Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Accept-CH
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
Permissions-Policy
X-Drupal-Dynamic-Cache
X-Request-ID
X-Ua-Compatible
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Accept-Ch
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
Accept-CH-Lifetime
X-Amz-Request-Id
X-Backend
X-Amz-Id-2
X-Hacker
X-UA-Device
Cf-Apo-Via
X-Cache-Group
X-Turbo-Charged-By
X-Proxy-Cache
X-Age
Keep-Alive
X-Rq
EagleId
X-Via
X-Vhost
X-Dispatcher
X-Server
X-Check
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Litespeed-Cache
X-Varnish-Cache
Grace
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Server-Powered-By
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
Allow
Xkey
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cache-Lookup
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Dns-Prefetch-Control
X-Backend-Server
X-Akam-SW-Version
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-HW
X-Node
X-Server-Id
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Nginx-Cache-Status
X-Url
Content-Location
X-Country-Code
Cache-Tag
X-Content-Type
X-Nginx-Upstream-Cache-Status
X-Trace
Service-Worker-Allowed
Fastly-Restarts
X-Clacks-Overhead
Cross-Origin-Opener-Policy
X-Application-Context
X-Rack-Cache
X-NWS-LOG-UUID
X-Amz-Server-Side-Encryption
X-Times
X-LiteSpeed-Cache
X-PC
X-Vname
X-TtlSet
Surrogate-Key
X-Mcache
X-Edge
X-Midtier
Rating
X-Cache-TTL
Accept-Ch-Lifetime
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Server-Name
X-Cnection
X-Browser-Type
X-Element-Page-Cache
X-Abt-Application-Version
X-Powered-By-Plesk
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-Exp-Variant
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-GitHub-Request-Id
Nginx-Cache
X-ESI
Edge-Control
X-Vcap-Request-Id
X-ECACHE
X-D2id
X-Ac
Verso
X-Ser
X-MS-InvokeApp
X-Ratelimit-Limit
X-Client-IP
X-Middleton-Response
Response
X-Amz-Rid
X-Wormhole-Sdk
X-Ratelimit-Remaining
X-ORACLE-DMS-RID
X-CST
X-ARC
X-Dw-Request-Base-Id
X-Powered-CMS
X-Goog-Hash
X-B3-TraceId
X-Navigation-Version
X-Edge-Location-Klb
X-Kinsta-Cache
X-Server-ID
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Upstream
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Ruxit-Js-Agent
X-Forwarded-For
X-Amzn-Trace-Id
X-FastCGI-Cache
X-Cache-Key
SPIisLatency
SPRequestDuration
RTSS
X-Oneagent-Js-Injection
X-Mod-Pagespeed
X-Daa-Tunnel
Edge-Cache-Tag
Cache-Status
AR-Request-ID
Public-Key-Pins
AR-ATIME
AR-PoweredBy
AR-SID
X-Content-Digest
X-Ezoic-Cdn
X-NF-Request-ID
X-Version
Origin-Trial
X-Mg-S
SPRequestGuid
X-SharePointHealthScore
X-Fastly-Request-ID
Realpath
X-FTR-Request-ID
S
X-MSEdge-Ref
X-Shield-Request-Id
X-T
X-Ttl
X-ORACLE-DMS-ECID
Fastcgi-Cache
X-Recruiting
Front-End-Https
Cross-Origin-Resource-Policy
X-Kong-Proxy-Latency
AR-CACHE
X-Accel-Expires
X-Kong-Upstream-Latency
X-Cached
X-TTL
X-Distributor
