Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
X-Download-Options
P3P
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
Accept-CH
X-Request-ID
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
X-Drupal-Dynamic-Cache
Permissions-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
X-Check
Content-Encoding
Status
Accept-Ch
X-CDN
X-Ua-Compatible
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
X-Turbo-Charged-By
Cf-Apo-Via
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
EagleId
X-Server
X-Dispatcher
X-UA-Device
X-Vhost
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-AH-Environment
X-Ws-Request-Id
Accept-CH-Lifetime
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Pingback
X-Litespeed-Cache
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Cache-Lookup
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Page-Speed
X-Cloud-Trace-Context
X-Device
X-Backend-Server
EagleEye-TraceId
X-Akam-SW-Version
X-Host
Surrogate-Control
Xkey
X-Response-Time
Cf-Railgun
X-Readtime
X-LiteSpeed-Cache
X-Server-Id
X-Node
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Nginx-Cache-Status
X-Country
X-Url
X-Content-Type
Cache-Tag
Content-Location
X-NWS-LOG-UUID
X-Application-Context
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Trace
Cross-Origin-Opener-Policy
Fastly-Restarts
X-Amz-Server-Side-Encryption
X-Country-Code
X-Times
X-Rack-Cache
X-Vname
X-TtlSet
X-PC
X-Midtier
X-Mcache
X-Edge
Rating
Surrogate-Key
X-Server-Name
X-Browser-Type
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Cache-TTL
X-Cnection
X-Element-Page-Cache
X-Abt-Application-Version
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-ESI
Nginx-Cache
X-Powered-By-Plesk
X-GitHub-Request-Id
X-Ser
X-Oneagent-Js-Injection
Edge-Control
X-ECACHE
X-D2id
Verso
X-Ac
X-Vcap-Request-Id
X-MS-InvokeApp
X-Client-IP
X-Dw-Request-Base-Id
X-ARC
X-ORACLE-DMS-RID
X-B3-TraceId
X-Amz-Rid
X-Middleton-Response
Response
X-CST
X-Navigation-Version
X-Powered-CMS
X-Goog-Hash
X-Upstream
X-Daa-Tunnel
X-Erf-Bev-Bev
X-Kinsta-Cache
X-Edge-Location-Klb
X-Erf-Bev-Bev-Is-Generated
X-PDP-UNCACHING-HASH
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Wormhole-Sdk
X-Forwarded-For
X-NF-Request-ID
X-Amzn-Trace-Id
X-Cache-Key
RTSS
X-Ua-Device
X-FastCGI-Cache
X-Ratelimit-Limit
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
SPIisLatency
SPRequestDuration
X-Mod-Pagespeed
Cache-Status
Edge-Cache-Tag
X-Ratelimit-Remaining
X-ORACLE-DMS-ECID
X-Server-ID
Public-Key-Pins
X-Version
X-Ttl
X-Mg-S
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-Content-Digest
AR-CACHE
SPRequestGuid
X-Varnish-TTL
X-SharePointHealthScore
S
Realpath
Cross-Origin-Resource-Policy
X-Shield-Request-Id
X-MSEdge-Ref
X-T
Fastcgi-Cache
X-Cached
X-Fastly-Request-ID
X-Recruiting
X-Accel-Expires
X-Distributor
Front-End-Https
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Access-Control-Request-Method
TP-Cache
