Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Accept-CH
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
Permissions-Policy
X-Drupal-Dynamic-Cache
X-Request-ID
X-Content-Security-Policy
Feature-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Accept-CH-Lifetime
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-AspNetMvc-Version
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-Amz-Id-2
X-Hacker
X-UA-Device
Cf-Apo-Via
X-Cache-Group
X-Turbo-Charged-By
X-Proxy-Cache
X-Age
Keep-Alive
X-Rq
EagleId
X-Via
X-Vhost
X-Dispatcher
X-Server
X-Check
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Litespeed-Cache
X-Varnish-Cache
Grace
X-OneAgent-JS-Injection
X-Server-Powered-By
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
Allow
X-Dns-Prefetch-Control
Xkey
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cache-Lookup
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
X-Akam-SW-Version
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-HW
X-Node
X-Server-Id
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Nginx-Cache-Status
X-Url
Content-Location
X-Country-Code
X-Content-Type
Cache-Tag
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Trace
Service-Worker-Allowed
X-Clacks-Overhead
Cross-Origin-Opener-Policy
X-Application-Context
X-NWS-LOG-UUID
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-LiteSpeed-Cache
X-Times
X-PC
X-Vname
X-TtlSet
Surrogate-Key
X-Mcache
X-Midtier
X-Edge
Rating
X-Server-Name
X-Cache-TTL
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Cnection
X-Element-Page-Cache
X-Browser-Type
X-Powered-By-Plesk
X-Abt-Application-Version
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-GitHub-Request-Id
X-ESI
Nginx-Cache
Edge-Control
X-Vcap-Request-Id
X-ECACHE
Verso
X-D2id
X-Ac
X-Ser
X-MS-InvokeApp
X-Ruxit-Js-Agent
X-ORACLE-DMS-RID
X-Client-IP
X-Ratelimit-Limit
X-Amz-Rid
Response
X-Middleton-Response
X-ASPNET-VERSION
X-Wormhole-Sdk
X-Ratelimit-Remaining
X-ARC
X-CST
X-Powered-CMS
X-Dw-Request-Base-Id
X-Goog-Hash
X-B3-TraceId
X-Navigation-Version
X-Kinsta-Cache
X-Edge-Location-Klb
X-Server-ID
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Upstream
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Forwarded-For
X-Amzn-Trace-Id
X-FastCGI-Cache
SPIisLatency
SPRequestDuration
X-Cache-Key
RTSS
X-Oneagent-Js-Injection
X-Mod-Pagespeed
X-Daa-Tunnel
Edge-Cache-Tag
Cache-Status
AR-Request-ID
AR-PoweredBy
AR-SID
Public-Key-Pins
AR-ATIME
X-Content-Digest
X-Aspnetmvc-Version
X-Ezoic-Cdn
X-NF-Request-ID
X-Version
X-Ttl
Origin-Trial
SPRequestGuid
X-SharePointHealthScore
X-Mg-S
Realpath
X-FTR-Request-ID
S
X-MSEdge-Ref
X-Shield-Request-Id
X-T
X-Fastly-Request-ID
Fastcgi-Cache
X-ORACLE-DMS-ECID
X-Recruiting
Front-End-Https
Cross-Origin-Resource-Policy
X-Accel-Expires
X-Kong-Upstream-Latency
AR-CACHE
X-Kong-Proxy-Latency
X-Cached
X-Distributor
