Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
X-XSS-Protection
Alt-Svc
Report-To
NEL
X-Xss-Protection
Referrer-Policy
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
P3p
X-Ua-Compatible
X-Request-ID
X-FRAME-OPTIONS
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-Drupal-Dynamic-Cache
Feature-Policy
Accept-CH-Lifetime
X-Content-Security-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Age
X-Cache-Group
X-Vhost
X-Proxy-Cache
EagleId
X-Turbo-Charged-By
Keep-Alive
X-Rq
X-Via
X-Dispatcher
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
Xkey
X-Varnish-Cache
X-WebKit-CSP
X-Litespeed-Cache
Grace
X-Server-Powered-By
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
Allow
X-Dns-Prefetch-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Check
X-Device
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-HW
X-Node
Request-Id
X-Ruxit-JS-Agent
X-Server-Id
X-LiteSpeed-Cache
X-Country-Code
X-Country
Content-Location
X-Nginx-Cache-Status
Cache-Tag
X-Content-Type
X-Nginx-Upstream-Cache-Status
X-Url
Service-Worker-Allowed
Fastly-Restarts
X-Clacks-Overhead
X-Trace
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Application-Context
X-Amz-Server-Side-Encryption
X-Times
X-NWS-LOG-UUID
Surrogate-Key
X-Vname
X-TtlSet
X-PC
Rating
X-Mcache
X-Midtier
X-Edge
X-Server-Name
X-Cache-TTL
X-Middleton-Display
Pagespeed
Display
X-Sol
X-Oneagent-Js-Injection
X-Cnection
X-Powered-By-Plesk
X-Element-Page-Cache
X-Abt-Application-Version
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Browser-Type
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-GitHub-Request-Id
X-ESI
Nginx-Cache
X-Vcap-Request-Id
Edge-Control
X-ECACHE
X-Ruxit-Js-Agent
X-D2id
X-Ac
X-ORACLE-DMS-RID
Verso
X-MS-InvokeApp
X-Ser
X-Server-ID
X-Client-IP
X-Amz-Rid
X-Ratelimit-Limit
Response
X-Middleton-Response
X-Wormhole-Sdk
X-Ratelimit-Remaining
X-FTR-Request-ID
X-Goog-Hash
X-CST
X-ARC
X-Powered-CMS
X-B3-TraceId
X-Navigation-Version
X-Edge-Location-Klb
X-Dw-Request-Base-Id
X-Kinsta-Cache
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Upstream
X-Forwarded-For
Origin-Trial
X-Amzn-Trace-Id
X-FastCGI-Cache
SPRequestDuration
SPIisLatency
X-Mod-Pagespeed
X-Cache-Key
X-Content-Digest
Edge-Cache-Tag
Cache-Status
RTSS
Public-Key-Pins
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-SID
X-Ezoic-Cdn
X-NF-Request-ID
SPRequestGuid
X-Version
X-SharePointHealthScore
X-Ttl
X-Daa-Tunnel
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Fastly-Request-ID
Realpath
X-Mg-S
X-Recruiting
X-MSEdge-Ref
X-ORACLE-DMS-ECID
X-T
X-Shield-Request-Id
Front-End-Https
S
Fastcgi-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Accel-Expires
X-Distributor
Cross-Origin-Resource-Policy
X-Cached
AR-CACHE
X-Xrds-Location
Arr-Disable-Session-Affinity
X-Azure-Ref
X-TTL
Access-Control-Request-Method