X-Request-Received
X-Azure-Ref
X-Request-Processing-Time
X-Id
X-Correlation-Id
MicrosoftSharePointTeamServices
Count-Hit
X-Ua-Browser
X-TTL
X-Debug
X-HS-Content-Id
Arr-Disable-Session-Affinity
X-HS-Cache-Config
X-HS-Hub-Id
Server-Node
X-LLID
X-Content-Security-Policy-Report-Only
X-Newrelic-App-Data
X-VARITI-CCR
X-Frontend
X-PressLabs-Stats
X-HS-Combine-CSS
Cache-Tags
Origin-Trial
X-Cluster-Name
X-Ismobilevalue
Payment
X-GUploader-UploadID
X-Amz-Replication-Status
X-Varnish-Backend
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Hits
X-LB-Cache
X-Goog-Metageneration
X-Forwarded-Proto
X-Protected-By
X-Microsite
X-Request-Handler-Origin-Region
X-Unique-Id
Cleartype
Host
X-Varnish-Server
X-FB-Debug
X-Git-Hash
X-Www-Served-By
X-AppVersion
X-NGENIX-Cache
X-Logged-In
X-Activity-Id
X-Az
X-Ratelimit-Reset
Content-Disposition
Filterid
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Hostname
X-App-Server
X-Xrds-Location
X-Page-Id
X-Amzn-RequestId
X-DIS-Request-ID
X-Amz-Apigw-Id
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Cambria-Cache-Control
Akamai-GRN
X-Geo-Country
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
Access-Control-Allow-Method
X-Nf-Request-Id
X-Template
X-Origin-Server
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Load-Cache
Retry-After
X-Upgrade-Enabled
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Frame-Options
X-Aspnet-Version
MS-Author-Via
X-Type
Section-Io-Cache
Viewport
Accept-Charset
Fastly-SWR
X-ASPNET-VERSION
Fastly-SIE
X-TT
X-Content-Options
Version
X-Fastcgi-Cache
X-Fb-Rlafr
X-Cache-Control
Content-MD5
X-B3-Sampled
X-WP-CF-Super-Cache
X-B
X-Grace
X-WP-CF-Super-Cache-Cache-Control
X-Ah-Environment
X-Rid
Amp-Access-Control-Allow-Source-Origin
X-RateLimit-Remaining
X-Request-Guid
X-Envoy-Decorator-Operation
X-Vcl-Version
X-Trace-Id
X-Revision
X-FTR-Request-ID
X-SRCache-Fetch-Status
X-Source
X-SRCache-Store-Status
X-Device-Type
X-Varnish-Ttl
Healthy
X-Cdn
X-Magnolia-Registration
Server-Name
X-Origin-Cache
X-Amz-Meta-S3cmd-Attrs
X-Language
Trailer
X-Contextid
X-Buckets
X-Mobile
X-Cache-Age
X-WP-CF-Super-Cache-Active
X-Px
X-Aspnetmvc-Version
X-Webkit-CSP
X-Backend-Name
X-CSRF-Token
X-Proxy
X-Akamai-Edgescape
X-App-Environment
X-Tumblr-User
X-RemovedCookies
X-Tumblr-Pixel-0
X-Status
X-RM-Cache-TTL
X-ProcessESI
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Mg-Request-UUID
X-Environment-Context
X-Framework
X-L-Path
X-Instance
X-Debug-Info
X-NYM-Debug-Backend
TCN
X-Rule
X-HTML-Minification-Powered-By
Access-Control-Request-Headers
SD-X-WS
X-UUID
X-Adobe-Loc
X-Region
X-Adobe-Content
X-G
X-Varnish-Grace
X-Node-Name
X-Proxy-Cache-Info
NGB
GEO-INFO
X-Debug-IsPreview
DC
Cross-Origin-Window-Policy
X-Debug-IsConnected
X-Storage
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-FW-Version
X-FW-Serve
X-ServerID
X-FW-Server
X-Datadog-Parent-Id
MS-CV
X-Datadog-Sampling-Priority
Ms-Operation-Id