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Xrds-Location
X-Azure-Ref
X-TTL
Access-Control-Request-Method
Arr-Disable-Session-Affinity
TP-Cache
X-Varnish-TTL
X-Request-Processing-Time
X-Request-Received
X-HS-Content-Id
X-Id
Count-Hit
X-Ua-Browser
X-HS-Hub-Id
X-HS-Cache-Config
X-Debug
X-Correlation-Id
Cache-Tags
X-LLID
X-Ismobilevalue
X-Cluster-Name
Server-Node
X-Newrelic-App-Data
X-Content-Security-Policy-Report-Only
X-Nf-Request-Id
X-PressLabs-Stats
MicrosoftSharePointTeamServices
Akamai-GRN
X-Frontend
X-VARITI-CCR
X-NGENIX-Cache
Accept-Ch-Lifetime
X-GUploader-UploadID
X-Varnish-Backend
Accept-Ch
X-Amz-Replication-Status
X-Protected-By
X-HS-Combine-CSS
X-Hits
X-Goog-Metageneration
Payment
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
X-Ratelimit-Reset
X-Unique-Id
X-LB-Cache
Cleartype
X-FB-Debug
X-Varnish-Server
X-Git-Hash
X-Activity-Id
X-Logged-In
X-Www-Served-By
X-Az
X-AppVersion
X-Tt-Trace-Tag
X-Hostname
X-Tt-Trace-Host
Content-Disposition
X-DIS-Request-ID
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
Host
X-Cambria-Cache-Control
Filterid
X-Forwarded-Proto
X-TraceId
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Template
Amp-Access-Control-Allow-Source-Origin
X-App-Server
X-Varnish-Ttl
X-Geo-Country
Frame-Options
X-Aspnet-Version
X-Fastcgi-Cache
Trailer
Version
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
Access-Control-Allow-Method
Accept-Charset
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Type
X-Load-Cache
Fastly-SWR
X-Upgrade-Enabled
X-Ah-Environment
Fastly-SIE
Section-Io-Cache
Viewport
X-Content-Options
X-Origin-Server
X-TT
X-Fb-Rlafr
X-Envoy-Decorator-Operation
X-B3-Sampled
X-TEC-API-ORIGIN
X-B
X-Grace
X-Cache-Control
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Source
MS-Author-Via
Retry-After
X-Rid
Content-MD5
Server-Name
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Device-Type
X-Cache-Age
X-Vcl-Version
X-Language
X-Cdn
X-Request-Guid
X-Px
X-HS-Prerendered
X-Magnolia-Registration
X-Buckets
X-Trace-Id
X-Mobile
X-Revision
TCN
Healthy
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-EdgeConnect-Cache-Status
X-Akamai-Edgescape
X-Varnish-Grace
X-WP-CF-Super-Cache-Active
X-Backend-Name
Protected
X-CSRF-Token
X-Debug-Info
X-Status
X-RM-Cache-TTL
X-App-Environment
X-Original-Request-Id
X-Instance
SD-X-WS
X-Response-Served-From
X-Rendered-As
X-ServerID
X-Rule
X-Tumblr-Pixel
X-Origin-Cache
X-Tumblr-Pixel-1
X-Is-Bot
X-RemovedCookies
X-Tumblr-User
X-Tumblr-Pixel-0
X-NYM-Debug-Backend
Cross-Origin-Embedder-Policy-Report-Only
Charset
X-ProcessESI
GEO-INFO
Upgrade-Insecure-Requests
X-Adobe-Loc
X-FW-Hash
X-Environment-Context
NGB
X-Edge-Location
X-Framework
X-Adobe-Content
X-FW-Dynamic
X-FW-Server
X-L-Path
X-FW-Version
X-Mg-Request-UUID
X-Node-Name
X-Region
Access-Control-Request-Headers
X-FW-Type
Cross-Origin-Window-Policy
X-Cache-Time
X-UUID