X-Varnish-TTL
Akamai-GRN
X-Request-Processing-Time
X-Request-Received
X-Correlation-Id
Cache-Tags
Count-Hit
X-HS-Cache-Config
X-Id
X-HS-Content-Id
X-HS-Hub-Id
TP-Cache
X-Ua-Browser
X-Debug
X-Cluster-Name
X-Ismobilevalue
X-TraceId
X-LLID
X-NGENIX-Cache
X-Nf-Request-Id
Server-Node
MicrosoftSharePointTeamServices
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Varnish-Backend
X-Frontend
X-Newrelic-App-Data
X-PressLabs-Stats
X-VARITI-CCR
Accept-Ch
X-Protected-By
X-HS-Combine-CSS
X-Amz-Replication-Status
X-Hits
X-Goog-Metageneration
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
X-Unique-Id
X-Ratelimit-Reset
X-DIS-Request-ID
Payment
Cleartype
X-Git-Hash
X-FB-Debug
X-Logged-In
X-Varnish-Server
X-Hostname
X-Www-Served-By
Content-Disposition
X-Tt-Trace-Host
X-Az
X-AppVersion
X-Activity-Id
X-Tt-Trace-Tag
X-HP-Trace-Id
X-Jurisdiction
X-Cambria-Cache-Control
X-HP-Webp
X-Template
Host
X-Amzn-RequestId
X-Amz-Apigw-Id
Filterid
Amp-Access-Control-Allow-Source-Origin
X-Forwarded-Proto
X-Fastcgi-Cache
X-Geo-Country
X-App-Server
X-Varnish-Ttl
Version
X-Aspnet-Version
Accept-Charset
X-Load-Cache
X-ASPNET-VERSION
X-Envoy-Decorator-Operation
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Trailer
X-Source
Frame-Options
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Type
Fastly-SIE
X-Ah-Environment
Fastly-SWR
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Content-Options
Viewport
Section-Io-Cache
X-HS-Prerendered
X-TT
X-Fb-Rlafr
Server-Name
X-Origin-Server
X-B3-Sampled
X-B
X-Grace
X-Language
X-Cache-Age
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Expires
X-Cache-Control
X-Device-Type
X-Buckets
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Rid
X-Px
X-TEC-API-ORIGIN
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Cdn
X-TEC-API-ROOT
MS-Author-Via
X-TEC-API-VERSION
Retry-After
Content-MD5
X-Magnolia-Registration
X-Mobile
X-Request-Guid
X-Vcl-Version
TCN
X-Trace-Id
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Revision
Protected
X-Akamai-Edgescape
Healthy
X-WP-CF-Super-Cache-Active
X-Backend-Name
Cross-Origin-Embedder-Policy-Report-Only
X-Proxy
Charset
Upgrade-Insecure-Requests
X-Response-Served-From
X-App-Environment
SD-X-WS
X-Instance
X-Original-Request-Id
X-RM-Cache-TTL
X-Debug-Info
X-Rendered-As
X-Is-Bot
X-ProcessESI
X-Tumblr-User
X-RemovedCookies
X-Tumblr-Pixel-0
X-NYM-Debug-Backend
X-ServerID
X-Tumblr-Pixel-1
X-Status
X-Tumblr-Pixel
Cross-Origin-Window-Policy
X-Cacheable-TTL
X-FW-Version
X-FW-Type
X-FW-Static
X-Mg-Request-UUID
X-Region
X-Storage
X-Rule
X-FW-Server
X-FW-Serve
X-Cache-Time
X-Adobe-Loc
X-Adobe-Content
X-CSRF-Token
X-Framework
X-FW-Hash
X-FW-Dynamic
NGB
Access-Control-Request-Headers
X-Node-Name
X-UUID
X-Yottaa-Optimizations
X-Edge-Location
X-Debug-IsPreview
Refresh
X-Whom
X-Yottaa-Metrics
X-Datadog-Trace-Id