X-Content-Powered-By
X-Rendered-As
X-Is-Bot
X-RTag
X-Datadog-Sampled
X-Cacheable-TTL
X-Datadog-Trace-Id
X-EdgeConnect-Cache-Status
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Seen-By
X-Cache-Time
X-Edge-Location
X-Webkit-Csp
Upgrade-Insecure-Requests
Paypal-Debug-Id
Charset
X-HS-Prerendered
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Protected
X-User-Agent
Countrycode
Webserver
X-TraceId
X-Whom
OT-Force-Account-Verify
Front
X-TT-LOGID
Refresh
X-Lambda-Id
X-WebKit-CSP-Report-Only
Section-Io-Id
X-VC
Cross-Origin-Embedder-Policy-Report-Only
X-IPS-LoggedIn
X-Reqid
Priority
X-Original-Request-Id
X-Response-Served-From
SRV
Alternate-Protocol
X-Amzn-Remapped-Content-Length
X-VHOST
X-N
X-Akamai-Request-ID2
X-AB
X-ECache
Country
X-Cache-Status-Check
Xet-Cookie
Backend
X-Time
X-Server-W
X-Fastly-Request-Id
X-B3-Traceid
X-B3-SpanId
X-WP-CF-Super-Cache-Cookies-Bypass
Liferay-Portal
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Real-IP
X-Mode
X-Hl-Ver
Onion-Location
X-UPSTREAM-Address
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
X-Tumblr-Pixel-2
TWC-GeoIP-Country
TWC-Privacy
Fastcgi-Useragent
From-Origin
Filters
Meta-Geo
Property-Id
TWC-Device-Class
TWC-Connection-Speed
X-Scope-Id
Webcakes-App-Version
X-Origin-Date
X-JoinUs
X-Origin-Hint
X-Rewrite-Enabled
X-Tb
Environment
X-Format
X-Fetched-On
X-Cache-Expired-At
Webcakes-Region
X-Cache-Host
X-VC-Cache
X-SaId
X-FB-TRIP-ID
X-Rn-Rsrv
ServerID
X-Restarts
X-Say-Cacheable
X-Request-URI
X-Redis-Cache
X-R9-Blue-Green-Version
X-Forwarded-Host
X-SayCDN-TTL
X-Webstats-RespID
X-Web-Node
X-Varnish-Age
X-Skip-Cache
Expiry
Mn-Server-Ip
X-Cache-Action
X-Cluster-Node
X-Connection-Hash
X-Frame-Option
X-Hosted-By
X-Accel-Version
Uber-Trace-Id
Web-Mar-Node
X-IPLB-Request-ID
X-IPLB-Instance
DB-Nickname
X-Say-TTL
Accept-Language
X-Tncms
X-PHP-Host
Apigw-Requestid
X-BYPASS-REASON
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Soup
X-Adobe-Source
X-Logging-Id
X-Loop
Atl-Traceid
X-Labrador-Cache-Channel
X-Httpd
X-ProxyCache-Status
X-Handled-By
X-Vcache
X-Director
X-Cms-Context
X-ProxyCache-Key
X-Served-From
X-Rocket-Nginx-Serving-Static
X-Origin-CC
ServedBy
Selected-Fe
X-Proxy-Build
Url
X-Servername
X-Cluster
X-Origin-TTL
X-Timing-Wait
X-Auth-Group-Type
X-Proxied
X-Extlb
X-Origin
X-Routing-Service
X-Zipkin-Id
X-Detected-As
X-Wix-Request-Id
X-Cloudmap
X-S
X-LSADC-Cache
VIX-Pulpo-Node
X-Generated-By
X-SRV
X-Hit
Cross-Origin-Embedder-Policy
VIX-Pulpo-Upstream-Status
X-DynaTrace
Referer-Policy
N-Cache
X-Lagoon
X-DataDome
X-Ms-Request-Id
X-Ms-Version
Xserver
X-Nginx-Cache
X-Tumblr-Pixel-3
X-XRDS-Location
X-Xfnlog-Site
X-Azure-Ref-OriginShield
X-Via-JSL
Source
Surrogated-Key
WPO-Cache-Status
WPO-Cache-Message
X-NWS-UUID-VERIFY
LB
X-App-Version
X-RateLimit-Limit-Second
X-Worker
X-RateLimit-Remaining-Second
X-RCS-CacheZone
X-Cache-Debug
CF-IPCountry
X-VCT
Cross-Origin-Opener-Policy-Report-Only
X-Generation-Time