X-FW-Static
X-Storage
X-Cacheable-TTL
X-FW-Serve
X-Proxy-Cache-Info
X-Datadog-Sampling-Priority
X-Yottaa-Metrics
X-Debug-IsPreview
X-Datadog-Trace-Id
X-Debug-IsConnected
X-Yottaa-Optimizations
X-Datadog-Sampled
X-RTag
X-Content-Powered-By
X-Proxy
X-Datadog-Parent-Id
Ms-Operation-Id
MS-CV
X-Contextid
X-G
Refresh
X-Ua-Device
X-Whom
OT-Force-Account-Verify
X-Lambda-Id
X-B3-Traceid
X-Amz-Meta-S3cmd-Attrs
Webserver
Section-Io-Id
Countrycode
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
Paypal-Debug-Id
X-FTR-Balancer
X-FTR-Cache-Status
X-User-Agent
DC
X-FTR-Expires
X-Reqid
X-Amzn-Remapped-Content-Length
X-Seen-By
X-HTML-Minification-Powered-By
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-VC
Front
X-ECache
X-TT-LOGID
Priority
Alternate-Protocol
X-Server-W
SRV
X-WebKit-CSP-Report-Only
X-Real-IP
X-DataDome
X-IPS-LoggedIn
X-B3-SpanId
X-WP-CF-Super-Cache-Cookies-Bypass
X-Time
Cross-Origin-Opener-Policy-Report-Only
X-Akamai-Request-ID2
Liferay-Portal
X-Origin-CC
X-AB
X-Origin-TTL
Backend
X-N
Country
X-Mode
X-Rocket-Nginx-Serving-Static
X-Cache-Status-Check
WPO-Cache-Status
X-Hl-Ver
WPO-Cache-Message
Onion-Location
Xet-Cookie
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Rn-Rsrv
TWC-Device-Class
X-Rewrite-Enabled
X-Redis-Cache
X-Origin-Hint
X-Tumblr-Pixel-2
X-Say-TTL
Filters
Fastcgi-Useragent
Meta-Geo
X-Say-Cacheable
ServerID
X-SayCDN-TTL
Property-Id
Environment
X-SaId
Webcakes-App-Version
X-Cache-Host
Webcakes-Region
X-FB-TRIP-ID
X-Format
X-Cache-Action
X-RateLimit-Remaining
X-UPSTREAM-Address
X-JoinUs
Web-Mar-Node
TWC-Privacy
Webcakes-App-Name
X-Nginx-Cache
X-Fetched-On
Expiry
X-Skip-Cache
X-DynaTrace
X-Soup
X-Scope-Id
X-Handled-By
X-Varnish-Age
X-VC-Cache
X-IPLB-Request-ID
X-Restarts
X-R9-Blue-Green-Version
X-IPLB-Instance
DB-Nickname
X-Labrador-Cache-Channel
X-PHP-Host
X-Vcache
X-Hosted-By
X-Frame-Option
X-Tb
Mn-Server-Ip
X-Cluster-Node
X-Cache-Expired-At
X-Accel-Version
X-Origin-Date
X-Cms-Context
From-Origin
X-Detected-As
X-Loop
X-Director
X-Tncms
X-Connection-Hash
Uber-Trace-Id
Atl-Traceid
X-Adobe-Source
X-Varnish-Beresp-Grace
Apigw-Requestid
X-Varnish-Cache-Hits
X-ProxyCache-Key
Url
X-ProxyCache-Status
X-Ms-Request-Id
X-Web-Node
X-Forwarded-Host
X-Webstats-RespID
X-Servername
X-BYPASS-REASON
X-Logging-Id
X-Httpd
X-Ms-Version
X-Proxy-Build
Selected-Fe
X-Cluster
X-Auth-Group-Type
ServedBy
X-Timing-Wait
X-Fastly-Request-Id
X-Served-From
Ohc-File-Size
X-Tumblr-Pixel-3
X-Resp-Is-Stale
X-Origin
Cross-Origin-Embedder-Policy
X-Zipkin-Id
X-Cloudmap
X-Extlb
X-Proxied
X-S
X-Routing-Service
X-Webkit-CSP
Referer-Policy
X-Hit
X-Request-URI
N-Cache
Accept-Language
X-SRV
X-LSADC-Cache
X-Azure-Ref-OriginShield
X-HS-CF-Cache-Status
Surrogated-Key
X-RateLimit-Limit-Second
X-Worker
X-RateLimit-Remaining-Second
LB
X-Generated-By
X-Sucuri-Cache
X-Lagoon
X-App-Version
X-Generation-Time
Xserver
X-Cache-Hit
