Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
X-Xss-Protection
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
P3p
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Accept-CH-Lifetime
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Cache-Group
X-Age
X-Vhost
X-Proxy-Cache
X-Turbo-Charged-By
EagleId
Keep-Alive
X-Rq
X-Via
X-Dispatcher
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Litespeed-Cache
Xkey
X-Varnish-Cache
X-WebKit-CSP
Grace
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Check
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Device
X-Dns-Prefetch-Control
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-Node
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Country
X-Server-Id
X-Country-Code
Content-Location
X-Nginx-Cache-Status
X-Url
Cache-Tag
X-Content-Type
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
Fastly-Restarts
X-LiteSpeed-Cache
X-Clacks-Overhead
X-Trace
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Application-Context
X-Amz-Server-Side-Encryption
X-Times
X-NWS-LOG-UUID
X-TtlSet
X-PC
Surrogate-Key
X-Vname
X-Mcache
X-Edge
Rating
X-Midtier
X-Server-Name
X-Cache-TTL
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Cnection
X-Powered-By-Plesk
X-Abt-Application-Version
X-Element-Page-Cache
X-Browser-Type
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-GitHub-Request-Id
X-ESI
Nginx-Cache
X-Server-ID
X-Vcap-Request-Id
Edge-Control
X-D2id
X-ORACLE-DMS-RID
Verso
X-Ac
X-Ser
X-MS-InvokeApp
X-ECACHE
X-Ratelimit-Limit
X-Amz-Rid
X-Client-IP
X-Wormhole-Sdk
Response
X-Middleton-Response
X-Oneagent-Js-Injection
X-CST
X-Goog-Hash
X-ARC
X-B3-TraceId
X-Powered-CMS
X-Dw-Request-Base-Id
X-Ratelimit-Remaining
X-FTR-Request-ID
X-Navigation-Version
X-Edge-Location-Klb
X-Kinsta-Cache
X-Instrumentation
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Upstream
X-Forwarded-For
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
Origin-Trial
X-Cache-Key
X-Mod-Pagespeed
RTSS
Edge-Cache-Tag
X-Content-Digest
Cache-Status
Public-Key-Pins
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
X-Ezoic-Cdn
X-FastCGI-Cache
X-Ttl
X-Daa-Tunnel
X-ORACLE-DMS-ECID
X-Version
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Mg-S
X-Pinterest-Rid
Pinterest-Generated-By
Realpath
Pinterest-Version
X-MSEdge-Ref
S
X-Recruiting
X-Shield-Request-Id
X-T
X-Fastly-Request-ID
Front-End-Https
Fastcgi-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-Xrds-Location
X-Distributor
Cross-Origin-Resource-Policy
X-Cached
AR-CACHE
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Azure-Ref
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-Correlation-Id
X-HS-Content-Id
TP-Cache
Count-Hit
X-HS-Cache-Config
X-Id
X-TTL
X-Debug
X-Nf-Request-Id
X-Ua-Browser
X-Ismobilevalue
Cache-Tags
X-Cluster-Name
X-Newrelic-App-Data
X-LLID
