Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
X-Drupal-Cache
X-Generator
Server-Timing
P3p
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
X-Check
Permissions-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-Ua-Compatible
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
Accept-CH
X-Backend
X-Hacker
X-Turbo-Charged-By
X-Cache-Group
Cf-Apo-Via
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
X-Server
X-Dispatcher
EagleId
X-Vhost
X-Amz-Version-Id
X-UA-Device
X-AH-Environment
Accept-CH-Lifetime
X-Ws-Request-Id
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Litespeed-Cache
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Pingback
X-Cache-Lookup
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Device
X-Backend-Server
EagleEye-TraceId
X-Akam-SW-Version
X-Cloud-Trace-Context
X-Host
X-Response-Time
Surrogate-Control
Cf-Railgun
X-Readtime
X-Node
X-Server-Id
X-HW
X-LiteSpeed-Cache
Xkey
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Url
X-Nginx-Cache-Status
X-NWS-LOG-UUID
X-Application-Context
X-Content-Type
Cache-Tag
Content-Location
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
Service-Worker-Allowed
X-Trace
X-Amz-Server-Side-Encryption
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Times
X-Vname
X-TtlSet
X-PC
X-Rack-Cache
X-Mcache
X-Edge
X-Midtier
X-Country-Code
Rating
Surrogate-Key
X-Server-Name
X-Browser-Type
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Cache-TTL
X-Cnection
X-Abt-Application-Version
X-Element-Page-Cache
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-ESI
X-Oneagent-Js-Injection
Nginx-Cache
X-Ser
Edge-Control
X-GitHub-Request-Id
X-Ua-Device
X-Powered-By-Plesk
X-D2id
Verso
X-Ac
X-Dw-Request-Base-Id
X-ARC
X-Vcap-Request-Id
Accept-Ch-Lifetime
X-Client-IP
X-MS-InvokeApp
X-ECACHE
X-ORACLE-DMS-RID
X-Aspnet-Version
X-Daa-Tunnel
X-CST
X-Navigation-Version
X-Amz-Rid
X-Upstream
X-Powered-CMS
X-Middleton-Response
Response
X-Goog-Hash
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev
X-Edge-Location-Klb
X-Kinsta-Cache
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Instrumentation
X-B3-TraceId
AR-SID
AR-PoweredBy
AR-ATIME
AR-Request-ID
X-Cache-Key
X-Amzn-Trace-Id
X-Ruxit-Js-Agent
X-Forwarded-For
X-Ratelimit-Limit
X-NF-Request-ID
X-Ttl
X-Wormhole-Sdk
RTSS
X-Mod-Pagespeed
X-Ratelimit-Remaining
X-Server-ID
SPRequestDuration
SPIisLatency
Edge-Cache-Tag
Cache-Status
X-ORACLE-DMS-ECID
X-Version
AR-CACHE
Public-Key-Pins
X-Mg-S
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
S
Realpath
X-SharePointHealthScore
SPRequestGuid
X-FastCGI-Cache
X-MSEdge-Ref
Fastcgi-Cache
X-Shield-Request-Id
X-T
X-Content-Digest
X-Cached
X-Recruiting
X-Accel-Expires
Access-Control-Request-Method
X-Distributor
X-Fastly-Request-ID
X-Newrelic-App-Data
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Front-End-Https
TP-Cache
X-Correlation-Id
X-Debug
Arr-Disable-Session-Affinity
Count-Hit
