Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Accept-CH
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
X-Request-ID
Timing-Allow-Origin
X-Iinfo
Permissions-Policy
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Accept-CH-Lifetime
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-Amz-Id-2
X-UA-Device
X-Hacker
Cf-Apo-Via
X-Cache-Group
X-Turbo-Charged-By
X-Proxy-Cache
X-Age
Keep-Alive
X-Rq
EagleId
X-Via
X-Vhost
X-Dispatcher
X-Server
X-Check
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Litespeed-Cache
X-Varnish-Cache
Grace
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Server-Powered-By
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Allow
Ali-Swift-Global-Savetime
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cache-Lookup
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Dns-Prefetch-Control
X-Backend-Server
X-Akam-SW-Version
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-HW
X-Node
X-Server-Id
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Nginx-Cache-Status
X-Url
Content-Location
X-Country-Code
X-Content-Type
Cache-Tag
X-Nginx-Upstream-Cache-Status
X-Trace
Service-Worker-Allowed
Fastly-Restarts
X-Clacks-Overhead
Cross-Origin-Opener-Policy
X-Application-Context
X-Rack-Cache
X-NWS-LOG-UUID
X-Amz-Server-Side-Encryption
X-Times
X-LiteSpeed-Cache
X-Vname
X-TtlSet
X-PC
X-Edge
X-Midtier
X-Mcache
Surrogate-Key
Rating
X-Cache-TTL
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Server-Name
X-Cnection
X-Browser-Type
X-Element-Page-Cache
X-Abt-Application-Version
X-Powered-By-Plesk
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Build
X-GitHub-Request-Id
X-ESI
Nginx-Cache
Edge-Control
X-Vcap-Request-Id
X-ECACHE
X-D2id
X-Ac
Verso
X-Ser
X-MS-InvokeApp
X-Ratelimit-Limit
X-Client-IP
X-Amz-Rid
X-Middleton-Response
Response
X-Ratelimit-Remaining
X-ORACLE-DMS-RID
X-Wormhole-Sdk
X-CST
X-ARC
X-Dw-Request-Base-Id
X-Powered-CMS
X-Goog-Hash
X-B3-TraceId
X-Edge-Location-Klb
X-Kinsta-Cache
X-Navigation-Version
X-Server-ID
X-Erf-Bev-Bev
X-PDP-UNCACHING-HASH
X-Upstream
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Ruxit-Js-Agent
X-Forwarded-For
X-Amzn-Trace-Id
X-FastCGI-Cache
SPRequestDuration
SPIisLatency
X-Cache-Key
RTSS
X-Oneagent-Js-Injection
X-Mod-Pagespeed
X-Daa-Tunnel
Cache-Status
Edge-Cache-Tag
AR-SID
AR-ATIME
AR-PoweredBy
Public-Key-Pins
AR-Request-ID
X-Content-Digest
X-Ezoic-Cdn
X-NF-Request-ID
X-Version
Origin-Trial
X-Mg-S
X-SharePointHealthScore
SPRequestGuid
X-Fastly-Request-ID
X-FTR-Request-ID
Realpath
S
X-MSEdge-Ref
X-T
X-Shield-Request-Id
X-Ttl
Fastcgi-Cache
X-ORACLE-DMS-ECID
X-Recruiting
Cross-Origin-Resource-Policy
Front-End-Https
X-Accel-Expires
AR-CACHE
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cached
X-TTL
X-Distributor
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Azure-Ref
Access-Control-Request-Method
TP-Cache
X-Varnish-TTL