X-Debug-IsConnected
X-Content-Powered-By
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Sampled
X-G
OT-Force-Account-Verify
GEO-INFO
Ms-Operation-Id
MS-CV
X-RTag
X-Proxy-Cache-Info
X-Environment-Context
X-L-Path
X-Lambda-Id
X-Resp-Is-Stale
Section-Io-Id
X-Contextid
Webserver
X-B3-Traceid
X-Reqid
X-Amzn-Remapped-Content-Length
X-TT-LOGID
DC
Countrycode
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-User-Agent
X-Origin-Cache
X-Server-W
Paypal-Debug-Id
X-HTML-Minification-Powered-By
X-Amz-Meta-S3cmd-Attrs
X-ECache
Alternate-Protocol
X-Real-IP
X-Time
X-HS-CF-Cache-Status
X-WebKit-CSP-Report-Only
Priority
SRV
Cross-Origin-Opener-Policy-Report-Only
Front
X-DataDome
X-B3-SpanId
X-VC
X-Seen-By
Ohc-File-Size
WPO-Cache-Message
WPO-Cache-Status
Accept-Ch-Lifetime
X-WP-CF-Super-Cache-Cookies-Bypass
Liferay-Portal
X-Hl-Ver
X-Rocket-Nginx-Serving-Static
X-Mode
Backend
X-Origin-CC
X-Origin-TTL
Xet-Cookie
X-IPS-LoggedIn
Onion-Location
X-Akamai-Request-ID2
Filters
X-Say-Cacheable
Fastcgi-Useragent
X-SaId
X-Tumblr-Pixel-2
ServerID
X-Rn-Rsrv
TWC-GeoIP-Country
Meta-Geo
TWC-Device-Class
TWC-Connection-Speed
Property-Id
X-Redis-Cache
X-Origin-Hint
TWC-Locale-Group
X-FB-TRIP-ID
X-Cache-Action
X-AB
X-UPSTREAM-Address
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
Web-Mar-Node
X-JoinUs
X-RateLimit-Remaining
X-Tumblr-Pixel-3
X-Rewrite-Enabled
X-Cache-Host
X-Format
TWC-GeoIP-LatLong
X-SayCDN-TTL
X-Say-TTL
X-Ms-Version
Expiry
X-Labrador-Cache-Channel
X-Detected-As
X-Fetched-On
X-Cache-Expired-At
X-Ms-Request-Id
X-Loop
X-Accel-Version
X-Cms-Context
X-Cluster-Node
Country
X-Connection-Hash
X-Director
X-VC-Cache
X-IPLB-Instance
X-Soup
X-Skip-Cache
X-Tncms
X-IPLB-Request-ID
X-Handled-By
X-Scope-Id
X-Hosted-By
X-Restarts
X-Vcache
Mn-Server-Ip
X-Origin-Date
Uber-Trace-Id
X-Varnish-Age
X-R9-Blue-Green-Version
X-PHP-Host
From-Origin
DB-Nickname
X-DynaTrace
X-Cache-Status-Check
X-N
X-Nginx-Cache
Environment
X-Servername
Url
X-ProxyCache-Key
X-Frame-Option
X-Forwarded-Host
Atl-Traceid
X-Web-Node
X-Logging-Id
X-Adobe-Source
Apigw-Requestid
X-Varnish-Beresp-Grace
X-Tb
X-BYPASS-REASON
X-Webstats-RespID
X-Varnish-Cache-Hits
X-ProxyCache-Status
X-Served-From
Selected-Fe
ServedBy
X-Httpd
X-Timing-Wait
X-Cluster
X-Proxy-Build
X-Auth-Group-Type
X-Cloudmap
X-Extlb
X-Routing-Service
X-Zipkin-Id
X-S
X-Proxied
X-Hit
X-Azure-Ref-OriginShield
X-Origin
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Surrogated-Key
X-Worker
Cross-Origin-Embedder-Policy
X-LSADC-Cache
LB
X-SRV
X-CDN-Forward
X-Cache-Hit
X-Request-URI
Accept-Language
X-Lagoon
X-Sucuri-Cache
Referer-Policy
X-Generation-Time
X-Drupal-Cache-Tags
N-Cache
X-Drupal-Cache-Contexts
X-Fastly-Request-Id
X-Generated-By
X-Cdn-Origin
X-App-Version
X-Sucuri-ID
Xserver
X-MP-GENERATED-AT
CDN-RequestId
CF-IPCountry
X-Oracle-Dms-Ecid