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Azure-Ref
Access-Control-Request-Method
X-Varnish-TTL
TP-Cache
Arr-Disable-Session-Affinity
X-Xrds-Location
X-Request-Processing-Time
X-Request-Received
Count-Hit
X-HS-Cache-Config
X-HS-Content-Id
X-Ua-Browser
X-Id
X-HS-Hub-Id
X-Debug
X-Newrelic-App-Data
X-Correlation-Id
X-LLID
Cache-Tags
X-Ismobilevalue
Server-Node
X-Cluster-Name
X-Content-Security-Policy-Report-Only
X-Nf-Request-Id
X-PressLabs-Stats
Akamai-GRN
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-Frontend
X-VARITI-CCR
X-NGENIX-Cache
X-GUploader-UploadID
X-Varnish-Backend
X-Amz-Replication-Status
X-Protected-By
X-HS-Combine-CSS
X-Hits
X-Goog-Metageneration
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
X-Unique-Id
Payment
X-Ratelimit-Reset
X-Git-Hash
Cleartype
X-Varnish-Server
X-LB-Cache
X-Az
X-AppVersion
X-Activity-Id
X-Www-Served-By
X-FB-Debug
X-Hostname
X-Tt-Trace-Tag
X-Logged-In
X-Tt-Trace-Host
Content-Disposition
X-DIS-Request-ID
X-HP-Webp
X-Cambria-Cache-Control
X-Jurisdiction
X-HP-Trace-Id
Host
X-Forwarded-Proto
Filterid
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TraceId
Amp-Access-Control-Allow-Source-Origin
X-Template
X-App-Server
X-Varnish-Ttl
X-Geo-Country
Frame-Options
X-Fastcgi-Cache
X-Aspnet-Version
Version
Trailer
X-B3-TraceId-Primal
X-ASPNET-VERSION
Mrf-Cache-Status
MRF-Tech
X-Goog-Generation
Accept-Charset
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Type
Access-Control-Allow-Method
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Fastly-SIE
X-Ah-Environment
X-Upgrade-Enabled
X-Load-Cache
Fastly-SWR
X-Origin-Server
Viewport
Section-Io-Cache
X-Content-Options
X-TT
X-Fb-Rlafr
X-Envoy-Decorator-Operation
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Source
X-Cache-Control
X-B
X-B3-Sampled
X-Grace
Retry-After
MS-Author-Via
Content-MD5
Server-Name
X-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Device-Type
X-Vcl-Version
X-Cache-Age
X-Language
X-Cdn
X-Px
X-Request-Guid
X-Buckets
X-HS-Prerendered
X-Magnolia-Registration
X-Revision
X-Trace-Id
X-Mobile
Healthy
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-EdgeConnect-Cache-Status
X-Akamai-Edgescape
TCN
X-Varnish-Grace
X-WP-CF-Super-Cache-Active
Protected
X-Backend-Name
X-CSRF-Token
X-Debug-Info
X-App-Environment
X-Original-Request-Id
X-Instance
X-Status
SD-X-WS
X-RM-Cache-TTL
X-Response-Served-From
X-Tumblr-Pixel-1
X-ProcessESI
X-Rendered-As
X-RemovedCookies
Cross-Origin-Embedder-Policy-Report-Only
X-Tumblr-Pixel
X-Tumblr-Pixel-0
Charset
X-Is-Bot
X-NYM-Debug-Backend
X-Tumblr-User
X-Origin-Cache
X-ServerID
X-FW-Hash
X-FW-Dynamic
X-Environment-Context
X-Cacheable-TTL
X-FW-Serve
X-FW-Server
X-L-Path
X-FW-Version
X-FW-Type
X-FW-Static
X-Cache-Time
X-Adobe-Loc
X-Rule
X-Node-Name
X-Storage
X-UUID
X-Region
Upgrade-Insecure-Requests
X-Adobe-Content
NGB
Cross-Origin-Window-Policy
Access-Control-Request-Headers