Arr-Disable-Session-Affinity
X-Xrds-Location
X-Request-Processing-Time
X-Request-Received
X-Ua-Browser
X-Id
Count-Hit
X-Debug
X-Newrelic-App-Data
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Correlation-Id
X-LLID
Cache-Tags
X-Cluster-Name
Server-Node
X-Nf-Request-Id
X-Content-Security-Policy-Report-Only
X-Ismobilevalue
Akamai-GRN
X-PressLabs-Stats
MicrosoftSharePointTeamServices
X-Frontend
X-Aspnetmvc-Version
X-NGENIX-Cache
X-VARITI-CCR
Accept-Ch-Lifetime
X-GUploader-UploadID
X-Varnish-Backend
Accept-Ch
X-Amz-Replication-Status
X-Protected-By
X-HS-Combine-CSS
X-Hits
X-Goog-Metageneration
X-Request-Handler-Origin-Region
X-Microsite
X-Ratelimit-Reset
Payment
X-Unique-Id
X-Page-Id
Cleartype
X-LB-Cache
X-Varnish-Server
X-Www-Served-By
X-AppVersion
X-Activity-Id
X-FB-Debug
X-Az
X-Git-Hash
X-Tt-Trace-Tag
X-Logged-In
X-Tt-Trace-Host
X-Hostname
Content-Disposition
X-DIS-Request-ID
Host
X-Forwarded-Proto
Filterid
X-TraceId
X-Cambria-Cache-Control
X-Amzn-RequestId
X-HP-Webp
X-HP-Trace-Id
X-Amz-Apigw-Id
X-Jurisdiction
Amp-Access-Control-Allow-Source-Origin
X-Template
X-App-Server
X-Varnish-Ttl
X-Geo-Country
Frame-Options
X-Fastcgi-Cache
X-Aspnet-Version
Trailer
Version
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-ASPNET-VERSION
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
Accept-Charset
X-Type
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Load-Cache
X-Ah-Environment
Access-Control-Allow-Method
Fastly-SWR
Fastly-SIE
X-Upgrade-Enabled
Section-Io-Cache
X-Origin-Server
X-Content-Options
Viewport
X-TT
X-Envoy-Decorator-Operation
X-Fb-Rlafr
X-B3-Sampled
X-B
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Cache-Control
X-Source
X-Grace
MS-Author-Via
Retry-After
Server-Name
X-Rid
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Vcl-Version
X-Cache-Age
X-Device-Type
X-Language
X-Cdn
X-Px
X-Request-Guid
X-Buckets
X-HS-Prerendered
X-Magnolia-Registration
X-Trace-Id
X-Revision
X-Mobile
Healthy
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
TCN
X-EdgeConnect-Cache-Status
X-Akamai-Edgescape
X-WP-CF-Super-Cache-Active
X-Varnish-Grace
Protected
X-Backend-Name
X-CSRF-Token
X-Original-Request-Id
X-Status
SD-X-WS
X-Response-Served-From
X-App-Environment
X-RM-Cache-TTL
X-Instance
X-Debug-Info
Cross-Origin-Embedder-Policy-Report-Only
X-Tumblr-Pixel
X-Is-Bot
X-Rendered-As
Charset
X-Origin-Cache
X-Tumblr-Pixel-0
X-RemovedCookies
X-NYM-Debug-Backend
X-Tumblr-Pixel-1
X-Tumblr-User
X-ProcessESI
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-FW-Static
X-Environment-Context
X-L-Path
X-FW-Version
X-FW-Type
X-Node-Name
X-FW-Server
X-Adobe-Loc
X-Storage
X-ServerID
X-Region
X-Edge-Location
X-UUID
X-Rule
Upgrade-Insecure-Requests
X-Adobe-Content
X-Cache-Time
NGB
Cross-Origin-Window-Policy
Access-Control-Request-Headers
X-Cacheable-TTL
GEO-INFO
X-Proxy-Cache-Info
X-RTag
X-Yottaa-Optimizations
X-Yottaa-Metrics