X-Request-Received
X-Request-Processing-Time
X-HS-Content-Id
X-Id
X-HS-Hub-Id
X-HS-Cache-Config
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
X-Varnish-TTL
Server-Node
X-Ua-Browser
X-LLID
X-VARITI-CCR
X-Azure-Ref
X-HS-Combine-CSS
X-Frontend
X-PressLabs-Stats
Cache-Tags
X-Cluster-Name
X-Ismobilevalue
X-Hits
Accept-Ch
Payment
X-Amz-Replication-Status
X-LB-Cache
X-GUploader-UploadID
X-Varnish-Backend
X-Forwarded-Proto
X-Goog-Metageneration
X-TTL
X-Fastcgi-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Protected-By
Filterid
Host
X-FB-Debug
X-Logged-In
X-Git-Hash
X-Unique-Id
X-Www-Served-By
Content-Disposition
X-Activity-Id
X-Az
X-AppVersion
X-Varnish-Server
X-Varnish-Ttl
X-Ratelimit-Reset
Cleartype
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-App-Server
X-Hostname
X-NGENIX-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Webkit-CSP
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-DIS-Request-ID
Origin-Trial
Mrf-Cache-Status
X-Page-Id
X-B3-TraceId-Primal
MRF-Tech
Access-Control-Allow-Method
Pinterest-Version
X-Pinterest-Rid
X-Geo-Country
Pinterest-Generated-By
X-Nf-Request-Id
Retry-After
X-Origin-Server
X-Load-Cache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Cambria-Cache-Control
X-ASPNET-VERSION
X-Upgrade-Enabled
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Akamai-GRN
MS-Author-Via
X-Template
Accept-Charset
Fastly-SIE
X-Type
Fastly-SWR
X-Ah-Environment
Section-Io-Cache
X-Fb-Rlafr
X-TT
X-Cache-Control
Viewport
X-B3-Sampled
X-Content-Options
Version
Content-MD5
X-Grace
X-B
Frame-Options
Amp-Access-Control-Allow-Source-Origin
X-Xrds-Location
X-Request-Guid
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Trace-Id
X-TEC-API-ROOT
X-Revision
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cdn
X-Amz-Meta-S3cmd-Attrs
Healthy
X-Envoy-Decorator-Operation
TCN
X-Device-Type
X-Magnolia-Registration
X-RateLimit-Remaining
X-Origin-Cache
X-Contextid
X-Vcl-Version
X-CSRF-Token
X-Source
X-Rid
X-Aspnetmvc-Version
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Cache-Age
X-WP-CF-Super-Cache-Active
Server-Name
X-Backend-Name
X-Px
X-Mobile
DC
X-Proxy
X-Language
X-Seen-By
X-Varnish-Grace
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-ProcessESI
X-RM-Cache-TTL
X-RemovedCookies
X-App-Environment
X-Environment-Context
Access-Control-Request-Headers
X-Rule
X-Framework
X-Debug-Info
X-Buckets
X-Akamai-Edgescape
X-L-Path
SD-X-WS
X-Adobe-Content
X-Adobe-Loc
X-Region
X-Status
X-UUID
Cross-Origin-Window-Policy
X-Cacheable-TTL
X-Debug-IsConnected
X-Mg-Request-UUID
X-Storage
X-Debug-IsPreview
X-Node-Name
X-NYM-Debug-Backend
X-Content-Powered-By
X-G
X-ServerID
X-RTag
X-Datadog-Trace-Id
X-Datadog-Parent-Id
MS-CV
X-Proxy-Cache-Info
X-Datadog-Sampled
X-Datadog-Sampling-Priority
X-Instance
Ms-Operation-Id
NGB
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-EdgeConnect-Cache-Status
X-FW-Serve
GEO-INFO