X-Edge-Location
GEO-INFO
X-Proxy-Cache-Info
X-RTag
X-Yottaa-Optimizations
X-Yottaa-Metrics
MS-CV
Ms-Operation-Id
X-Mg-Request-UUID
X-Proxy
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
Refresh
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Content-Powered-By
X-Datadog-Parent-Id
X-Datadog-Sampled
X-G
X-Contextid
X-Ua-Device
X-Whom
OT-Force-Account-Verify
X-Amz-Meta-S3cmd-Attrs
X-Lambda-Id
X-B3-Traceid
Section-Io-Id
Countrycode
Webserver
X-FTR-Backend-Server
X-Country-Code-Real
Paypal-Debug-Id
DC
X-FTR-Backend
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Balancer
X-Amzn-Remapped-Content-Length
X-Reqid
X-User-Agent
X-Seen-By
X-HTML-Minification-Powered-By
Front
X-ECache
X-TT-LOGID
Alternate-Protocol
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Priority
X-Server-W
SRV
X-VC
X-Real-IP
X-WebKit-CSP-Report-Only
X-DataDome
X-Time
X-B3-SpanId
X-IPS-LoggedIn
X-WP-CF-Super-Cache-Cookies-Bypass
X-Akamai-Request-ID2
Liferay-Portal
Cross-Origin-Opener-Policy-Report-Only
Backend
X-N
X-Origin-CC
X-AB
X-Nginx-Cache
X-Origin-TTL
X-Rocket-Nginx-Serving-Static
Country
X-Mode
Onion-Location
Xet-Cookie
X-Hl-Ver
Environment
X-JoinUs
TWC-GeoIP-Country
TWC-Privacy
X-Tumblr-Pixel-2
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Connection-Speed
X-Say-TTL
Filters
X-Rn-Rsrv
X-Rewrite-Enabled
X-Origin-Hint
Fastcgi-Useragent
X-Redis-Cache
Meta-Geo
WPO-Cache-Status
X-Format
X-SayCDN-TTL
X-Say-Cacheable
X-SaId
WPO-Cache-Message
Property-Id
ServerID
Webcakes-App-Name
X-Cache-Action
Webcakes-App-Version
Webcakes-Region
X-UPSTREAM-Address
X-Cache-Host
X-RateLimit-Remaining
Web-Mar-Node
X-FB-TRIP-ID
X-Loop
Mn-Server-Ip
X-IPLB-Instance
X-Skip-Cache
X-Connection-Hash
X-Scope-Id
X-Hosted-By
X-Fetched-On
X-Detected-As
X-Cache-Expired-At
X-R9-Blue-Green-Version
X-Cluster-Node
Expiry
X-PHP-Host
X-Cache-Status-Check
X-Restarts
X-VC-Cache
X-IPLB-Request-ID
X-Tb
X-Cms-Context
From-Origin
X-DynaTrace
X-Vcache
X-Origin-Date
X-Tncms
DB-Nickname
X-Accel-Version
Uber-Trace-Id
X-Labrador-Cache-Channel
X-Frame-Option
X-Varnish-Age
X-Director
X-Soup
X-Handled-By
X-Web-Node
X-Forwarded-Host
X-Servername
Url
Atl-Traceid
Apigw-Requestid
X-Ms-Version
X-Varnish-Cache-Hits
X-Ms-Request-Id
X-Adobe-Source
X-Logging-Id
X-Httpd
X-Proxy-Build
X-ProxyCache-Status
X-ProxyCache-Key
X-Auth-Group-Type
X-Resp-Is-Stale
X-Webstats-RespID
Selected-Fe
X-Varnish-Beresp-Grace
X-Cluster
X-Timing-Wait
X-Tumblr-Pixel-3
Ohc-File-Size
X-BYPASS-REASON
ServedBy
X-Origin
X-Extlb
X-Cloudmap
Cross-Origin-Embedder-Policy
X-Routing-Service
X-Served-From
X-Zipkin-Id
X-Proxied
X-S
X-Webkit-CSP
Referer-Policy
X-Request-URI
X-Hit
Accept-Language
N-Cache
X-SRV
X-LSADC-Cache
X-Azure-Ref-OriginShield
X-XRDS-Location
X-HS-CF-Cache-Status
Surrogated-Key
X-RateLimit-Remaining-Second
X-Worker
X-RateLimit-Limit-Second
LB
X-Generated-By
X-Sucuri-Cache
X-Lagoon
X-App-Version
Xserver