MS-CV
Ms-Operation-Id
X-Mg-Request-UUID
X-Proxy
X-Framework
X-Debug-IsPreview
X-Debug-IsConnected
Refresh
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Content-Powered-By
X-Datadog-Parent-Id
X-Datadog-Sampled
X-G
X-Contextid
X-Ua-Device
X-Whom
OT-Force-Account-Verify
X-B3-Traceid
X-Lambda-Id
X-Amz-Meta-S3cmd-Attrs
Section-Io-Id
Countrycode
Webserver
X-FTR-Backend-Server
X-Country-Code-Real
Paypal-Debug-Id
DC
X-FTR-Backend
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Balancer
X-Amzn-Remapped-Content-Length
X-User-Agent
X-Reqid
X-Seen-By
X-HTML-Minification-Powered-By
Front
X-ECache
X-TT-LOGID
Alternate-Protocol
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Priority
X-Server-W
SRV
X-VC
X-Real-IP
X-WebKit-CSP-Report-Only
X-DataDome
X-Time
X-B3-SpanId
X-IPS-LoggedIn
X-WP-CF-Super-Cache-Cookies-Bypass
X-Akamai-Request-ID2
Liferay-Portal
Cross-Origin-Opener-Policy-Report-Only
Backend
X-N
X-Origin-CC
X-AB
X-Nginx-Cache
X-Origin-TTL
X-Rocket-Nginx-Serving-Static
Country
X-Mode
Onion-Location
Xet-Cookie
X-Hl-Ver
Environment
X-JoinUs
TWC-GeoIP-Country
TWC-Privacy
X-Tumblr-Pixel-2
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Connection-Speed
X-Say-TTL
Filters
X-Rn-Rsrv
X-Rewrite-Enabled
X-Origin-Hint
Fastcgi-Useragent
X-Redis-Cache
Meta-Geo
WPO-Cache-Status
X-Format
X-SayCDN-TTL
X-Say-Cacheable
X-SaId
WPO-Cache-Message
Property-Id
ServerID
Webcakes-App-Version
X-UPSTREAM-Address
X-Cache-Action
X-RateLimit-Remaining
Webcakes-App-Name
Webcakes-Region
X-FB-TRIP-ID
Web-Mar-Node
X-Cache-Host
X-Tb
X-Hosted-By
X-Connection-Hash
X-Detected-As
X-Scope-Id
X-Fetched-On
X-Loop
X-Skip-Cache
X-PHP-Host
X-Cache-Expired-At
X-Cms-Context
X-Restarts
X-VC-Cache
X-Soup
X-Cache-Status-Check
From-Origin
Expiry
Mn-Server-Ip
X-DynaTrace
X-Vcache
X-Director
X-Accel-Version
X-Frame-Option
Uber-Trace-Id
X-Labrador-Cache-Channel
X-Tncms
DB-Nickname
X-Varnish-Age
X-Handled-By
X-IPLB-Instance
X-Cluster-Node
X-Ms-Version
Apigw-Requestid
X-IPLB-Request-ID
X-R9-Blue-Green-Version
X-Origin-Date
X-Forwarded-Host
Atl-Traceid
X-Ms-Request-Id
Url
X-Web-Node
X-Adobe-Source
X-Logging-Id
X-Httpd
X-Varnish-Cache-Hits
X-Servername
X-Proxy-Build
X-Tumblr-Pixel-3
Selected-Fe
X-ProxyCache-Key
X-ProxyCache-Status
X-Timing-Wait
Ohc-File-Size
X-Auth-Group-Type
X-Webstats-RespID
X-Resp-Is-Stale
X-BYPASS-REASON
X-Varnish-Beresp-Grace
X-Cloudmap
ServedBy
X-Cluster
X-Origin
X-Extlb
Cross-Origin-Embedder-Policy
X-Routing-Service
X-Served-From
X-Zipkin-Id
X-Proxied
X-S
X-Webkit-CSP
Referer-Policy
X-Request-URI
X-Hit
Accept-Language
N-Cache
X-SRV
X-LSADC-Cache
X-Azure-Ref-OriginShield
Surrogated-Key
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-XRDS-Location
X-HS-CF-Cache-Status
X-Worker
X-Generated-By
LB
X-Sucuri-Cache
X-Lagoon
Xserver
X-App-Version
X-Fastly-Request-Id
X-Generation-Time
X-Cache-Hit
VIX-Pulpo-Node
X-Drupal-Cache-Tags
