Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
X-Xss-Protection
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
P3p
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-FRAME-OPTIONS
X-Drupal-Dynamic-Cache
X-Request-ID
X-Ua-Compatible
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Accept-CH-Lifetime
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Cache-Group
X-Age
X-Vhost
X-Proxy-Cache
X-Turbo-Charged-By
EagleId
Keep-Alive
X-Rq
X-Via
X-Dispatcher
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Litespeed-Cache
Xkey
X-Varnish-Cache
X-WebKit-CSP
Grace
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Check
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Dns-Prefetch-Control
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Device
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-Node
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Country
X-Server-Id
X-Country-Code
Content-Location
X-Nginx-Cache-Status
X-Url
Cache-Tag
X-Content-Type
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
Fastly-Restarts
X-LiteSpeed-Cache
X-Clacks-Overhead
X-Trace
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Application-Context
X-Amz-Server-Side-Encryption
X-Times
X-NWS-LOG-UUID
X-TtlSet
X-PC
Surrogate-Key
X-Vname
X-Mcache
X-Edge
Rating
X-Midtier
X-Server-Name
X-Cache-TTL
X-Middleton-Display
X-Sol
Pagespeed
Display
X-Cnection
X-Powered-By-Plesk
X-Abt-Application-Version
X-Element-Page-Cache
X-Browser-Type
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-GitHub-Request-Id
X-ESI
Nginx-Cache
X-Server-ID
X-Vcap-Request-Id
Edge-Control
X-D2id
X-ORACLE-DMS-RID
Verso
X-Ac
X-Ser
X-MS-InvokeApp
X-ECACHE
X-Ratelimit-Limit
X-Amz-Rid
X-Client-IP
X-Wormhole-Sdk
Response
X-Middleton-Response
X-Oneagent-Js-Injection
X-CST
X-Goog-Hash
X-ARC
X-B3-TraceId
X-Powered-CMS
X-Dw-Request-Base-Id
X-Ratelimit-Remaining
X-FTR-Request-ID
X-Navigation-Version
X-Edge-Location-Klb
X-Kinsta-Cache
X-Instrumentation
X-Server-Lifecycle-Phase
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Upstream
X-Forwarded-For
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
Origin-Trial
X-Cache-Key
X-Mod-Pagespeed
RTSS
Edge-Cache-Tag
X-Content-Digest
Cache-Status
Public-Key-Pins
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
X-Ezoic-Cdn
X-FastCGI-Cache
X-Ttl
X-Daa-Tunnel
X-ORACLE-DMS-ECID
X-Version
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Mg-S
X-Pinterest-Rid
Pinterest-Generated-By
Realpath
Pinterest-Version
X-MSEdge-Ref
S
X-Recruiting
X-Shield-Request-Id
X-T
X-Fastly-Request-ID
Front-End-Https
Fastcgi-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-Xrds-Location
X-Distributor
Cross-Origin-Resource-Policy
X-Cached
AR-CACHE
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Azure-Ref
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Correlation-Id
TP-Cache
Count-Hit
X-TTL
X-Debug
X-Id
X-Nf-Request-Id
X-Ua-Browser
X-Ismobilevalue
Cache-Tags
X-Cluster-Name
X-LLID
X-Newrelic-App-Data
X-TraceId
X-NGENIX-Cache
Server-Node
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
MicrosoftSharePointTeamServices
Akamai-GRN
X-Hits
X-Varnish-TTL
X-PressLabs-Stats
X-Varnish-Backend
X-Frontend
X-Protected-By
X-VARITI-CCR
X-HS-Combine-CSS
X-Aspnetmvc-Version
X-Amz-Replication-Status
X-Goog-Metageneration
X-Fastcgi-Cache
Accept-Ch
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Ratelimit-Reset
Payment
X-Page-Id
X-DIS-Request-ID
X-FB-Debug
X-Unique-Id
X-Git-Hash
X-Activity-Id
X-Logged-In
X-AppVersion
X-Az
Cleartype
X-Hostname
X-Www-Served-By
Content-Disposition
X-Varnish-Ttl
X-Varnish-Server
X-Tt-Trace-Tag
X-Jurisdiction
X-HP-Trace-Id
X-Tt-Trace-Host
X-HP-Webp
X-Cambria-Cache-Control
X-Template
Host
X-Amz-Apigw-Id
X-Amzn-RequestId
Filterid
X-Forwarded-Proto
X-App-Server
Amp-Access-Control-Allow-Source-Origin
X-Geo-Country
Version
X-Load-Cache
Accept-Charset
X-Goog-Stored-Content-Encoding
X-Envoy-Decorator-Operation
MRF-Tech
X-Goog-Generation
X-B3-TraceId-Primal
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
Mrf-Cache-Status
Frame-Options
X-Aspnet-Version
X-Source
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Access-Control-Allow-Method