X-Generation-Time
X-Fastly-Request-Id
X-Cache-Hit
VIX-Pulpo-Upstream-Status
X-Xfnlog-Site
X-Drupal-Cache-Tags
X-TA-CDN-Provider
X-Drupal-Cache-Contexts
VIX-Pulpo-Node
X-Sucuri-ID
CF-IPCountry
X-Cdn-Origin
X-Wix-Request-Id
X-CDN-Forward
X-MP-GENERATED-AT
X-Tx-Id
Source
X-Oracle-Dms-Ecid
X-F-Cache
Node
X-Cache-Debug
CDN-RequestId
X-NWS-UUID-VERIFY
X-RCS-CacheZone
X-VCT
X-NODE
X-Mly-Id
Cache
X-Via-Edge
X-Varnish-Beresp-Ttl
X-Via-SSL
X-Via-CDN
Edge-Copy-Time
X-Cache-Rule
X-Is-Tablet
X-Is-Supported-Browser
X-Tcp-Rtt
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Browser-Name
X-Geo-Region
X-Is-Mobile
X-Is-Desktop
X-No-Session
X-INCAP-ABP
Ohc-Cache-HIT
X-Signature
X-ElasticPress-Query
X-Pad
Cache-Provider
X-B-Cache
We-Hiring
Wxu-Next-Commit
Web-Mar-Region
Sslversion
Rendered-Blocks
Redirect-Candidate
PFcat
Wxu-Next-Hostname
Producers
W
X-A-Ccd
X-Access
X-AB-Test
X-Aed
X-Aicache-OS
X-App-Name
X-A-Wwc
X-A-Dgt
X-A
Origin
X-A-Dam
X-A-Dcw
Wxu-Next-Region
MD5-Digest
Content-Secure-Policy
Cluster
DCR-Decision-By
DCR-Processing-Time-Ms
Expect-Staple
Candidate-Md5Url
BehaviorPad-Version
Apple-News-Services-Handled
X-Site-Version
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Mail-Subject
Lang
X-Application
Meta-Geo-Continent
Ngx.Var.Host
L5d-Success-Class
Host-ID
Fastly-SSL
Fl-Custom-Application
Ha-Gx-Prefs
HA-Ipaddr
Odigeo-Trace-Id
X-Bl-Debug
X-Origin-Time
X-Org
X-Path
X-PAYTM-SRV-ID
X-Platform-Server
X-Op-Id-All
X-Nyt-Route
X-HS-Content-Campaign-Id
X-HN
X-Ig-Origin-Region
X-Ig-Push-State
X-Jobs
X-Proto
X-Proxied-Request
X-TIM-N
X-Slack-Shared-Secret-Outcome
X-VarnishDD-TTL
X-Vdms-Version
X-Vtex-Remote-Cache
X-Slack-Backend
X-Section
X-Rojux
X-S-Cookie
X-ScT
X-SD-PageType
X-Geolocation
X-GeoIP-Region-Code
X-CGP
X-Cache-Operation
X-Conf
X-Csrf-Jwt
X-D
X-Cache-NE
X-Cache-Info
X-Backend-Instance
X-Bc-Bl
X-BCube-Filmed-By
Xc-Version
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Gdpr
X-External-Request-Id
X-GeoCode
X-GeoCountry
X-GeoIP-Country-Code
X-Eu-Site
X-Ec-GeoHdr
X-Destination
X-Developer
X-DPWN-IS-SECURE
X-Ec-Fail
X-B-Cookie
X-Cache-Grace
X-Litespeed-Tag
X-Via-JSL
X-Locale
X-DefElseHash
X-Date
X-Core-Value
X-Content-Age
X-Cached-By
X-CacheTTL
X-Cdn-Srv
X-Clientip
X-Content-Length
X-DefHash
X-Fastly-Backend
X-FC-Vary-Parameters
X-Fmm-Version
X-Gamma-Serve
X-Esi-Check
X-Epic-Correlation-Id
X-Dispatcher-Server
X-Ec-Custom-Error
X-Edge-Server
X-Cache-Id
X-Bug-Bounty
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
User-Agent
User-Cache-Control
TDXMobile
Server-Host
Req-Svc-Chain
RNT-Machine
RNT-Time
V-Age
X-Accel-Expires-Debug
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Block-Status
X-Gen-Mode
X-Auto-Login
X-Amz-Storage-Class
X-AK-Request-ID
X-Akamai-Device-Characteristics
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Date
X-Generated-On
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Director