X-XRDS-Location
X-URL
Ohc-Cache-HIT
X-Xfnlog-Site
X-Tx-Id
X-F-Cache
X-TA-CDN-Provider
Node
Source
X-VC-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-AIR-PT
X-Mly-Id
Edge-Copy-Time
X-Via-CDN
X-Via-SSL
Cache
X-Via-Edge
X-Wix-Request-Id
X-Cache-Debug
X-NODE
X-Cache-Rule
X-RCS-CacheZone
X-Varnish-Beresp-Ttl
X-INCAP-ABP
X-UA
Cache-Provider
X-Pad
X-Site-Version
X-VCT
X-Locale
X-GEO
X-ElasticPress-Query
Wxu-Next-Region
Wxu-Next-Hostname
Web-Mar-Region
We-Hiring
Wxu-Next-Commit
Mail-Subject
Expect-Staple
DCR-Processing-Time-Ms
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Fl-Custom-Application
Fastly-SSL
DCR-Decision-By
Cluster
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Request-Url
BehaviorPad-Version
Candidate-Md5Url
Ha-Gx-Prefs
HA-Ipaddr
Origin
Odigeo-Trace-Id
PFcat
Producers
Rendered-Blocks
Redirect-Candidate
Ngx.Var.Host
Meta-Geo-Continent
L5d-Success-Class
Host-ID
Lang
X-A
MD5-Digest
Sslversion
X-Bug-Bounty
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Mobile
X-Jobs
X-Mvc-Supplant-Cachable
X-Org
X-Op-Id-All
X-Nyt-Route
X-Is-Desktop
X-Ig-Push-State
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-GeoCountry
X-Geolocation
X-HN
X-Ig-Origin-Region
X-HS-Content-Campaign-Id
X-Origin-Time
X-Path
X-Tcp-Rtt
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-VarnishDD-TTL
X-Vdms-Version
Xc-Version
X-Vtex-Remote-Cache
X-Section
X-SD-PageType
X-Proto
X-Platform-Server
X-PAYTM-SRV-ID
X-Proxied-Request
X-Rojux
X-ScT
X-S-Cookie
X-GeoCode
X-Geo-Region
X-BCube-Filmed-By
X-Bc-Bl
X-Backend-Instance
X-Bl-Debug
X-Browser-Name
X-Cache-Grace
Apple-News-Services-Handled
X-B-Cookie
X-Application
X-A-Dgt
X-A-Dcw
X-A-Dam
X-A-Wwc
X-Access
X-Aicache-OS
X-Aed
X-Cache-NE
X-Cache-Operation
X-Ec-GeoHdr
X-Ec-Fail
X-DPWN-IS-SECURE
X-Eu-Site
X-External-Request-Id
X-Gdpr
X-FC-Vary-Parameters
X-Developer
X-Destination
X-Conf
X-CGP
X-Cached-By
X-Csrf-Jwt
X-D
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-A-Ccd
X-AB-Test
X-Urbn-Context-Path
X-NWS-UUID-VERIFY
X-Urbn-Site-Id
Locale
X-NGINX-Cache
X-No-Session
X-Core-Value
X-CUA
X-Date
X-Content-Length
X-Clientip
X-CacheTTL
X-DefElseHash
X-Content-Age
X-DefHash
X-Fastly-Backend
X-Fmm-Version
X-Generated-On
X-Esi-Check
X-Epic-Correlation-Id
X-Dispatcher-Server
X-Ec-Custom-Error
X-Cache-Info
X-Cache-Id
X-Accel-Expires-Debug
X-AK-Request-ID
X-Akamai-Device-Characteristics
V-Age
User-Cache-Control
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Amz-Meta-Cb-Modifiedtime
X-Amz-Storage-Class
X-BBC-Edge-Cache-Status
X-Block-Status
X-Cache-Date
X-B3-Trace-ID
X-B-Cache
X-App-Name
X-Auto-Login
X-GeoIP
X-GeoIP-City
X-V-Cache
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-User
X-Thinkindot-L3
X-Scheme
X-Shield-Cache-Expires
X-Signature
X-Varnish-Director
X-Varnish-Remaining-TTL