X-TraceId
Server-Node
X-NGENIX-Cache
MicrosoftSharePointTeamServices
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
Akamai-GRN
X-Varnish-TTL
X-Hits
X-Frontend
X-PressLabs-Stats
X-Varnish-Backend
X-Protected-By
X-HS-Combine-CSS
X-VARITI-CCR
X-Aspnetmvc-Version
X-Amz-Replication-Status
X-Goog-Metageneration
Accept-Ch
X-Fastcgi-Cache
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
Payment
X-Ratelimit-Reset
X-DIS-Request-ID
X-FB-Debug
X-Unique-Id
X-Git-Hash
X-Activity-Id
X-Logged-In
X-AppVersion
X-Az
Cleartype
X-Tt-Trace-Host
X-Hostname
X-Www-Served-By
X-Varnish-Server
X-Varnish-Ttl
X-Tt-Trace-Tag
Content-Disposition
X-Jurisdiction
X-Cambria-Cache-Control
X-HP-Trace-Id
X-HP-Webp
X-Template
X-Amzn-RequestId
X-Amz-Apigw-Id
Host
Filterid
X-Forwarded-Proto
Amp-Access-Control-Allow-Source-Origin
X-App-Server
X-Geo-Country
Version
X-Load-Cache
Accept-Charset
MRF-Tech
X-Goog-Stored-Content-Encoding
X-B3-TraceId-Primal
X-Envoy-Decorator-Operation
Mrf-Cache-Status
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
Frame-Options
X-Aspnet-Version
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Source
X-ASPNET-VERSION
Access-Control-Allow-Method
Fastly-SIE
X-Type
Fastly-SWR
X-Cache-Age
Section-Io-Cache
Trailer
X-HS-Prerendered
X-TT
X-Content-Options
X-Fb-Rlafr
X-Upgrade-Enabled
Viewport
X-Origin-Server
Server-Name
X-B3-Sampled
X-B
X-Grace
X-Ah-Environment
X-Language
X-Cache-Control
X-Device-Type
X-TEC-API-ORIGIN
X-Rid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Buckets
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend-Server
Retry-After
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
Content-MD5
MS-Author-Via
X-Px
X-Magnolia-Registration
X-Mobile
X-Vcl-Version
X-Request-Guid
X-Cdn
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
TCN
X-Trace-Id
X-Revision
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Akamai-Edgescape
Protected
Healthy
X-WP-CF-Super-Cache-Active
X-Backend-Name
Accept-Ch-Lifetime
Upgrade-Insecure-Requests
Cross-Origin-Embedder-Policy-Report-Only
Charset
X-Debug-Info
X-Response-Served-From
SD-X-WS
X-App-Environment
X-Original-Request-Id
X-Proxy
X-RM-Cache-TTL
X-Tumblr-User
X-Instance
X-Is-Bot
X-CSRF-Token
X-RemovedCookies
X-ProcessESI
X-ServerID
X-Tumblr-Pixel
X-Rendered-As
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-NYM-Debug-Backend
X-Rule
Cross-Origin-Window-Policy
X-Status
X-Node-Name
X-Storage
X-UUID
Access-Control-Request-Headers
X-Mg-Request-UUID
X-FW-Type
X-FW-Serve
X-FW-Static
X-FW-Server
X-Cache-Time
X-Adobe-Loc
X-FW-Version
X-Framework
NGB
X-FW-Dynamic
X-FW-Hash
X-Adobe-Content
X-Cacheable-TTL
X-Content-Powered-By
X-Datadog-Trace-Id
X-Debug-IsConnected
X-Debug-IsPreview
X-Proxy-Cache-Info
X-Datadog-Sampling-Priority
X-Datadog-Sampled
Ms-Operation-Id
X-RTag
Refresh
X-Datadog-Parent-Id