X-TA-CDN-Provider
X-Drupal-Cache-Contexts
X-Xfnlog-Site
VIX-Pulpo-Upstream-Status
X-Wix-Request-Id
X-Sucuri-ID
CF-IPCountry
X-Cdn-Origin
X-CDN-Forward
X-Tx-Id
X-MP-GENERATED-AT
Source
X-F-Cache
Node
X-Cache-Debug
CDN-RequestId
X-Oracle-Dms-Ecid
X-RCS-CacheZone
X-NWS-UUID-VERIFY
X-VCT
X-NODE
X-Mly-Id
Cache
X-Via-Edge
X-Via-SSL
X-Via-CDN
X-Cache-Rule
X-Varnish-Beresp-Ttl
Edge-Copy-Time
X-Is-Tablet
X-Is-Supported-Browser
X-Tcp-Rtt
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
X-Browser-Name
X-Geo-Region
X-Is-Mobile
X-Is-Desktop
X-INCAP-ABP
X-No-Session
Cache-Provider
X-ElasticPress-Query
Ohc-Cache-HIT
X-Pad
X-Signature
X-B-Cache
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
W
Redirect-Candidate
Sslversion
Producers
Rendered-Blocks
Web-Mar-Region
X-A-Dgt
X-Aed
X-Aicache-OS
X-App-Name
X-Application
X-Access
X-AB-Test
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Wwc
X-A
Meta-Geo-Continent
Cluster
Candidate-Md5Url
Content-Secure-Policy
DCR-Decision-By
DCR-Processing-Time-Ms
BehaviorPad-Version
Apple-News-Services-Request-Url
X-Site-Version
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Expect-Staple
Fastly-Backend-Name
X-B-Cookie
Ngx.Var.Host
Odigeo-Trace-Id
Origin
MD5-Digest
Lang
Fastly-GeoIP-CountryCode
Fastly-SSL
Fl-Custom-Application
Host-ID
PFcat
X-Cache-Info
X-Path
X-PAYTM-SRV-ID
X-Platform-Server
X-Proxied-Request
X-Origin-Time
X-Org
X-Ig-Push-State
X-Jobs
X-Nyt-Route
X-Op-Id-All
X-Rojux
X-S-Cookie
X-VarnishDD-TTL
X-Vdms-Version
X-Vtex-Remote-Cache
Xc-Version
X-TIM-N
X-Slack-Shared-Secret-Outcome
X-ScT
X-SD-PageType
X-Section
X-Slack-Backend
X-Ig-Origin-Region
X-HS-Content-Campaign-Id
X-D
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Destination
X-Conf
X-Cache-Operation
X-Bc-Bl
X-BCube-Filmed-By
X-Bl-Debug
X-Cache-NE
X-Developer
X-DPWN-IS-SECURE
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Geolocation
X-HN
X-GeoCountry
X-GeoCode
X-Ec-Fail
X-Ec-GeoHdr
X-External-Request-Id
X-Gdpr
X-Backend-Instance
X-Cache-Grace
X-Litespeed-Tag
X-Via-JSL
X-Locale
X-V-Cache
X-User
X-Accel-Expires-Debug
X-Varnish-CookieHashed-On
X-Varnish-Director
X-Node-Id
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
X-AK-Request-ID
X-Block-Status
X-Bug-Bounty
X-Cache-Date
X-Origin-Expires
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
X-Akamai-Device-Characteristics
X-Amz-Meta-Cb-Modifiedtime
X-Amz-Storage-Class
X-Auto-Login
We-Hiring
V-Age
RNT-Machine
RNT-Time
X-VServer
Server-Host
Req-Svc-Chain
Product
Platform
X-VTEX-Cache-Time
Pramga
X-VTEX-Cache-Server
X-Vmg-Version
X-Viewer-Country
X-Varnishpool
User-Agent
User-Cache-Control
X-Cache-Id
X-VG-WebCache
X-Via-Fastly
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Loc
X-Shield-Cache-Expires
X-Proto
X-Gen-Mode
X-Generated-On
X-GEO
X-Gamma-Serve
X-Fmm-Version
X-Eu-Site
X-Fastly-Backend
X-FC-Vary-Parameters
X-Powered-By-VTEX-Cache
X-GeoIP
X-Human