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Version
X-ECache
X-FW-Dynamic
X-Is-Bot
X-Rendered-As
X-FW-Type
Paypal-Debug-Id
X-HTML-Minification-Powered-By
X-Cache-Time
X-User-Agent
Upgrade-Insecure-Requests
Countrycode
X-B3-Traceid
Charset
Front
Webserver
Trailer
Protected
X-Fastly-Request-Id
X-Whom
X-WebKit-CSP-Report-Only
X-Edge-Location
OT-Force-Account-Verify
X-Lambda-Id
X-VC
X-N
X-HS-Prerendered
X-VHOST
Refresh
Section-Io-Id
X-AB
X-Cache-Status-Check
X-Akamai-Request-ID2
X-IPS-LoggedIn
Country
X-TT-LOGID
X-Time
X-Reqid
Priority
Alternate-Protocol
Backend
X-Amzn-Remapped-Content-Length
X-Hcs-Proxy-Type
X-Hl-Ver
X-WP-CF-Super-Cache-Cookies-Bypass
Xet-Cookie
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Server-W
Liferay-Portal
X-CLOUD-TRACE-CONTEXT
X-Response-Served-From
X-B3-SpanId
X-Original-Request-Id
Accept-Language
X-Via-JSL
Onion-Location
SRV
X-Mode
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-Rn-Rsrv
X-Auth-Group-Type
Fastcgi-Useragent
X-Fetched-On
From-Origin
X-Real-IP
Environment
Filters
X-Web-Node
X-JoinUs
X-Wix-Request-Id
X-Rewrite-Enabled
Cross-Origin-Embedder-Policy-Report-Only
VIX-Pulpo-Node
X-SaId
X-Origin-Date
X-Skip-Cache
Meta-Geo
VIX-Pulpo-Upstream-Status
X-Request-URI
X-Nginx-Cache
X-Hosted-By
Atl-Traceid
X-IPLB-Request-ID
X-VC-Cache
X-R9-Blue-Green-Version
X-Restarts
X-Webstats-RespID
X-IPLB-Instance
X-Say-TTL
X-Frame-Option
X-Generated-By
X-Tb
X-Format
Property-Id
Expiry
X-BYPASS-REASON
ServerID
X-SayCDN-TTL
X-Say-Cacheable
X-Cache-Action
X-Connection-Hash
X-Scope-Id
X-ProxyCache-Status
TWC-GeoIP-Country
X-Cache-Expired-At
X-FB-TRIP-ID
X-Cache-Host
TWC-GeoIP-LatLong
X-ProxyCache-Key
X-Varnish-Age
TWC-Privacy
X-Accel-Version
Uber-Trace-Id
TWC-Locale-Group
X-Cluster-Node
Webcakes-Region
X-Varnish-Cache-Hits
X-Logging-Id
Webcakes-App-Version
X-Origin-Hint
TWC-Device-Class
Webcakes-App-Name
TWC-Connection-Speed
X-Forwarded-Host
X-DataDome
X-Handled-By
X-PHP-Host
X-Director
X-Served-From
X-Soup
X-Httpd
X-Redis-Cache
Mn-Server-Ip
X-Cms-Context
X-Labrador-Cache-Channel
Apigw-Requestid
X-Adobe-Source
X-Varnish-Beresp-Grace
Selected-Fe
Web-Mar-Node
X-Loop
X-Proxy-Build
DB-Nickname
X-Vcache
X-Tncms
X-Timing-Wait
X-S
X-Detected-As
X-Proxied
Url
ServedBy
X-Zipkin-Id
X-Extlb
X-Origin-TTL
X-Origin
X-Cluster
X-Origin-CC
X-Cloudmap
X-Servername
X-Routing-Service
LB
Xserver
N-Cache
X-LSADC-Cache
X-TraceId
Referer-Policy
X-XRDS-Location
X-Rocket-Nginx-Serving-Static
X-Hit
Cross-Origin-Embedder-Policy
X-Webkit-Csp
CF-IPCountry
X-Ms-Version
X-Ms-Request-Id
X-FTR-Request-ID
X-Xfnlog-Site
X-Lagoon
X-SRV
X-Tumblr-Pixel-3
X-NWS-UUID-VERIFY
X-DynaTrace
X-XRDS-LOCATION
X-RID
X-Upstream-Ht
X-Upstream-Ct
X-VCT
X-Azure-Ref-OriginShield
X-Cache-Debug
Source
WPO-Cache-Status
WPO-Cache-Message
X-Proxy-Cache-Status
X-RCS-CacheZone
CDN-RequestId
X-UA
X-Worker
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Surrogated-Key
X-Is-Mobile