MS-CV
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Region
X-Whom
X-G
X-Edge-Location
X-L-Path
GEO-INFO
OT-Force-Account-Verify
X-Environment-Context
X-Lambda-Id
X-Contextid
Webserver
Section-Io-Id
X-ECache
X-Resp-Is-Stale
X-Amzn-Remapped-Content-Length
X-Reqid
X-B3-Traceid
Countrycode
DC
X-Origin-Cache
X-Amz-Meta-S3cmd-Attrs
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-User-Agent
X-VC
X-Server-W
Paypal-Debug-Id
X-TT-LOGID
X-HTML-Minification-Powered-By
Alternate-Protocol
Front
X-Real-IP
X-RateLimit-Remaining
X-B3-SpanId
X-Time
X-Seen-By
X-DataDome
Cross-Origin-Opener-Policy-Report-Only
X-HS-CF-Cache-Status
Priority
X-WebKit-CSP-Report-Only
SRV
WPO-Cache-Status
WPO-Cache-Message
X-WP-CF-Super-Cache-Cookies-Bypass
Xet-Cookie
Ohc-File-Size
X-Origin-CC
X-Hl-Ver
X-Rocket-Nginx-Serving-Static
Liferay-Portal
X-Origin-TTL
X-Mode
Backend
X-IPS-LoggedIn
X-Akamai-Request-ID2
Onion-Location
X-AB
X-Nginx-Cache
X-Redis-Cache
X-Say-Cacheable
X-SaId
X-Say-TTL
X-SayCDN-TTL
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-Rn-Rsrv
X-Rewrite-Enabled
ServerID
Meta-Geo
X-Cache-Action
X-Cache-Host
X-JoinUs
X-FB-TRIP-ID
Fastcgi-Useragent
Filters
X-N
Country
X-Cache-Status-Check
Environment
X-Tb
X-VC-Cache
DB-Nickname
X-Varnish-Age
X-DynaTrace
X-Vcache
X-Origin-Date
TWC-GeoIP-LatLong
TWC-GeoIP-Country
From-Origin
TWC-Connection-Speed
TWC-Device-Class
X-Soup
X-Scope-Id
X-Hosted-By
X-Restarts
Property-Id
X-Handled-By
X-Connection-Hash
X-Origin-Hint
TWC-Locale-Group
X-Skip-Cache
X-PHP-Host
X-Tncms
TWC-Privacy
X-Fetched-On
X-Format
X-Tumblr-Pixel-3
X-IPLB-Request-ID
X-Director
X-Loop
X-Cms-Context
X-Cluster-Node
Expiry
X-Detected-As
X-Ms-Request-Id
X-Labrador-Cache-Channel
Web-Mar-Node
X-Ms-Version
Uber-Trace-Id
X-R9-Blue-Green-Version
Webcakes-App-Version
Webcakes-App-Name
X-IPLB-Instance
X-Accel-Version
Webcakes-Region
X-Httpd
X-ProxyCache-Status
Apigw-Requestid
X-ProxyCache-Key
Atl-Traceid
X-Logging-Id
X-Varnish-Cache-Hits
Mn-Server-Ip
X-Web-Node
X-Adobe-Source
X-Frame-Option
X-Cache-Expired-At
X-BYPASS-REASON
X-Varnish-Beresp-Grace
X-Webstats-RespID
X-Auth-Group-Type
Selected-Fe
X-Cluster
X-Timing-Wait
X-Forwarded-Host
Url
X-Proxy-Build
X-Servername
X-Served-From
X-Cloudmap
X-Extlb
ServedBy
X-Proxied
X-Zipkin-Id
X-Routing-Service
X-Origin
X-S
Surrogated-Key
X-SRV
X-Azure-Ref-OriginShield
X-RateLimit-Limit-Second
X-Fastly-Request-Id
X-RateLimit-Remaining-Second
X-Worker
Accept-Language
X-LSADC-Cache
Cross-Origin-Embedder-Policy
X-Hit
LB
X-Request-URI
X-Lagoon
X-Cache-Hit
X-Sucuri-Cache
Referer-Policy
N-Cache
X-Generation-Time
X-Drupal-Cache-Tags
X-Generated-By
X-Drupal-Cache-Contexts
X-CDN-Forward
X-Cdn-Origin
X-App-Version
X-Sucuri-ID
X-MP-GENERATED-AT
Xserver
CF-IPCountry
CDN-RequestId
Source
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-F-Cache