X-Sucuri-Cache
X-Proxy-Cache-Status
Ohc-File-Size
X-F-Cache
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Node
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
X-Is-Desktop
X-Cdn-Origin
X-Geo-Region
X-Upstream-Ct
X-Tcp-Rtt
X-Upstream-Ht
X-Sucuri-ID
X-Browser-Name
X-UA
X-Urbn-Context-Path
X-No-Session
Locale
X-Urbn-Site-Id
X-Signature
X-NGINX-Cache
CDN-RequestId
X-B-Cache
X-MP-GENERATED-AT
X-Varnish-Beresp-Ttl
X-RateLimit-Limit
AMP-Access-Control-Allow-Source-Origin
X-NODE
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Tx-Id
X-ShardId
X-ShopId
X-Shopify-Stage
X-HS-CF-Cache-Status
X-Service
X-Cache-Hit
X-Locale
X-Cache-Operation
X-RID
X-ElasticPress-Query
X-PAYTM-SRV-ID
Producers
Redirect-Candidate
User-Agent
Rendered-Blocks
X-Op-Id-All
TDXMobile
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Sslversion
X-Org
X-Nyt-Route
X-Platform-Server
X-Origin-Time
X-Origin-Expires
X-Path
Ngx.Var.Host
Cdncip
Candidate-Md5Url
Cache-Provider
Cdnsip
Cluster
DCR-Decision-By
Content-Secure-Policy
BehaviorPad-Version
Apple-News-Services-Request-Url
Cache
X-ScT
X-Rojux
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Expect-Staple
Fastly-Backend-Name
MD5-Digest
Mail-Subject
Meta-Geo-Continent
W
Origin
Odigeo-Trace-Id
Lang
L5d-Success-Class
Ha-Gx-Prefs
Fastly-GeoIP-CountryCode
HA-Ipaddr
Host-ID
X-Proto
X-Proxied-Request
PFcat
X-A-Dcw
X-DefHash
X-DefElseHash
X-Depends
X-Developer
X-INCAP-ABP
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Conf
X-Jobs
X-Contensis-Viewer-Groups
X-Csrf-Jwt
X-D
X-DPWN-IS-SECURE
X-Ec-Fail
X-GeoCode
X-Gdpr
X-GeoCountry
X-GeoIP
X-GeoIP-City
X-HN
X-FC-Vary-Parameters
X-Ec-GeoHdr
X-Ig-Push-State
X-Ig-Origin-Region
X-Eu-Site
X-CGP
X-Loc
X-A-Wwc
X-A-Dgt
X-AB-Test
X-Access
X-Aed
X-Section
X-A-Dam
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-A
X-A-Ccd
X-Aicache-OS
X-Mvc-Supplant-Cachable
X-Bug-Bounty
X-BCube-Filmed-By
X-Cache-Aspx
X-Cache-Info
X-Cache-NE
X-Bc-Bl
X-Backend-Instance
X-Mly-Id
X-AK-Request-ID
X-Akamai-Device-Characteristics
X-App-Name
We-Hiring
DCR-Processing-Time-Ms
X-Cache-Rule
X-TIM-N
X-Vtex-Remote-Cache
X-Varnish-CookieHashed-On
Xc-Version
X-Varnish-Authentication
X-TA-CDN-Provider
X-Thinkindot-L3
X-Varnish-CookieINHashed-On
X-Vmg-Version
X-Shield-Cache-Expires
X-Vdms-Version
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
Akamai-Mon-Iucid-Del
X-Litespeed-Tag
X-Site-Version
Mime-Version
X-B3-Trace-ID
X-VTEX-Cache-Server
L
X-Edge-Server
X-Var-Ttl
Platform
Origin-EX
X-Platform
X-BBC-Edge-Cache-Status
NM-Fastcgi-Cache
X-UA-Device-Type
X-Auto-Login
X-Epic-Correlation-Id
Product
X-V-Cache
X-Esi-Check
Origin-Agent-Cluster
X-Powered-By-VTEX-Cache
X-Policy
Origin-CC
Req-Svc-Chain
X-Internal-TTL
X-Date
X-Accel-Expires-Debug
X-ORCA-Accelerator
X-Irp-Debug
X-NodeID
X-VTEX-Cache-Time
V-Age
Web-Mar-Region
X-Mvc-Supplant-OutputCached
X-Clientip
X-NMSegId
X-Node-Id
Fl-Custom-Application