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Desktop
X-Browser-Name
X-Tcp-Rtt
X-Geo-Region
X-Signature
X-Urbn-Context-Path
X-F-Cache
X-No-Session
X-Urbn-Site-Id
X-B-Cache
Locale
X-Generation-Time
Node
X-Sucuri-Cache
X-Cdn-Origin
X-RateLimit-Limit
X-App-Version
X-Sucuri-ID
X-NODE
X-Alternate-Cache-Key
X-Drupal-Cache-Tags
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Drupal-Cache-Contexts
X-Tx-Id
X-Cdn-Forward
X-MP-GENERATED-AT
Ohc-File-Size
Cross-Origin-Opener-Policy-Report-Only
X-Cache-Rule
X-Site-Version
X-Locale
X-Cache-Operation
Azure-Version
X-Ec-Fail
BehaviorPad-Version
X-Ec-GeoHdr
X-ElasticPress-Query
X-Loc
X-DPWN-IS-SECURE
Azure-SlotName
Candidate-Md5Url
X-Jobs
Azure-InstanceId
X-GeoCountry
X-GeoCode
X-GeoIP
X-A-Dgt
X-Ig-Push-State
X-GeoIP-City
X-Developer
X-Internal-TTL
X-Ig-Origin-Region
Azure-RegionName
X-Epic-Correlation-Id
A
X-Gdpr
Azure-SiteName
Cdnsip
X-Bc-Bl
Sslversion
TDXMobile
Thinkindot-CacheControl
X-BCube-Filmed-By
X-Bug-Bounty
Producers
Redirect-Candidate
Rendered-Blocks
Thinkindot-CacheControl-Type
X-App-Name
X-A
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Wwc
X-Aed
X-Amz-Storage-Class
X-AK-Request-ID
X-Aicache-OS
X-Cache-Info
Origin-Agent-Cluster
Content-Secure-Policy
DCR-Decision-By
DCR-Processing-Time-Ms
Expect-Staple
Cluster
X-D
X-DefElseHash
Cdncip
X-Mly-Id
Fastly-GeoIP-CountryCode
Gannett-Cam-Experience-Id
Ngx.Var.Host
Odigeo-Trace-Id
X-Cache-NE
Meta-Geo-Continent
MD5-Digest
X-Conf
Host-ID
Lang
X-DefHash
X-FC-Vary-Parameters
X-PAYTM-SRV-ID
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Platform-Server
X-Origin-Time
X-Origin-Response-Time
X-ScT
X-Vmg-Version
X-Origin-Expires
X-Vtex-Remote-Cache
X-Service
X-Proto
X-Proxied-Request
AMP-Access-Control-Allow-Source-Origin
Xc-Version
X-TIM-N
X-Rojux
X-Request-Time
X-Thinkindot-L3
X-Org
X-Scheme
X-Varnish-Remaining-TTL
X-NGINX-Cache
X-Nyt-Route
X-Vdms-Version
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-Shield-Cache-Expires
X-Varnish-Beresp-Ttl
X-Optimistic-Header
Mime-Version
NM-Fastcgi-Cache
NGX
X-V-Cache
X-Slack-Backend
Esi-Enabled
PFcat
Origin-EX
Origin-CC
X-UA-Device-Type
Fastly-Backend-Name
L
X-Cache-Id
Gh-Request-Id
X-CGP
Ha-Gx-Prefs
X-Clientip
HA-Ipaddr
X-SVT-ORM-RULES
X-Contensis-Viewer-Groups
X-Slack-Shared-Secret-Outcome
X-Cached-By
X-SVT-ORM-VERSION
X-CacheTTL
X-Content-Age
L5d-Success-Class
X-Sn-Servicetimems
Mail-Subject
RNT-Machine
X-Varnish-Director
X-VarnishDD-TTL
X-Acquia-Purge-Cdn-Unconfigured
X-Akamai-Device-Characteristics
Tube-Return
Tube-Got-Eval
Tube-Got-Results
X-Access
W
X-Varnishpool
X-Viewer-Country
X-VG-WebCache
Wxu-Next-Region
Wxu-Next-Hostname
We-Hiring
Wxu-Next-Commit
Tube-Get-Contents
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Aspx
Req-Svc-Chain
X-Core-Value
X-We-Are-Hiring
Release
Product
X-Cache-Bucket
RNT-Time
X-Varnish-Authentication
X-Auto-Login
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Backend-Instance