X-Xfnlog-Site
X-Wix-Request-Id
Node
Ohc-Cache-HIT
X-TA-CDN-Provider
X-Tx-Id
X-Mly-Id
Cache
Edge-Copy-Time
X-Via-CDN
X-Via-SSL
X-Via-Edge
X-Cache-Debug
X-VC-TTL
X-Cache-Rule
X-AIR-PT
X-INCAP-ABP
X-Pad
X-VCT
X-NODE
X-RCS-CacheZone
X-Varnish-Beresp-Ttl
Cache-Provider
X-Site-Version
X-Locale
X-NWS-UUID-VERIFY
X-XRDS-Location
X-Urbn-Context-Path
X-Urbn-Site-Id
X-ElasticPress-Query
X-GEO
X-Is-Supported-Browser
X-Tcp-Rtt
X-Geo-Region
X-Browser-Name
Locale
X-Is-Mobile
X-Is-Desktop
X-Is-Tablet
Redirect-Candidate
Rendered-Blocks
Lang
Mail-Subject
Meta-Geo-Continent
Odigeo-Trace-Id
X-Platform-Server
Ngx.Var.Host
Producers
MD5-Digest
X-PAYTM-SRV-ID
X-Proxied-Request
X-GeoIP-Region-Code
BehaviorPad-Version
X-Path
X-UA
X-Rojux
X-ScT
X-S-Cookie
Candidate-Md5Url
Cluster
Fl-Custom-Application
X-Proto
Fastly-GeoIP-CountryCode
Fastly-Backend-Name
DCR-Decision-By
Expect-Staple
Host-ID
Web-Mar-Region
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Destination
X-Developer
X-Ig-Origin-Region
X-D
X-Cache-Operation
X-Jobs
X-Conf
X-Ig-Push-State
X-DPWN-IS-SECURE
X-Ec-Fail
X-Geolocation
X-GeoCode
X-GeoCountry
X-GeoIP-Country-Code
X-Gdpr
X-FC-Vary-Parameters
X-Ec-GeoHdr
X-HS-Content-Campaign-Id
X-External-Request-Id
X-Cache-NE
X-Cache-Grace
X-A
X-A-Ccd
X-A-Dam
X-A-Dcw
X-SD-PageType
We-Hiring
X-Org
Sslversion
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-A-Dgt
X-A-Wwc
X-Bc-Bl
X-BCube-Filmed-By
X-Bl-Debug
X-Bug-Bounty
X-Backend-Instance
X-B-Cookie
X-Aed
X-Aicache-OS
X-Application
X-Origin-Time
DCR-Processing-Time-Ms
X-Vdms-Version
X-No-Session
Xc-Version
X-Slack-Shared-Secret-Outcome
X-Litespeed-Tag
X-Vtex-Remote-Cache
X-Slack-Backend
X-Signature
X-Oracle-Dms-Ecid
X-B-Cache
X-Wikidot-Static-Cache
NM-Fastcgi-Cache
X-Level-Front-Cache
X-Cache-Date
X-Policy
X-Block-Status
Origin
Platform
X-Platform
X-BBC-Edge-Cache-Status
PFcat
Origin-Agent-Cluster
X-Viewer-Country
Wxu-Next-Commit
Debug
Ha-Gx-Prefs
X-Cached-By
Gh-Request-Id
X-CGP
X-CacheTTL
Gannett-Cam-Experience-Id
HA-Ipaddr
X-Clientip
X-Cache-Id
L5d-Success-Class
X-B3-Trace-ID
X-Cache-Info
X-Powered-By-VTEX-Cache
Fastly-SSL
X-App-Name
X-Accel-Expires-Debug
X-Node-Id
X-NMSegId
X-Access
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
X-AB-Test
X-Thinkindot-L3
V-Age
X-Mvc-Supplant-OutputCached
Wxu-Next-Hostname
User-Cache-Control
Wxu-Next-Region
X-VTEX-Cache-Time
X-Micro-Cache
X-Op-Id-All
X-VTEX-Cache-Server
X-Amz-Storage-Class
X-Location
Req-Svc-Chain
X-Loc
X-Content-Age
Product
X-Vmg-Version
RNT-Machine
RNT-Time
X-AK-Request-ID
X-VServer
X-Origin-Expires
X-Amz-Meta-Cb-Modifiedtime
Server-Host
X-Wikidot-Backend
X-Auto-Login
X-Via-Fastly
X-Epic-Correlation-Id
X-Hash
X-Request-Host
Mime-Version
X-Esi-Check
X-Varnish-Director
X-Eu-Site
X-Req
X-HN
Apple-News-Services-Request-Url
Azure-InstanceId
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Hnp-Log