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Zen-Fury
X-VServer
X-Vmg-Version
X-VG-WebCache
X-Via-Fastly
X-Viewer-Country
X-SB
X-Request-Time
X-Loc
X-Location
X-Micro-Cache
X-Level-Front-Cache
X-Human
X-Gzip
X-Hash
X-Hnp-Log
X-Mvc-Supplant-OutputCached
X-NMSegId
X-Policy
X-Powered-By-VTEX-Cache
X-Req
X-Platform
X-Origin-Expires
X-Node-Id
X-NodeID
Server-Host
X-Gen-Mode
Azure-InstanceId
Azure-RegionName
NM-Fastcgi-Cache
Cdncip
Content-Script-Type
L
Azure-SiteName
Product
Canary
CDCHOST
Origin-Agent-Cluster
Platform
Azure-SlotName
Azure-Version
Content-Style-Type
Cdnsip
RNT-Machine
Debug
Gh-Request-Id
Gannett-Cam-Experience-Id
Req-Svc-Chain
RNT-Time
Akamai-Mon-Iucid-Del
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-COUNTRY
X-Ua-Device
Cdn-Host
X-Request-Host
X-Request-Start
X-Thanos
Content-Secure-Policy
X-IsAdmin
X-GoCache-CacheStatus
X-Depends
X-Internal-TTL
X-Cache-Aspx
X-Pool
Origin-CC
X-Cache-FS-Status
X-TIM-N
X-Litespeed-Tag
X-Men
DSUID
Cdn-Request-Time
X-Contensis-Viewer-Groups
NGX
X-Edge-Server
X-Server-IP
Click-Count-Action-Start
X-HITS
X-Origin-Response-Time
X-Gamma-Serve
Country-Code
X-Cdn-Srv
X-Pubstack
Click-Count-Error
X-Sn-Servicetimems
Origin-EX
X-UA-Device-Type
Tube-Got-Results
Tube-Return
Tube-Got-Eval
Release
W
X-We-Are-Hiring
X-Wikidot-Backend
Req-ID
Yak-Timeinfo
XM
X-Wikidot-Static-Cache
X-Acquia-Purge-Cdn-Unconfigured
Tube-Get-Contents
X-Varnish-Beresp-Status
X-TH-Server
X-VG-TLSProxy
X-Varnish-Authentication
ServerName
X-Bip
Mime-Version
X-Via-JSL
X-Service
X-Irp-Debug
IsBot
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestPullCode
User-Agent
CDN-RequestPullSuccess
X-Vgn-Hpd-Reason
Ssr
X-LB-NoCache
CDN-Uid
CDN-EdgeStorageId
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-SIPLIST1
X-HOST
X-RID
CDN-Cache
CDN-CachedAt
X-Tb-Optimization-Total-Bytes-Saved
Fastly-Drupal-HTML
X-Moov-Xdn-Version
X-Varnishpool
X-Varnish-Hits
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Var-Ttl
X-Old-Content-Length
X-CACHE-GROUP
Sid
N1-Cache
Pramga
GeoIP-Latitude
X-NewRelic-App-Data
X-DC
X-Api-Version
X-Proxy-Cache-Status
X-ZONE
X-ORCA-Accelerator
X-RequestId
X-Servedbyhost
X-Cs
CloudFront-Viewer-Country
X-Refresh
X-HubSpot-Correlation-Id
X-Presslabs-Stats
X-Action
X-Wa
Esi-Enabled
X-APP
X-Nc
TWC-GeoIP-Region
TWC-GeoIP-DMA
TWC-GeoIP-City
X-Via-Poph
X-Upstream-Ct
X-Via-Popn
X-LiteSpeed-Tag
X-Thinkindot-L1
Cache-Hits
C-Via
X-Upstream-Ht
X-Via-Popv
X-HA-Backend
Location
X-Vercel-Cache
X-Cache-VC
Server-ID
X-Vercel-Id
X-Newrelic-Synthetics
X-Cache-Bucket
X-CACHE-AGE
Cdn-Requestid
X-LiteSpeed-Cache-Control
X-Dc
X-Webkit-CSP
XkeyRZ
AMP-Access-Control-Allow-Source-Origin
A
X-Parent-Response-Time
Cache-Key
X-Nananana
X-Proxy-CacheRZ
X-B3-Parentspanid
X-LB-ID
X-Tt-Logid
X-CS
X-DynaTrace-JS-Agent
X-B3-Spanid
X-ApacheServer
X-Zone
X-PERF
HostName