X-BBC-Edge-Cache-Status
Server-Host
X-Bl-Debug
Platform
X-Csrf-Jwt
X-Gamma-Serve
X-Fmm-Version
X-Via-Fastly
X-Pool
X-Policy
X-Platform
X-Generated-On
X-Fastly-Backend
X-Powered-By-VTEX-Cache
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Edge-Server
Yak-Timeinfo
X-Eu-Site
X-Esi-Check
X-Path
X-GeoIP-Country-Code
X-Node-Id
X-INCAP-ABP
X-Op-Id-All
X-NMSegId
X-Pad
X-Location
X-Level-Front-Cache
X-Human
X-HS-Content-Campaign-Id
X-GoCache-CacheStatus
X-GeoIP-Region-Code
X-Gzip
Origin
X-HN
X-Hash
Apple-News-Services-Request-Url
XkeyRZ
X-Depends
Cdn-Request-Time
Cdn-Host
X-Section
Content-Script-Type
X-SB
Click-Count-Error
X-SD-PageType
Click-Count-Action-Start
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Ec-Custom-Error
X-Dispatcher-Server
X-Req
Cache
Debug
X-Proxy-CacheRZ
DSUID
Cache-Provider
Content-Style-Type
Canary
TP-L2-Cache
X-VG-TLSProxy
X-Date
X-Men
X-NodeID
X-Accel-Expires-Debug
IsBot
X-CUA
X-Server-IP
X-Micro-Cache
X-Hnp-Log
X-AB-Test
X-Content-Length
X-Request-Host
X-Request-Start
X-Var-Ttl
X-Pubstack
X-Cache-FS-Status
X-Wikidot-Backend
X-Block-Status
X-Bip
X-Cache-Grace
X-Tb-Optimization-Total-Bytes-Saved
X-SIPLIST1
X-Gen-Mode
X-Thanos
X-Wikidot-Static-Cache
X-Varnish-Beresp-Status
X-Cdn-Srv
X-B3-Trace-ID
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
Country-Code
Fastly-SSL
Req-ID
Pramga
CDN-RequestCountryCode
CDN-PullZone
Cache-Key
X-Newrelic-Synthetics
CDCHOST
CDN-Cache
CDN-EdgeStorageId
CDN-CachedAt
ServerName
Sid
User-Cache-Control
Web-Mar-Region
User-Agent
Ssr
V-Age
X-Cache-Hit
Akamai-Mon-Iucid-Del
XM
X-Irp-Debug
X-HOST
Fl-Custom-Application
X-ORCA-Accelerator
X-Api-Version
X-Varnish-Hits
X-CACHE-GROUP
X-LiteSpeed-Cache-Control
X-Dc
X-Cs
X-HS-CF-Cache-Status
X-LB-NoCache
X-LiteSpeed-Tag
X-AWS-Id
X-GEO
X-LJ-Flow-ID
X-TA-CDN-Provider
True-Client-Country-4JS
X-VWS-Id
X-Air-Pt
Server-Hostname
X-Test
X-HITS
X-Provided-By
Sever-Int
Server-Ext
C-Via
X-Nananana
Eagleid
GeoIP-Latitude
CloudFront-Viewer-Country
X-Geolocation
X-Cache-Date
X-Refresh
X-RequestId
X-B3-Spanid
X-VServer
X-Servedbyhost
Fastly-Drupal-HTML
X-Litespeed-Tag
X-Via-CDN
X-S-Cookie
X-DC
X-Via-Edge
X-Application
X-Destination
X-APP
Edge-Copy-Time
Is-Eu
X-IsAdmin
X-External-Request-Id
X-B-Cookie
X-Via-SSL
Proxy-Firewall
X-B3-Parentspanid
Adler-Geo
X-HA-Backend
X-Via-Popv
X-Tt-Logid
X-Via-Poph
X-Zen-Fury
X-Dispatcher-Number
X-Nginx-Cache-Key
X-Zone
X-Via-Popn
Cdn-Requestid
X-Endurance-Cache-Level
S-Rt
X-ZONE
X-LB-ID
X-User
WZWS-RAY
X-Nc
Fastly-Drupal-Html
X-Wa
Cache-Tv-Group
X-DynaTrace-JS-Agent
X-Geo-Header
X-Webkit-Csp-Report-Only
HostName
X-Custom-Header
Server-ID
T-Server
X-Presslabs-Stats
X-CDN-Forward
X-Srv
Cdn
X-AIR-PT
X-Pass-Why
X-COUNTRY
X-Oracle-Dms-Ecid
X-URL
X-ND-Cache
X-CS
Ohc-Cache-HIT
X-VC-TTL
Vc-Max-Age
X-Cache-Server
X-CMSURLCustom
GeoIp-Country-Code
X-HubSpot-Correlation-Id
X-CACHE-AGE
X-Parent-Response-Time
X-Vgn-Hpd-Reason