Content-Style-Type
X-Fastly-Backend
X-Gzip
X-Scheme
X-SB
X-Generated-On
X-GeoIP
X-Section
X-GeoIP-City
X-Shield-Cache-Expires
X-Gen-Mode
X-Fmm-Version
X-Varnish-CookieINHashed-On
X-GoCache-CacheStatus
X-Request-Time
X-Varnish-CookieHashed-On
X-Gamma-Serve
Azure-RegionName
Apple-News-Services-Handled
X-DefHash
X-DefElseHash
Azure-SiteName
X-Core-Value
X-Dispatcher-Server
X-Human
X-V-Cache
X-Date
Cdncip
Cdnsip
X-CUA
X-Csrf-Jwt
X-User
X-VG-WebCache
X-Ec-Custom-Error
Content-Script-Type
X-Varnish-Remaining-TTL
Azure-Version
Azure-SlotName
Canary
X-VarnishDD-TTL
X-Alternate-Cache-Key
X-ShopId
X-NGINX-Cache
X-Shopify-Stage
X-ShardId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
Akamai-Mon-Iucid-Del
X-Varnish-Authentication
X-IsAdmin
X-Varnish-Beresp-Status
X-Internal-TTL
X-Content-Length
X-Contensis-Viewer-Groups
X-Akamai-Device-Characteristics
X-Cache-Aspx
X-Bip
X-Edge-Server
X-TIM-N
X-Cache-FS-Status
X-Depends
X-UA-Device-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Men
X-VG-TLSProxy
X-Origin-Response-Time
Yak-Timeinfo
DSUID
X-Via-JSL
Country-Code
X-Pool
L
Origin-EX
Origin-CC
NGX
X-Zen-Fury
Content-Secure-Policy
Click-Count-Error
X-Pubstack
X-Sn-Servicetimems
X-Request-Start
X-Server-IP
X-SVT-ORM-RULES
CDCHOST
Click-Count-Action-Start
Cdn-Request-Time
Cdn-Host
Release
X-SVT-ORM-VERSION
Tube-Get-Contents
X-NodeID
X-We-Are-Hiring
Tube-Got-Eval
Tube-Got-Results
W
X-Thanos
ServerName
Tube-Return
Req-ID
X-Service
X-Ua-Device
X-TH-Server
CDN-Uid
X-Irp-Debug
CDN-RequestPullSuccess
X-Tb-Optimization-Total-Bytes-Saved
CDN-PullZone
CDN-Cache
User-Agent
CDN-CachedAt
CDN-EdgeStorageId
X-Cdn-Srv
CDN-RequestPullCode
CDN-RequestCountryCode
XM
Ssr
X-URL
X-Vgn-Hpd-Reason
IsBot
X-Varnishpool
X-RID
X-Cs
X-Var-Ttl
Sid
X-LB-NoCache
X-HOST
X-SIPLIST1
Fastly-Drupal-HTML
X-Moov-Xdn-Version
X-Moov-Xdn-Caching-Status
X-Old-Content-Length
X-Moov-T
X-Varnish-Hits
X-CACHE-GROUP
X-DC
Pramga
X-Proxy-Cache-Status
GeoIP-Latitude
X-ORCA-Accelerator
X-Refresh
N1-Cache
X-Api-Version
X-HubSpot-Correlation-Id
X-ZONE
Esi-Enabled
CloudFront-Viewer-Country
X-RequestId
X-Servedbyhost
X-HITS
X-Upstream-Ht
X-Presslabs-Stats
X-Upstream-Ct
X-APP
X-Action
X-CLOUD-TRACE-CONTEXT
X-HA-Backend
X-Wa
X-Via-Popn
X-Via-Poph
C-Via
X-Nc
AMP-Access-Control-Allow-Source-Origin
Cdn-Requestid
X-Via-Popv
X-Newrelic-Synthetics
Cache-Hits
X-Thinkindot-L1
X-Cache-VC
X-LB-ID
X-Vercel-Id
Location
X-Vercel-Cache
Server-ID
X-Cache-Bucket
TWC-GeoIP-DMA
TWC-GeoIP-City
X-Tt-Logid
TWC-GeoIP-Region
X-DynaTrace-JS-Agent
X-LiteSpeed-Cache-Control
HostName
X-Parent-Response-Time
XkeyRZ
Cache-Key
A
X-Dc
X-Proxy-CacheRZ
X-LiteSpeed-Tag
X-Ua
X-Webkit-CSP
X-Zone
X-B3-Parentspanid
X-NewRelic-App-Data
X-Nananana
Fastly-Drupal-Html
X-B3-Spanid
X-Webkit-Csp-Report-Only
X-COUNTRY
X-Cdn-Forward
X-PERF