X-Location
X-Irp-Debug
X-Level-Front-Cache
X-Hnp-Log
X-Hash
X-GeoIP-City
X-GoCache-CacheStatus
X-Gzip
X-Esi-Check
X-Epic-Correlation-Id
X-Scheme
X-Content-Age
X-Content-Length
X-Core-Value
X-Clientip
X-CGP
Origin-Agent-Cluster
X-Cached-By
X-Cdn-Srv
X-Csrf-Jwt
X-SB
X-Ec-Custom-Error
X-Edge-Server
X-Request-Host
X-Req
X-Dispatcher-Server
X-DefHash
X-Date
X-Request-Time
X-DefElseHash
X-Micro-Cache
X-Varnish-Remaining-TTL
Azure-RegionName
HA-Ipaddr
Azure-InstanceId
Mail-Subject
X-Wikidot-Static-Cache
X-Zen-Fury
Azure-SiteName
CDCHOST
L5d-Success-Class
L
Azure-Version
Azure-SlotName
Content-Style-Type
Mime-Version
Ha-Gx-Prefs
Cdn-Request-Time
X-Wikidot-Backend
X-Mvc-Supplant-Cachable
Gannett-Cam-Experience-Id
X-VC-TTL
Cdncip
NM-Fastcgi-Cache
X-NodeID
Content-Script-Type
X-NMSegId
Cdnsip
Debug
Cdn-Host
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-UA
X-Proxy-Cache-Status
Akamai-Mon-Iucid-Del
X-ShardId
X-Alternate-Cache-Key
X-ShopId
Click-Count-Error
X-Server-IP
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-SIPLIST1
CDN-Uid
X-Mvc-Supplant-OutputCached
Click-Count-Action-Start
X-Cache-FS-Status
CDN-RequestPullSuccess
X-Sn-Servicetimems
Origin-CC
Canary
X-Pool
X-Men
X-Request-Start
X-Policy
X-Platform
X-IsAdmin
X-Internal-TTL
X-Origin-Response-Time
X-Depends
X-CUA
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
X-Contensis-Viewer-Groups
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
X-CacheTTL
X-Cache-Aspx
Tube-Return
Tube-Got-Results
Tube-Got-Eval
Gh-Request-Id
Yak-Timeinfo
X-Varnish-Authentication
X-AIR-PT
Tube-Get-Contents
XM
X-HITS
X-We-Are-Hiring
Origin-EX
Req-ID
NGX
IsBot
ServerName
X-Var-Ttl
X-VG-TLSProxy
X-UA-Device-Type
Country-Code
X-Acquia-Purge-Cdn-Unconfigured
DSUID
X-URL
X-LB-NoCache
X-Bip
X-Varnish-Hits
Release
X-RID
X-Service
X-Thanos
X-HOST
X-Tb-Optimization-Total-Bytes-Saved
X-ORCA-Accelerator
Ssr
X-Varnish-Beresp-Status
X-NGINX-Cache
X-Pubstack
X-Upstream-Ht
Fastly-Drupal-HTML
X-Upstream-Ct
X-CACHE-GROUP
Esi-Enabled
X-VHOST
Sid
X-DC
X-Vgn-Hpd-Reason
X-TH-Server
GeoIP-Latitude
X-Api-Version
X-HubSpot-Correlation-Id
X-Refresh
X-Cache-Bucket
X-RequestId
X-ZONE
X-Servedbyhost
X-Cs
CloudFront-Viewer-Country
Cdn-Requestid
X-Nc
X-Old-Content-Length
X-Moov-T
A
X-Wa
Cache-Key
XkeyRZ
X-Proxy-CacheRZ
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Newrelic-Synthetics
X-HA-Backend
X-APP
X-Via-Popn
X-Via-Popv
C-Via
X-Via-Poph
Server-ID
X-Tt-Logid
X-B3-Spanid
X-Nananana
X-CACHE-AGE
X-B3-Parentspanid
X-Parent-Response-Time
N1-Cache
X-Webkit-Csp-Report-Only
X-SERVER-NAME
AMP-Access-Control-Allow-Source-Origin
X-Cdn-Forward
X-LiteSpeed-Cache-Control
X-LB-ID
X-CS
X-Action
X-Presslabs-Stats
X-LiteSpeed-Tag
X-Vercel-Cache
X-Vercel-Id
X-Endurance-Cache-Level
Location
X-DynaTrace-JS-Agent
X-Zone
X-Dc
X-Thinkindot-L1
X-COUNTRY
X-Cache-VC
Proxy-Firewall
HostName
X-Webkit-Csp
SID
Cache-Hits