X-Dispatcher-Server
IsBot
RNT-Machine
X-Amz-Storage-Class
X-Content-Age
X-We-Are-Hiring
RNT-Time
X-Varnishpool
X-Micro-Cache
X-Pad
X-Amz-Meta-Cb-Modifiedtime
X-Origin-Response-Time
Server-Host
X-Content-Length
X-Fastly-Backend
X-Level-Front-Cache
X-CacheTTL
X-SB
CDCHOST
X-Cdn-Srv
X-Cached-By
Cdn-Host
X-Core-Value
X-Wikidot-Backend
X-Varnish-Director
X-Location
Cdn-Request-Time
Canary
X-Gzip
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-Sn-Servicetimems
X-Via-Fastly
Azure-SlotName
X-Slack-Backend
X-Generated-On
Cache-Key
X-SIPLIST1
X-SVT-ORM-RULES
Azure-Version
X-Cache-Id
X-VG-WebCache
X-Bl-Debug
X-Fmm-Version
Esi-Enabled
X-Req
X-Scheme
X-Tb-Optimization-Total-Bytes-Saved
Fastly-SSL
Gh-Request-Id
X-HS-Content-Campaign-Id
X-SD-PageType
X-GoCache-CacheStatus
Gannett-Cam-Experience-Id
X-Slack-Shared-Secret-Outcome
Debug
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Cache-Grace
X-Request-Time
X-Gamma-Serve
X-Viewer-Country
X-Cache-Bucket
X-SVT-ORM-VERSION
Content-Style-Type
Content-Script-Type
X-Hash
X-Wikidot-Static-Cache
X-XRDS-LOCATION
X-Men
X-Block-Status
X-Bip
XkeyRZ
XM
X-Cache-FS-Status
X-CUA
Yak-Timeinfo
X-Acquia-Purge-Cdn-Unconfigured
Pramga
Country-Code
X-Request-Host
X-Request-Start
Click-Count-Error
DSUID
X-Hnp-Log
X-Thanos
X-Human
X-Proxy-CacheRZ
X-Pubstack
Click-Count-Action-Start
CDN-Uid
CDN-CachedAt
CDN-Cache
X-Gen-Mode
A
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestPullSuccess
CDN-RequestPullCode
CDN-RequestCountryCode
X-Pool
NGX
Tube-Get-Contents
X-Server-IP
X-Cdn-Forward
Tube-Got-Eval
Tube-Got-Results
User-Cache-Control
Tube-Return
ServerName
X-VG-TLSProxy
Req-ID
Release
X-Ec-Custom-Error
X-Varnish-Beresp-Status
Sid
X-COUNTRY
X-HITS
X-Varnish-Hits
Ssr
X-VServer
X-LB-NoCache
X-Newrelic-Synthetics
X-URL
X-HOST
X-Geolocation
X-Optimistic-Header
TP-L2-Cache
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
X-Cache-Date
X-Application
X-Dc
X-Destination
X-External-Request-Id
X-S-Cookie
X-CACHE-GROUP
X-B-Cookie
X-Refresh
X-IsAdmin
X-CDN-Forward
Cdn-Requestid
X-Cs
X-Via-CDN
X-APP
X-Zen-Fury
X-Via-Edge
X-GEO
X-Via-SSL
X-Api-Version
X-Nananana
Edge-Copy-Time
X-CLOUD-TRACE-CONTEXT
X-User
CloudFront-Viewer-Country
Proxy-Firewall
X-Servedbyhost
X-AIR-PT
Fastly-Drupal-HTML
C-Via
X-RequestId
GeoIP-Latitude
True-Client-Country-4JS
Ohc-Cache-HIT
Server-ID
X-DC
X-Endurance-Cache-Level
X-ZONE
Fastly-Drupal-Html
X-VC-TTL
X-Test
X-Via-Poph
X-HA-Backend
X-Via-Popv
X-Via-Popn
Sever-Int
X-VWS-Id
X-Zone
Server-Ext
Server-Hostname
X-LJ-Flow-ID
X-AWS-Id
X-B3-Spanid
X-LiteSpeed-Cache-Control
X-LiteSpeed-Tag
Adler-Geo
Is-Eu
X-Nc
X-Wa
X-LB-ID
X-Provided-By
X-CACHE-AGE
X-Air-Pt
X-DynaTrace-JS-Agent
HostName
X-TH-Server
GeoIp-Country-Code
X-Resp-Is-Stale
X-Webkit-Csp-Report-Only
X-Nginx-Cache-Key
X-NewRelic-App-Data
X-B3-Parentspanid
X-Vgn-Hpd-Reason
X-CS
X-Dispatcher-Number
X-Datadome
X-Tt-Logid
Cdn
X-Presslabs-Stats
X-Oracle-Dms-Ecid
WP-Super-Cache