X-Varnish-Remaining-TTL
X-V-Cache
X-User
X-Scheme
X-Shield-Cache-Expires
X-Thinkindot-L3
X-Varnishpool
X-VG-WebCache
X-VTEX-Cache-Time
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Zen-Fury
X-VTEX-Cache-Server
X-VServer
X-Via-Fastly
X-Viewer-Country
X-Vmg-Version
X-SB
X-Request-Time
X-Hnp-Log
X-Human
X-Irp-Debug
X-Level-Front-Cache
X-Hash
X-Gzip
X-GeoIP
X-GeoIP-City
X-GoCache-CacheStatus
X-Loc
X-Location
X-Origin-Expires
X-Powered-By-VTEX-Cache
X-Req
X-Request-Host
X-NodeID
X-Node-Id
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-NMSegId
Product
X-GEO
X-VC-TTL
Debug
CDCHOST
Cdncip
Mime-Version
Origin-Agent-Cluster
Content-Style-Type
Cdn-Request-Time
Cdnsip
NM-Fastcgi-Cache
Content-Script-Type
Cdn-Host
Azure-Version
Canary
Azure-RegionName
Gannett-Cam-Experience-Id
Pramga
Azure-InstanceId
L
Azure-SiteName
Platform
Azure-SlotName
X-Sorting-Hat-PodId
X-ShardId
Akamai-Mon-Iucid-Del
X-Sorting-Hat-ShopId
X-UA
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-ShopId
X-Shopify-Stage
X-Proxy-Cache-Status
Click-Count-Action-Start
X-Depends
X-Internal-TTL
Click-Count-Error
DSUID
X-Contensis-Viewer-Groups
Gh-Request-Id
X-CUA
Country-Code
IsBot
X-Cache-FS-Status
CDN-PullZone
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-SIPLIST1
X-Request-Start
X-Server-IP
X-UA-Device-Type
X-Var-Ttl
XM
Yak-Timeinfo
X-We-Are-Hiring
X-VG-TLSProxy
X-Varnish-Authentication
CDN-Cache
X-Pool
X-Men
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-Uid
X-Mvc-Supplant-OutputCached
X-Cache-Aspx
X-Platform
X-Policy
X-AIR-PT
X-Origin-Response-Time
CDN-EdgeStorageId
X-IsAdmin
CDN-CachedAt
Req-ID
Tube-Return
NGX
Origin-CC
Tube-Get-Contents
Tube-Got-Results
Tube-Got-Eval
Origin-EX
ServerName
X-Acquia-Purge-Cdn-Unconfigured
X-HITS
X-URL
X-HOST
X-Pubstack
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Beresp-Status
X-Bip
X-ORCA-Accelerator
X-Thanos
X-Service
Release
X-RID
X-NGINX-Cache
X-LB-NoCache
Ssr
X-Varnish-Hits
X-Upstream-Ht
X-Upstream-Ct
Fastly-Drupal-HTML
Esi-Enabled
X-CACHE-GROUP
X-DC
X-VHOST
Sid
X-TH-Server
X-Vgn-Hpd-Reason
GeoIP-Latitude
X-HubSpot-Correlation-Id
X-Api-Version
X-RequestId
X-ZONE
X-Servedbyhost
X-Cache-Bucket
X-Refresh
CloudFront-Viewer-Country
X-Cs
Cdn-Requestid
X-Wa
X-Old-Content-Length
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Proxy-CacheRZ
XkeyRZ
X-Nc
A
Cache-Key
X-Newrelic-Synthetics
X-Via-Popn
C-Via
Server-ID
X-Via-Poph
X-B3-Spanid
X-Via-Popv
X-HA-Backend
X-APP
X-Tt-Logid
X-CACHE-AGE
X-Nananana
X-B3-Parentspanid
X-Parent-Response-Time
N1-Cache
X-LB-ID
X-Action
AMP-Access-Control-Allow-Source-Origin
X-Cdn-Forward
X-SERVER-NAME
X-Webkit-Csp-Report-Only
X-LiteSpeed-Cache-Control
X-CS
X-Presslabs-Stats
X-LiteSpeed-Tag
X-Cache-VC
X-Thinkindot-L1
X-Vercel-Id
X-COUNTRY
X-Dc
X-Endurance-Cache-Level
X-Vercel-Cache
X-Zone
X-DynaTrace-JS-Agent
HostName
Proxy-Firewall
Location
X-Webkit-Csp