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Xfnlog-Site
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-TA-CDN-Provider
X-XRDS-Location
X-Cdn-Origin
X-Wix-Request-Id
CF-IPCountry
X-Webkit-Csp
X-Sucuri-ID
X-Oracle-Dms-Ecid
Source
X-CDN-Forward
X-Tx-Id
X-MP-GENERATED-AT
X-NWS-UUID-VERIFY
X-F-Cache
CDN-RequestId
Node
X-Cache-Debug
X-RCS-CacheZone
X-NODE
X-VCT
Cache
X-Mly-Id
X-Varnish-Beresp-Ttl
Edge-Copy-Time
X-Cache-Rule
X-Via-Edge
X-Via-CDN
X-Via-SSL
X-Is-Tablet
X-Tcp-Rtt
X-Is-Supported-Browser
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Browser-Name
X-Geo-Region
X-Is-Mobile
X-Is-Desktop
X-INCAP-ABP
X-Pad
X-No-Session
X-ElasticPress-Query
Ohc-Cache-HIT
X-Signature
Cache-Provider
X-B-Cache
X-Gdpr
X-Cache-Grace
X-Cache-Info
X-Bug-Bounty
Candidate-Md5Url
BehaviorPad-Version
X-Cache-Operation
X-Cache-NE
X-Bl-Debug
X-BCube-Filmed-By
X-Application
X-App-Name
Cluster
X-B-Cookie
X-Backend-Instance
X-GeoCode
X-Bc-Bl
X-CGP
X-Conf
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-D
X-Destination
X-Eu-Site
X-DPWN-IS-SECURE
X-Developer
X-Csrf-Jwt
X-External-Request-Id
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Handled
X-FC-Vary-Parameters
X-Site-Version
Content-Secure-Policy
X-Ec-GeoHdr
X-Access
Wxu-Next-Hostname
Wxu-Next-Commit
Ngx.Var.Host
Meta-Geo-Continent
MD5-Digest
Lang
Wxu-Next-Region
Mail-Subject
Web-Mar-Region
Odigeo-Trace-Id
Sslversion
Redirect-Candidate
Rendered-Blocks
Producers
PFcat
We-Hiring
Origin
W
L5d-Success-Class
X-A
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Fastly-SSL
Expect-Staple
X-GeoCountry
DCR-Processing-Time-Ms
X-Aicache-OS
X-Aed
Fl-Custom-Application
X-AB-Test
X-A-Dcw
X-A-Dam
X-A-Ccd
Host-ID
HA-Ipaddr
X-A-Wwc
X-A-Dgt
Ha-Gx-Prefs
DCR-Decision-By
X-Ec-Fail
X-Nyt-Route
X-HS-Content-Campaign-Id
X-Vdms-Version
X-Litespeed-Tag
X-Op-Id-All
X-Mvc-Supplant-Cachable
X-Org
X-ScT
X-Ig-Origin-Region
X-Ig-Push-State
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-TIM-N
X-Jobs
X-Section
X-VarnishDD-TTL
X-SD-PageType
X-Origin-Time
X-HN
X-GeoIP-Region-Code
X-Proxied-Request
X-GeoIP-Country-Code
X-Platform-Server
X-Proto
Xc-Version
X-Rojux
X-Geolocation
X-Path
X-Via-JSL
X-S-Cookie
X-Vtex-Remote-Cache
X-PAYTM-SRV-ID
X-NGINX-Cache
X-Locale
X-VC-TTL
X-Shield-Cache-Expires
X-Thinkindot-L3
X-Request-Time
X-Scheme
X-SB
X-Accel-Expires-Debug
X-Request-Host
X-Req
X-Varnish-Director
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
User-Agent
User-Cache-Control
V-Age
TDXMobile
X-Wikidot-Backend
RNT-Time
RNT-Machine
X-Zen-Fury
Server-Host
X-Wikidot-Static-Cache
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Varnish-CookieINHashed-On
X-AK-Request-ID
X-Varnish-CookieHashed-On
X-Var-Ttl
X-V-Cache
X-Varnish-Remaining-TTL
X-Varnishpool
X-Vmg-Version
X-VServer
X-Viewer-Country
X-Via-Fastly
X-VG-WebCache
X-User
X-BBC-Edge-Cache-Status
X-Hash
X-DefHash