WZWS-RAY
X-Pass-Why
S-Rt
T-Server
X-Old-Content-Length
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Moov-T
X-Custom-Header
X-Geo-Header
X-API-Version
Cache-Tv-Group
X-Srv
X-HubSpot-Correlation-Id
True-Client-IP
X-DataCenter
X-Fpc
X-ND-Cache
SID
X-Parent-Response-Time
X-Cache-Server
X-CMSURLCustom
Vc-Max-Age
Resin-Trace
Tcn
X-Thinkindot-L1
X-Action
X-Cache-VC
Location
Pics-Label
Uri
SEZNAM-JOBS-OFFER
Powered-By
X-Vercel-Id
X-Vercel-Cache
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Litespeed-Cache-Control
X-TX-ID
X-FPC
True-Client-Ip
Vix-Hermes-Req-Id
N1-Cache
X-SERVER-NAME
X-Ckpd-Fst-Backend
Serverhost
X-Fastly-Cache
X-Client-Ip
X-Dynatrace-Js-Agent
X-Service-Response-Time
X-Varnish-Beresp-TTL
Sm-Log-Id
X-Cache-TTL-Remaining
GeoIP-Country-Code
Thinkindot-Control
X-Datacenter
X-ApacheServer
On-Server
X-PERF
X-Stale
TWC-GeoIP-City
TWC-GeoIP-Region
TWC-GeoIP-DMA
Cache-Hits
Srv
X-APP-VERSION
X-WA-Info
X-Oracle-Dms-Rid
X-Render-Time
X-Ua
ServerHost
Hostname
Av-Poweredby
X-NC
X-PHP-Backend
X-Uri
X-WA
X-Cdn-Cache-Status
X-Fastly-Cache-Status
X-Amz-Meta-Opti
X-Nitro-Cache
X-Debug-Service
AKAMAI
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
X-Ion-Healthy
Log-Origin
X-Jungle-Id
X-Ion-Hop
Server-Id
Xkeylog
RewriteTestHook
Xkey-La3
X-Lb-Id
X-Air-Trace-Id
Cache-Contol
Lb
X-Air-Source
Geoip-Latitude
X-Air-Hostname
X-Proxy-Cache-La3
RewriteTeamHook
X-Vc
My-App
Cmsid
X-Udemy-Cache-App-Namespace
X-Via-PopH
X-Via-PopN
X-Via-PopV
Cmstype
X-Ha-Backend
Time-Cloud-Cache
X-Save-Cache
X-Vary-Devices
Cf-Ipcountry
X-VTEX-Cache-Backend-Header-Time
X-Cms-Device
X-Ee-Request-Id
X-Ee-Generated-By
X-Ee-Origin
X-Ee-Request-Date
X-VTEX-Cache-Backend-Connect-Time
Store-Cloud-Cache
Magicmarker
X-Info
X-Fastly-Backend-Reqs
X-Geo
Cl-Cache
X-Cache-Ttl
X-Github-Request-Id
X-Up
X-From
Cloudfront-Viewer-Country
X-Requestid
X-Oracle-DMS-ECID
X-ServedByHost
X-Esi
X-Akamai-Pragma-Client-IP
CacheControlHeader
X-App
X-VCL-Version
X-IAuth-Set-Uid
X-CDN-Cache-Status
X-V
X-Wp-Cf-Super-Cache-Cache-Control
CDN
X-Wp-Cf-Super-Cache
X-Eligible
X-New
X-Rollout
X-Limited
X-Traceid
WWW-Authenticate
WebServer
X-Correlation-ID
CountryCode
X-Dw-Trace-Id
X-MSEdge-Flight
Machine
X-LAGOON
X-Region-Sid
X-Forwarded-Site
Warning
X-MSEdge-Features
Cneonction
X-Acquia-Purge-Tags
NtCoent-Length
Pragrma
X-Lb-Nocache
X-Check-Cacheable
X-Acquia-Site
Server-Info
Reporter
X-Serial
X-HS-Status
Wpo-Cache-Message
FSS-Cache
Wpo-Cache-Status
X-CSRF-TOKEN
X-Pod
X-Akamai-Transformed
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Sucuri-Id
X-Elasticpress-Query
X-Td-Header-From-No-Data
X-Web-Server
X-Ftr-Request-Id
X-BBC-Origin-Response-Status
Thinkindot-Cache-Type
X-Akamai-ERPolicy
X-Ramcache
X-Ms-Blob-Type
CF-Cached-On
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Ms-Lease-Status
X-Tncms-Bot-Tier
X-Orig-Cache-Control
X-Cdn-Request-ID
Edge-Cache
X-Akamai-ERRuleID
Timeexpire
X-EC-Lua