X-Optimistic-Header
TWC-GeoIP-City
Fastly-Drupal-Html
Cache-Hits
SID
X-Ua
TWC-GeoIP-DMA
TWC-GeoIP-Region
X-Srv
Server-Hostname
Sever-Int
GeoIp-Country-Code
X-Fpc
True-Client-Country-4JS
WP-Super-Cache
Server-Ext
TP-L2-Cache
X-DataCenter
Cdn
X-Litespeed-Cache-Control
X-API-Version
X-PERF
X-ApacheServer
Uri
X-Test
X-NewRelic-App-Data
X-Air-Pt
Is-Eu
X-Oracle-Dms-Rid
X-Dispatcher-Number
X-WA-Info
True-Client-IP
Adler-Geo
X-Render-Time
WZWS-RAY
SEZNAM-JOBS-OFFER
Resin-Trace
X-Uri
X-Nitro-Cache
X-Datadome
X-Nginx-Cache-Key
True-Client-Ip
X-AWS-Id
X-Jungle-Id
X-Ion-Hop
GeoIP-Country-Code
X-Datacenter
Cache-Contol
X-VWS-Id
X-Ssense-Shipping-Surcharge-Enabled
X-CLOUD-TRACE-CONTEXT
X-Ion-Healthy
X-Ssense-Gql
RewriteTeamHook
RewriteTestHook
X-LJ-Flow-ID
Sm-Log-Id
X-Service-Response-Time
My-App
Cmsid
Log-Origin
Cmstype
T-Server
X-Geo-Header
X-Custom-Header
X-Provided-By
Tcn
X-Varnish-Beresp-TTL
X-Dynatrace-Js-Agent
X-Client-Ip
X-Pass-Why
X-RateLimit-Limit
X-Up
X-Stale
X-FPC
X-From
X-ND-Cache
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Lb
Vc-Max-Age
X-CMSURLCustom
Serverhost
X-Udemy-Cache-App-Namespace
Hostname
CacheControlHeader
X-Cache-Server
X-APP-VERSION
Srv
X-Vc
S-Rt
Pics-Label
X-Fastly-Cache-Status
X-Debug-Service
Av-Poweredby
Cache-Tv-Group
X-TX-ID
X-Cdn-Cache-Status
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-App
Powered-By
Server-Id
X-Akamai-Pragma-Client-IP
Vix-Hermes-Req-Id
X-Lb-Id
X-Correlation-ID
X-Cache-TTL-Remaining
Cf-Ipcountry
X-Fastly-Backend-Reqs
X-Cache-Ttl
X-Via-PopH
X-WA
X-Via-PopN
ServerHost
X-Via-PopV
X-Oracle-DMS-ECID
X-Fastly-Cache
X-NC
Origin-Site
NtCoent-Length
X-Ha-Backend
X-Html-Minification-Powered-By
X-Ckpd-Fst-Backend
X-LAGOON
WebServer
X-XRDS-LOCATION
X-Esi
On-Server
Xkey-La3
Geoip-Latitude
Xkeylog
X-Varnish-Hostname
X-VCL-Version
X-Proxy-Cache-La3
X-SRCache-Key
Thinkindot-Control
Edge-Cache
Cloudfront-Viewer-Country
WWW-Authenticate
Epwk-X-Cache
X-Requestid
X-ServedByHost
X-Traceid
CountryCode
Pragrma
X-Cms-Device
X-Ee-Generated-By
X-Ee-Request-Id
Warning
Store-Cloud-Cache
X-MSEdge-Flight
X-MSEdge-Features
X-Sucuri-Id
X-Save-Cache
Time-Cloud-Cache
X-Ee-Origin
X-Ee-Request-Date
X-Vary-Devices
AKAMAI
X-Amz-Meta-Opti
X-HS-Status
X-PHP-Backend
X-Serial
X-IAuth-Set-Uid
X-VTEX-Cache-Backend-Connect-Time
X-Wp-Cf-Super-Cache-Cache-Control
X-VTEX-Cache-Backend-Header-Time
X-Wp-Cf-Super-Cache
Ms-Author-Via
X-Check-Cacheable
X-Rocket-Build-Number
Reporter
X-Sigma
FSS-Cache
X-Akamai-Transformed
X-Sigma-Backend
YJS-ID
X-Lb-Nocache
X-Cdn-Request-ID
X-Region-Sid
X-Pod
X-Forwarded-Site
Machine
X-Mg-Cache
X-Lsadc-Cache
X-Ms-Blob-Type
Cneonction
X-Elasticpress-Query
X-Tncms-Bot-Tier
Timeexpire
X-Akamai-ERPolicy
X-Orig-Cache-Control
X-Akamai-ERRuleID
X-Limited
Magicmarker
X-Dw-Trace-Id
Thinkindot-Cache-Type
X-Td-Header-From-No-Data
X-Ms-Lease-Status
X-Info
Cl-Cache
X-BBC-Origin-Response-Status
X-Web-Server