X-Webkit-Csp
WP-Super-Cache
X-Endurance-Cache-Level
X-Ua
Fastly-Drupal-Html
X-DataCenter
SID
X-WA-Info
X-Render-Time
X-Srv
X-Nitro-Cache
X-Uri
GeoIp-Country-Code
X-Fpc
X-Webkit-Csp-Report-Only
Proxy-Firewall
X-Litespeed-Cache-Control
X-API-Version
RewriteTeamHook
Uri
X-Ion-Healthy
X-Ion-Hop
X-Jungle-Id
RewriteTestHook
Cache-Contol
X-Cdn-Forward
True-Client-IP
My-App
TP-L2-Cache
Log-Origin
Cmsid
Cmstype
Resin-Trace
Server-Ext
X-Up
X-From
Sever-Int
True-Client-Country-4JS
Server-Hostname
True-Client-Ip
X-Datadome
Sm-Log-Id
X-Optimistic-Header
X-Service-Response-Time
X-Ssense-Shipping-Surcharge-Enabled
X-CLOUD-TRACE-CONTEXT
GeoIP-Country-Code
X-Ssense-Gql
X-Test
CacheControlHeader
X-SERVER-NAME
X-Stale
Tcn
SEZNAM-JOBS-OFFER
X-Datacenter
X-Udemy-Cache-App-Namespace
X-Dispatcher-Number
Cdn
Is-Eu
Adler-Geo
X-Dynatrace-Js-Agent
X-Client-Ip
X-Pass-Why
X-Varnish-Beresp-TTL
X-RateLimit-Limit
WZWS-RAY
X-Nginx-Cache-Key
X-FPC
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Hostname
Srv
X-APP-VERSION
X-Oracle-Dms-Rid
Lb
X-Vc
X-Air-Pt
X-Geo-Header
Origin-Site
X-Air-Trace-Id
X-Air-Hostname
X-Debug-Service
T-Server
X-Fastly-Cache-Status
X-Air-Source
X-Custom-Header
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
X-TX-ID
X-Lb-Id
X-SRCache-Key
Server-Id
X-Varnish-Hostname
X-ND-Cache
X-Provided-By
X-CMSURLCustom
X-Cache-Server
Edge-Cache
Serverhost
AKAMAI-GRN
Cf-Ipcountry
Vc-Max-Age
NtCoent-Length
X-App
X-Akamai-Pragma-Client-IP
X-Correlation-ID
X-VCL-Version
X-Fastly-Backend-Reqs
X-Cache-Ttl
Pics-Label
X-NC
X-Ha-Backend
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Html-Minification-Powered-By
X-Oracle-DMS-ECID
X-WA
Pragrma
ServerHost
X-Esi
X-XRDS-LOCATION
X-Sigma
Machine
X-Sigma-Backend
YJS-ID
Epwk-X-Cache
X-Cdn-Cache-Status
Powered-By
X-Region-Sid
Geoip-Latitude
X-Forwarded-Site
X-Rocket-Build-Number
S-Rt
Av-Poweredby
X-LAGOON
Cloudfront-Viewer-Country
X-ServedByHost
Nord-Request-ID
X-Requestid
WebServer
X-Cache-TTL-Remaining
Ms-Author-Via
Cache-Tv-Group
Vix-Hermes-Req-Id
X-Traceid
WWW-Authenticate
CountryCode
X-MSEdge-Features
X-Fastly-Cache
MIME-Version
X-Sucuri-Id
X-Ckpd-Fst-Backend
Warning
X-MSEdge-Flight
Xkey-La3
X-Proxy-Cache-La3
X-HS-Status
Xkeylog
X-Akamai-ERPolicy
X-Wp-Cf-Super-Cache
X-IAuth-Set-Uid
X-Check-Cacheable
On-Server
Reporter
X-Serial
Thinkindot-Control
X-Wp-Cf-Super-Cache-Cache-Control
FSS-Cache
X-Akamai-ERRuleID
X-Lb-Nocache
X-Elasticpress-Query
Timeexpire
X-Dw-Trace-Id
Coldstone-Viewer-Country
Yjs-Id
Datacenter
Coldstone-Viewer-Currency
Coldstone-Viewer-Country-Region-Name
DataCenter
X-Cdn-Request-ID
X-Mg-Cache
X-VTEX-Cache-Backend-Header-Time
X-Lsadc-Cache
X-Tncms-Bot-Tier
X-VTEX-Cache-Backend-Connect-Time
Cneonction
Thinkindot-Cache-Type
X-Td-Header-From-No-Data
X-Web-Server
X-BBC-Origin-Response-Status
X-Orig-Cache-Control