X-TH-Server
X-Fpc
SID
X-Swift-Savetime
X-Swift-Cachetime
X-Moov-Xdn-Caching-Status
WP-Super-Cache
X-Moov-Xdn-Version
X-Moov-T
X-NewRelic-App-Data
True-Client-IP
Resin-Trace
X-DataCenter
X-API-Version
Vix-Hermes-Req-Id
X-Old-Content-Length
Pics-Label
Powered-By
X-Varnish-Beresp-TTL
SEZNAM-JOBS-OFFER
Uri
X-Fastly-Cache
True-Client-Ip
X-Ckpd-Fst-Backend
X-Datadome
X-Srcache-Store-Status
X-Srcache-Fetch-Status
On-Server
X-APP-VERSION
Srv
X-SERVER-NAME
X-Vercel-Cache
X-Vercel-Id
ServerHost
GeoIP-Country-Code
Serverhost
X-Cache-VC
X-Thinkindot-L1
X-TX-ID
X-FPC
Thinkindot-Control
Location
X-Client-Ip
X-FTR-Balancer
AKAMAI
X-Cache-TTL-Remaining
X-PHP-Backend
X-Action
X-FTR-Expires
X-Amz-Meta-Opti
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-Country-Code-Real
X-Air-Source
X-Air-Hostname
X-Dynatrace-Js-Agent
X-Air-Trace-Id
X-Oracle-Dms-Rid
N1-Cache
X-Stale
Server-Id
X-Info
Magicmarker
Av-Poweredby
Hostname
X-Debug-Service
X-Cdn-Cache-Status
X-Datacenter
Cl-Cache
X-Resp-Is-Stale
X-ApacheServer
X-Fastly-Backend-Reqs
X-Fastly-Cache-Status
X-PERF
X-WA
X-NC
X-Vc
X-Service-Response-Time
Sm-Log-Id
X-VCL-Version
Tcn
X-Ssense-Gql
X-Litespeed-Cache-Control
X-Ssense-Shipping-Surcharge-Enabled
X-V
X-Nitro-Cache
X-Udemy-Cache-App-Namespace
X-Ee-Generated-By
X-Cms-Device
X-Ee-Origin
X-CDN-Cache-Status
X-Ee-Request-Id
X-WA-Info
X-Lb-Id
X-Save-Cache
X-Render-Time
X-Vary-Devices
X-Ee-Request-Date
Xkey-La3
X-Proxy-Cache-La3
X-VTEX-Cache-Backend-Header-Time
X-IAuth-Set-Uid
X-Geo
X-VTEX-Cache-Backend-Connect-Time
Store-Cloud-Cache
Time-Cloud-Cache
Xkeylog
X-Cache-Ttl
CDN
X-New
X-Uri
TWC-GeoIP-Region
X-Github-Request-Id
X-Oracle-DMS-ECID
X-App
X-Rollout
TWC-GeoIP-City
TWC-GeoIP-DMA
X-Ha-Backend
Cache-Hits
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Eligible
X-Esi
X-Ua
X-Forwarded-Site
X-Region-Sid
X-ServedByHost
Machine
Geoip-Latitude
X-Limited
Cloudfront-Viewer-Country
X-Ion-Hop
X-Jungle-Id
RewriteTestHook
X-Ion-Healthy
RewriteTeamHook
Cache-Contol
X-Akamai-Pragma-Client-IP
WWW-Authenticate
My-App
Log-Origin
Cmsid
X-Lb-Nocache
Cmstype
X-Traceid
WebServer
Server-Info
Cneonction
CountryCode
X-Correlation-ID
Pragrma
X-Container-Uri
X-MSEdge-Flight
X-MSEdge-Features
X-LAGOON
X-Dw-Trace-Id
X-EC-Lua
Cf-Ipcountry
X-From
X-Git-Commit
Edge-Cache
X-Requestid
X-Up
X-Ftr-Request-Id
X-Acquia-Site
X-Check-Cacheable
X-Acquia-Purge-Tags
Lb
X-HS-Status
X-Acquia-Application-Trace
Reporter
X-Acquia-Application-UUID
X-Cdn-Request-ID
X-Serial
X-Akamai-Transformed
X-SRCache-Key
FSS-Cache
Permission-Policy
X-Pod
X-Varnish-Hostname
X-Sucuri-Id
X-Html-Minification-Powered-By
Timeexpire
X-Elasticpress-Query
X-Ms-Blob-Type
CacheControlHeader
X-BBC-Origin-Response-Status
X-Ms-Lease-Status
X-Fastly-Cache-Hits
X-Akamai-ERPolicy
X-Orig-Cache-Control
X-Tncms-Bot-Tier
X-Platform-Cluster
X-Platform-Processor
PICS-Label
X-Ramcache
CF-Cached-On
X-Platform-Router
X-Akamai-ERRuleID
Warning