TWC-GeoIP-City
TWC-GeoIP-DMA
X-Ua
Fastly-Drupal-Html
X-Optimistic-Header
TWC-GeoIP-Region
X-Srv
GeoIp-Country-Code
X-DataCenter
WP-Super-Cache
X-Fpc
Server-Ext
Server-Hostname
Sever-Int
True-Client-Country-4JS
TP-L2-Cache
X-Litespeed-Cache-Control
Cdn
X-API-Version
X-NewRelic-App-Data
X-Test
X-ApacheServer
Uri
X-PERF
X-Air-Pt
X-Dispatcher-Number
Is-Eu
X-Render-Time
X-WA-Info
True-Client-IP
Adler-Geo
X-Oracle-Dms-Rid
X-Datadome
True-Client-Ip
WZWS-RAY
X-Nginx-Cache-Key
X-Nitro-Cache
Resin-Trace
X-Uri
SEZNAM-JOBS-OFFER
X-VWS-Id
RewriteTestHook
X-Ion-Healthy
X-Ion-Hop
X-AWS-Id
X-Jungle-Id
RewriteTeamHook
Cache-Contol
X-Datacenter
X-Ssense-Shipping-Surcharge-Enabled
X-CLOUD-TRACE-CONTEXT
X-LJ-Flow-ID
X-Ssense-Gql
GeoIP-Country-Code
X-Service-Response-Time
Sm-Log-Id
Cmsid
Cmstype
X-Custom-Header
X-Geo-Header
My-App
Log-Origin
T-Server
X-Provided-By
Tcn
X-Client-Ip
X-Dynatrace-Js-Agent
X-Pass-Why
X-Varnish-Beresp-TTL
X-RateLimit-Limit
X-Up
X-From
X-ND-Cache
X-Stale
X-FPC
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Srv
Serverhost
Hostname
X-APP-VERSION
CacheControlHeader
Lb
X-Cache-Server
X-CMSURLCustom
X-Udemy-Cache-App-Namespace
Vc-Max-Age
X-Vc
S-Rt
Av-Poweredby
X-Fastly-Cache-Status
X-Debug-Service
Pics-Label
Cache-Tv-Group
X-TX-ID
Server-Id
X-App
X-Air-Hostname
X-Cdn-Cache-Status
Powered-By
X-Air-Source
X-Air-Trace-Id
X-Correlation-ID
X-Cache-TTL-Remaining
X-Lb-Id
Cf-Ipcountry
X-Fastly-Backend-Reqs
Vix-Hermes-Req-Id
X-Akamai-Pragma-Client-IP
X-Cache-Ttl
X-Via-PopV
X-Html-Minification-Powered-By
X-NC
X-WA
X-Ckpd-Fst-Backend
NtCoent-Length
X-Via-PopH
X-Via-PopN
Origin-Site
X-Ha-Backend
ServerHost
X-LAGOON
X-Fastly-Cache
X-Oracle-DMS-ECID
X-Esi
WebServer
X-XRDS-LOCATION
Xkeylog
X-SRCache-Key
X-Proxy-Cache-La3
Xkey-La3
X-VCL-Version
X-Varnish-Hostname
Thinkindot-Control
Geoip-Latitude
On-Server
Epwk-X-Cache
X-ServedByHost
X-Requestid
Edge-Cache
Cloudfront-Viewer-Country
WWW-Authenticate
X-Traceid
CountryCode
X-Amz-Meta-Opti
X-Ee-Origin
X-Ee-Request-Id
X-Ee-Generated-By
X-Ee-Request-Date
X-PHP-Backend
X-MSEdge-Flight
Time-Cloud-Cache
X-Cms-Device
Store-Cloud-Cache
AKAMAI
Warning
X-Save-Cache
X-HS-Status
X-Sucuri-Id
X-Vary-Devices
X-MSEdge-Features
X-Rocket-Build-Number
Ms-Author-Via
X-Pod
FSS-Cache
X-Akamai-Transformed
X-VTEX-Cache-Backend-Connect-Time
X-Cdn-Request-ID
YJS-ID
X-Sigma-Backend
X-VTEX-Cache-Backend-Header-Time
X-Forwarded-Site
X-Check-Cacheable
Reporter
X-Lb-Nocache
X-IAuth-Set-Uid
X-Sigma
X-Region-Sid
Pragrma
X-Serial
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Machine
X-Lsadc-Cache
X-Mg-Cache
X-Akamai-ERRuleID
Cl-Cache
Timeexpire
X-Akamai-ERPolicy
Cneonction
X-Tncms-Bot-Tier
Magicmarker
X-Limited
X-Orig-Cache-Control
X-Info
X-Dw-Trace-Id
Thinkindot-Cache-Type
X-Td-Header-From-No-Data
X-BBC-Origin-Response-Status
X-Elasticpress-Query
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Web-Server