X-Dispatcher-Server
X-Gzip
X-Ec-Custom-Error
X-DefElseHash
X-Hnp-Log
X-Irp-Debug
X-Human
X-CUA
X-Date
Req-Svc-Chain
X-GoCache-CacheStatus
X-Gen-Mode
X-GeoIP-City
X-Generated-On
X-GEO
X-GeoIP
X-Gamma-Serve
X-Fmm-Version
X-Edge-Server
X-Epic-Correlation-Id
X-Esi-Check
X-Fastly-Backend
X-Core-Value
X-Content-Length
X-Origin-Expires
X-B3-Trace-ID
X-Block-Status
X-Cache-Date
X-NodeID
X-Platform
X-Auto-Login
X-Amz-Meta-Cb-Modifiedtime
X-Powered-By-VTEX-Cache
X-Amz-Storage-Class
X-Policy
X-Node-Id
X-NMSegId
X-Location
X-Loc
X-Level-Front-Cache
X-Content-Age
X-Micro-Cache
X-Clientip
X-Cached-By
X-Mvc-Supplant-OutputCached
X-CacheTTL
X-Cdn-Srv
X-Akamai-Device-Characteristics
X-Cache-Id
Content-Style-Type
Content-Script-Type
Cdnsip
Gannett-Cam-Experience-Id
Gh-Request-Id
NM-Fastcgi-Cache
Mime-Version
L
Cdncip
Cdn-Request-Time
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
Cdn-Host
CDCHOST
Canary
Origin-Agent-Cluster
Debug
Platform
Pramga
Product
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Proxy-Cache-Status
X-COUNTRY
X-UA
X-ShardId
Akamai-Mon-Iucid-Del
CDN-PullZone
X-Bip
CDN-RequestPullSuccess
X-Origin-Response-Time
X-VG-TLSProxy
CDN-Uid
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-EdgeStorageId
Yak-Timeinfo
XM
X-We-Are-Hiring
X-HITS
X-Depends
X-Contensis-Viewer-Groups
Release
X-Internal-TTL
X-IsAdmin
X-Cache-FS-Status
Click-Count-Action-Start
CDN-CachedAt
CDN-Cache
X-Men
ServerName
X-Cache-Aspx
Req-ID
X-UA-Device-Type
X-SVT-ORM-RULES
NGX
X-Varnish-Authentication
X-SIPLIST1
X-Sn-Servicetimems
Tube-Get-Contents
X-SVT-ORM-VERSION
Tube-Return
Tube-Got-Results
X-Thanos
Origin-EX
Origin-CC
IsBot
X-Varnish-Beresp-Status
DSUID
X-Pubstack
X-Request-Start
Country-Code
X-Acquia-Purge-Cdn-Unconfigured
X-Pool
X-Server-IP
X-AIR-PT
Click-Count-Error
Tube-Got-Eval
X-URL
X-Varnish-Hits
Ssr
X-RID
X-ORCA-Accelerator
X-Tb-Optimization-Total-Bytes-Saved
X-LB-NoCache
X-Service
X-HOST
X-Upstream-Ht
Fastly-Drupal-HTML
X-Upstream-Ct
X-CACHE-GROUP
Esi-Enabled
X-ZONE
X-VHOST
Sid
X-DC
X-Vgn-Hpd-Reason
GeoIP-Latitude
X-TH-Server
X-Api-Version
X-HubSpot-Correlation-Id
X-Cs
CloudFront-Viewer-Country
X-Refresh
X-Servedbyhost
X-RequestId
X-Cache-Bucket
Cdn-Requestid
X-Wa
Cache-Key
X-Old-Content-Length
X-Moov-Xdn-Version
XkeyRZ
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Proxy-CacheRZ
X-Nc
A
X-Newrelic-Synthetics
Server-ID
X-APP
X-Tt-Logid
C-Via
X-B3-Spanid
X-NewRelic-App-Data
X-CACHE-AGE
X-HA-Backend
X-Via-Poph
X-Nananana
X-Via-Popn
X-B3-Parentspanid
X-Via-Popv
N1-Cache
X-Parent-Response-Time
X-Cdn-Forward
AMP-Access-Control-Allow-Source-Origin
X-Action
X-Webkit-Csp-Report-Only
X-LiteSpeed-Cache-Control
X-CS
X-LB-ID
X-LiteSpeed-Tag
X-Presslabs-Stats
X-Thinkindot-L1
HostName
X-Cache-VC
X-DynaTrace-JS-Agent
Proxy-Firewall
Location
X-Vercel-Cache
X-Endurance-Cache-Level
X-Vercel-Id
X-Dc
X-Ua
Cache-Hits
X-Optimistic-Header
