
X-Presslabs-Stats
X-ApacheServer
X-PERF
HostName
X-COUNTRY
X-Zone
X-Webkit-Csp
X-Render-Time
X-WA-Info
X-DataCenter
WP-Super-Cache
SID
X-Endurance-Cache-Level
X-Ua
Fastly-Drupal-Html
X-Srv
X-Nitro-Cache
X-Webkit-Csp-Report-Only
Proxy-Firewall
X-Uri
X-Fpc
X-Litespeed-Cache-Control
X-Jungle-Id
X-API-Version
X-Oracle-Dms-Rid
Uri
X-Ion-Hop
GeoIp-Country-Code
RewriteTeamHook
Cache-Contol
RewriteTestHook
X-Ion-Healthy
X-Cdn-Forward
Cmsid
Cmstype
My-App
Log-Origin
TP-L2-Cache
X-Datadome
True-Client-Country-4JS
True-Client-Ip
Sever-Int
True-Client-IP
Server-Ext
Resin-Trace
X-Up
Server-Hostname
X-Service-Response-Time
Sm-Log-Id
X-Optimistic-Header
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
X-From
GeoIP-Country-Code
CacheControlHeader
X-CLOUD-TRACE-CONTEXT
X-Test
X-SERVER-NAME
X-Stale
Cdn
X-Udemy-Cache-App-Namespace
X-Dispatcher-Number
Tcn
Adler-Geo
SEZNAM-JOBS-OFFER
X-Datacenter
Is-Eu
X-Client-Ip
X-Dynatrace-Js-Agent
X-Varnish-Beresp-TTL
X-Pass-Why
WZWS-RAY
X-Nginx-Cache-Key
X-RateLimit-Limit
X-FPC
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Traceid
X-APP-VERSION
Srv
Lb
X-Air-Pt
X-Custom-Header
X-Air-Source
X-Fastly-Cache-Status
X-Air-Hostname
X-Debug-Service
Hostname
X-Air-Trace-Id
T-Server
X-Geo-Header
Origin-Site
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-TX-ID
X-SRCache-Key
X-Varnish-Hostname
X-ND-Cache
Server-Id
X-Vc
X-Provided-By
X-Akamai-Pragma-Client-IP
AKAMAI-GRN
X-Lb-Id
Cf-Ipcountry
X-Cache-Server
X-CMSURLCustom
Edge-Cache
NtCoent-Length
Vc-Max-Age
X-App
Serverhost
X-VCL-Version
X-Fastly-Backend-Reqs
X-Correlation-ID
X-Cache-Ttl
X-Ha-Backend
X-Via-PopH
X-Via-PopN
WebServer
X-Via-PopV
X-Html-Minification-Powered-By
YJS-ID
X-WA
X-NC
Pics-Label
X-Oracle-DMS-ECID
ServerHost
X-Esi
X-XRDS-LOCATION
Epwk-X-Cache
X-Rocket-Build-Number
X-Sigma-Backend
X-Forwarded-Site
Machine
X-Sigma
Pragrma
Geoip-Latitude
X-Region-Sid
Powered-By
S-Rt
X-Cdn-Cache-Status
Av-Poweredby
X-LAGOON
X-Cache-TTL-Remaining
X-Requestid
Nord-Request-ID
X-ServedByHost
Cache-Tv-Group
Ms-Author-Via
WWW-Authenticate
Vix-Hermes-Req-Id
Cloudfront-Viewer-Country
CountryCode
X-Sucuri-Id
X-Fastly-Cache
X-Proxy-Cache-La3
Xkey-La3
MIME-Version
Xkeylog
X-Ckpd-Fst-Backend
X-HS-Status
X-MSEdge-Flight
Warning
X-MSEdge-Features
On-Server
X-Lb-Nocache
X-Akamai-ERPolicy
X-Wp-Cf-Super-Cache-Cache-Control
X-Akamai-ERRuleID
X-Wp-Cf-Super-Cache
X-IAuth-Set-Uid
X-Check-Cacheable
FSS-Cache
Reporter
X-Serial
Thinkindot-Control
Coldstone-Viewer-Currency
Datacenter
Coldstone-Viewer-Country
Coldstone-Viewer-Country-Region-Name
DataCenter
X-Cdn-Request-ID
X-Web-Server
Timeexpire
Cneonction
X-BBC-Origin-Response-Status
X-Elasticpress-Query
X-Orig-Cache-Control
X-Dw-Trace-Id
Thinkindot-Cache-Type
X-Lsadc-Cache
X-Mg-Cache
X-VTEX-Cache-Backend-Header-Time
X-VTEX-Cache-Backend-Connect-Time
X-Td-Header-From-No-Data
X-Tncms-Bot-Tier