X-ApacheServer
X-Endurance-Cache-Level
X-Webkit-Csp
X-CS
X-Render-Time
Proxy-Firewall
SID
X-WA-Info
WP-Super-Cache
X-API-Version
X-Litespeed-Cache-Control
X-Srv
X-CACHE-AGE
X-DataCenter
GeoIp-Country-Code
X-Nitro-Cache
X-Uri
X-Fpc
Uri
X-Ion-Healthy
Cache-Contol
X-Jungle-Id
RewriteTeamHook
RewriteTestHook
TP-L2-Cache
X-Ion-Hop
X-Optimistic-Header
Sever-Int
True-Client-Country-4JS
Cmsid
True-Client-Ip
My-App
Log-Origin
Server-Ext
Server-Hostname
Cmstype
True-Client-IP
GeoIP-Country-Code
Resin-Trace
X-From
X-Test
X-Up
X-Datadome
AKAMAI-GRN
Cdn
X-Service-Response-Time
Sm-Log-Id
Is-Eu
SEZNAM-JOBS-OFFER
X-Dispatcher-Number
Adler-Geo
X-Datacenter
CacheControlHeader
X-Ssense-Gql
X-Varnish-Beresp-TTL
X-Ssense-Shipping-Surcharge-Enabled
X-Pass-Why
X-SERVER-NAME
Tcn
X-Nginx-Cache-Key
WZWS-RAY
X-Stale
X-Udemy-Cache-App-Namespace
X-FPC
X-Client-Ip
X-RateLimit-Limit
Srv
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-Dynatrace-Js-Agent
X-Oracle-Dms-Rid
X-Geo-Header
X-Air-Pt
X-APP-VERSION
T-Server
Lb
X-VWS-Id
X-AWS-Id
X-Custom-Header
X-LJ-Flow-ID
X-TX-ID
X-Provided-By
X-ND-Cache
X-Fastly-Cache-Status
Origin-Site
Server-Id
X-Debug-Service
Hostname
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Cf-Ipcountry
X-App
X-CMSURLCustom
NtCoent-Length
X-Cache-Server
X-Varnish-Hostname
Serverhost
Vc-Max-Age
X-SRCache-Key
X-Vc
X-Akamai-Pragma-Client-IP
X-Fastly-Backend-Reqs
X-WA
Pics-Label
X-Correlation-ID
X-NC
X-VCL-Version
Edge-Cache
X-Lb-Id
X-Cache-Ttl
S-Rt
X-Cdn-Cache-Status
ServerHost
X-Ha-Backend
X-Via-PopH
X-Via-PopV
X-Via-PopN
Powered-By
Pragrma
Av-Poweredby
X-Oracle-DMS-ECID
X-Html-Minification-Powered-By
X-XRDS-LOCATION
X-Esi
Cache-Tv-Group
Epwk-X-Cache
X-Rocket-Build-Number
Cloudfront-Viewer-Country
X-ServedByHost
X-Sigma-Backend
X-Sigma
Vix-Hermes-Req-Id
X-Region-Sid
X-Cache-TTL-Remaining
X-Forwarded-Site
Geoip-Latitude
Machine
YJS-ID
X-LAGOON
Nord-Request-ID
X-Requestid
Xkey-La3
Xkeylog
X-Fastly-Cache
Ms-Author-Via
X-Traceid
X-Proxy-Cache-La3
X-Ckpd-Fst-Backend
WWW-Authenticate
WebServer
CountryCode
X-MSEdge-Flight
X-MSEdge-Features
X-HS-Status
X-Lb-Nocache
X-Sucuri-Id
On-Server
Thinkindot-Control
Warning
X-Wp-Cf-Super-Cache
X-IAuth-Set-Uid
Reporter
X-Wp-Cf-Super-Cache-Cache-Control
FSS-Cache
DataCenter
X-Check-Cacheable
X-Akamai-ERPolicy
X-Serial
X-Akamai-ERRuleID
MIME-Version
X-Ee-Request-Date
X-Mg-Cache
Yjs-Id
Store-Cloud-Cache
Time-Cloud-Cache
X-Akamai-Transformed
X-Cdn-Request-ID
X-Cms-Device
X-Ee-Origin
X-Amz-Meta-Opti
X-Ee-Request-Id
X-Ee-Generated-By
X-Save-Cache
X-BBC-Origin-Response-Status
X-Vary-Devices
X-Dw-Trace-Id
X-Tncms-Bot-Tier
Cneonction
Timeexpire
X-Elasticpress-Query
X-Orig-Cache-Control
Thinkindot-Cache-Type
AKAMAI
X-Lsadc-Cache
X-VTEX-Cache-Backend-Header-Time
X-VTEX-Cache-Backend-Connect-Time
X-Td-Header-From-No-Data
X-Web-Server
X-PHP-Backend