Fastly-Drupal-Html
TWC-GeoIP-DMA
TWC-GeoIP-Region
SID
TWC-GeoIP-City
X-Srv
X-Zone
Server-Ext
X-Fpc
WP-Super-Cache
X-DataCenter
TP-L2-Cache
True-Client-Country-4JS
Sever-Int
Server-Hostname
GeoIp-Country-Code
X-API-Version
X-Litespeed-Cache-Control
Cdn
X-PERF
X-Test
X-ApacheServer
Is-Eu
Uri
X-Dispatcher-Number
Adler-Geo
X-Air-Pt
True-Client-IP
X-WA-Info
X-Render-Time
SEZNAM-JOBS-OFFER
WZWS-RAY
X-Datadome
X-Nginx-Cache-Key
X-Nitro-Cache
Resin-Trace
True-Client-Ip
X-Uri
X-Jungle-Id
X-VWS-Id
X-Datacenter
X-CLOUD-TRACE-CONTEXT
GeoIP-Country-Code
X-Ssense-Shipping-Surcharge-Enabled
RewriteTestHook
RewriteTeamHook
Cache-Contol
X-Ion-Healthy
X-Ssense-Gql
X-LJ-Flow-ID
X-AWS-Id
X-Ion-Hop
Sm-Log-Id
X-Service-Response-Time
X-SERVER-NAME
T-Server
X-Custom-Header
X-Geo-Header
X-Provided-By
My-App
Cmstype
Cmsid
Tcn
Log-Origin
X-Client-Ip
X-Pass-Why
X-Dynatrace-Js-Agent
X-Varnish-Beresp-TTL
X-Up
X-From
X-RateLimit-Limit
X-Stale
X-ND-Cache
X-FPC
X-Srcache-Fetch-Status
X-Srcache-Store-Status
Hostname
CacheControlHeader
X-Udemy-Cache-App-Namespace
Serverhost
Srv
X-APP-VERSION
Lb
X-CMSURLCustom
X-Cache-Server
Vc-Max-Age
X-Oracle-Dms-Rid
S-Rt
Pics-Label
X-Debug-Service
X-Fastly-Cache-Status
Av-Poweredby
X-TX-ID
Cache-Tv-Group
X-Air-Source
X-Air-Hostname
X-Lb-Id
X-App
X-Cdn-Cache-Status
Server-Id
X-Air-Trace-Id
Powered-By
X-Vc
X-Correlation-ID
X-Cache-TTL-Remaining
X-Ha-Backend
X-Fastly-Backend-Reqs
Cf-Ipcountry
Vix-Hermes-Req-Id
X-Via-PopV
X-Via-PopH
X-Via-PopN
X-Akamai-Pragma-Client-IP
X-Cache-Ttl
X-Ckpd-Fst-Backend
X-WA
X-Html-Minification-Powered-By
X-LAGOON
ServerHost
X-Fastly-Cache
X-Oracle-DMS-ECID
Origin-Site
X-NC
X-Esi
X-XRDS-LOCATION
X-VCL-Version
X-Proxy-Cache-La3
Xkey-La3
Geoip-Latitude
Xkeylog
On-Server
NtCoent-Length
X-Varnish-Hostname
X-SRCache-Key
Epwk-X-Cache
Thinkindot-Control
Edge-Cache
X-Traceid
Cloudfront-Viewer-Country
WWW-Authenticate
WebServer
X-ServedByHost
X-Requestid
CountryCode
X-Sucuri-Id
X-Ee-Request-Id
X-Ee-Origin
X-Cms-Device
X-Ee-Request-Date
X-Ee-Generated-By
AKAMAI
X-PHP-Backend
X-MSEdge-Features
X-MSEdge-Flight
X-Save-Cache
Time-Cloud-Cache
X-Vary-Devices
Pragrma
X-HS-Status
X-Amz-Meta-Opti
Store-Cloud-Cache
Warning
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
YJS-ID
X-Region-Sid
X-Cdn-Request-ID
X-Forwarded-Site
Machine
X-Wp-Cf-Super-Cache-Cache-Control
Ms-Author-Via
FSS-Cache
X-Wp-Cf-Super-Cache
X-Pod
X-Akamai-Transformed
X-IAuth-Set-Uid
X-Serial
X-VTEX-Cache-Backend-Connect-Time
X-VTEX-Cache-Backend-Header-Time
X-Check-Cacheable
X-Lb-Nocache
Reporter
Magicmarker
X-Ms-Lease-Status
Yjs-Id
X-Info
X-Ms-Blob-Type
X-Limited
Cl-Cache
Cneonction
X-Dw-Trace-Id
X-Akamai-ERRuleID
X-Orig-Cache-Control
X-Elasticpress-Query
X-BBC-Origin-Response-Status
X-Akamai-ERPolicy
Thinkindot-Cache-Type
X-Lsadc-Cache
X-Tncms-Bot-Tier
Timeexpire
X-Web-Server
X-Td-Header-From-No-Data
X-Mg-Cache