Fastly-SIE
X-Type
X-Cache-Age
Fastly-SWR
X-ASPNET-VERSION
Section-Io-Cache
Trailer
X-HS-Prerendered
X-Upgrade-Enabled
X-Content-Options
X-Fb-Rlafr
X-TT
Viewport
X-Origin-Server
Server-Name
X-B3-Sampled
X-B
X-Grace
X-Ah-Environment
X-Language
X-Cache-Control
X-Device-Type
X-TEC-API-ORIGIN
X-Rid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Buckets
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend-Server
Retry-After
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
Content-MD5
MS-Author-Via
X-Px
X-Magnolia-Registration
X-Mobile
X-Vcl-Version
X-Request-Guid
X-Cdn
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
TCN
X-Trace-Id
X-Revision
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Akamai-Edgescape
Protected
Healthy
X-WP-CF-Super-Cache-Active
X-Backend-Name
Accept-Ch-Lifetime
Upgrade-Insecure-Requests
Cross-Origin-Embedder-Policy-Report-Only
Charset
X-Debug-Info
X-Response-Served-From
SD-X-WS
X-App-Environment
X-Original-Request-Id
X-Proxy
X-RM-Cache-TTL
X-Tumblr-User
X-Instance
X-Is-Bot
X-CSRF-Token
X-RemovedCookies
X-ProcessESI
X-ServerID
X-Tumblr-Pixel
X-Rendered-As
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-NYM-Debug-Backend
X-Rule
Cross-Origin-Window-Policy
X-Status
X-Node-Name
X-Storage
X-UUID
Access-Control-Request-Headers
X-Mg-Request-UUID
X-FW-Type
X-FW-Serve
X-FW-Static
X-FW-Server
X-Cache-Time
X-Adobe-Loc
X-FW-Version
X-Framework
NGB
X-FW-Dynamic
X-FW-Hash
X-Adobe-Content
X-Cacheable-TTL
X-Content-Powered-By
X-Datadog-Trace-Id
X-Debug-IsConnected
X-Debug-IsPreview
X-Proxy-Cache-Info
X-Datadog-Sampling-Priority
X-Datadog-Sampled
Ms-Operation-Id
X-RTag
Refresh
X-Datadog-Parent-Id
MS-CV
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Region
X-Whom
X-G
X-Edge-Location
X-L-Path
GEO-INFO
OT-Force-Account-Verify
X-Environment-Context
X-Lambda-Id
X-Contextid
Webserver
Section-Io-Id
X-ECache
X-Resp-Is-Stale
X-Amzn-Remapped-Content-Length
X-Reqid
DC
Countrycode
X-B3-Traceid
X-Hcs-Proxy-Type
X-Amz-Meta-S3cmd-Attrs
X-Origin-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-User-Agent
X-Server-W
X-VC
Paypal-Debug-Id
X-HTML-Minification-Powered-By
Alternate-Protocol
X-Real-IP
Front
X-Time
X-RateLimit-Remaining
X-Seen-By
X-B3-SpanId
X-DataDome
X-TT-LOGID
Cross-Origin-Opener-Policy-Report-Only
X-HS-CF-Cache-Status
Priority
X-WebKit-CSP-Report-Only
SRV
WPO-Cache-Status
X-WP-CF-Super-Cache-Cookies-Bypass
WPO-Cache-Message
X-Hl-Ver
Liferay-Portal
Ohc-File-Size
X-Origin-CC
X-Origin-TTL
X-Rocket-Nginx-Serving-Static
Xet-Cookie
X-Mode
Backend
X-Akamai-Request-ID2
X-IPS-LoggedIn
Onion-Location
X-Nginx-Cache
X-AB
X-Redis-Cache
X-Say-Cacheable
X-SaId
X-Say-TTL
X-SayCDN-TTL
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-Rn-Rsrv
X-Rewrite-Enabled
ServerID
Meta-Geo
X-Cache-Action
X-Cache-Host
X-JoinUs
X-FB-TRIP-ID
Fastcgi-Useragent
Filters
X-N
Country
X-Cache-Status-Check
Environment
From-Origin
X-DynaTrace
X-Vcache
X-Loop
X-VC-Cache
X-Labrador-Cache-Channel
Property-Id
X-IPLB-Instance
X-Tumblr-Pixel-3
X-IPLB-Request-ID
Expiry
X-Tb
X-Tncms
X-Scope-Id
X-Origin-Date
X-Origin-Hint
X-PHP-Host
X-Restarts
X-Skip-Cache
X-Soup
DB-Nickname
X-R9-Blue-Green-Version
X-Ms-Request-Id
X-Ms-Version
X-Varnish-Age
TWC-Connection-Speed
X-Hosted-By
X-Detected-As
X-Accel-Version
Webcakes-Region
X-Handled-By
X-Connection-Hash
X-Fetched-On
X-Cluster-Node
X-Format
X-Cms-Context
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Locale-Group
TWC-Privacy
X-Director
Web-Mar-Node
Uber-Trace-Id
Apigw-Requestid
X-ProxyCache-Status
X-Adobe-Source
X-Logging-Id
Mn-Server-Ip
X-Httpd
X-Frame-Option
X-Cache-Expired-At
X-BYPASS-REASON
Atl-Traceid
X-ProxyCache-Key
X-Varnish-Cache-Hits
X-Webstats-RespID
X-Varnish-Beresp-Grace
X-Web-Node
X-Served-From
X-Servername
X-Auth-Group-Type
Url
X-Timing-Wait
X-Proxy-Build
Selected-Fe
X-Forwarded-Host
ServedBy
X-Zipkin-Id
X-Extlb
X-Cloudmap
X-S
X-Routing-Service
X-Cluster
X-Origin
X-Proxied
X-SRV
X-Azure-Ref-OriginShield
Surrogated-Key
X-Fastly-Request-Id
X-RateLimit-Remaining-Second
Accept-Language
X-Worker
X-RateLimit-Limit-Second
X-Request-URI
X-LSADC-Cache
Cross-Origin-Embedder-Policy
X-Hit
LB
X-Lagoon
X-Cache-Hit
X-Sucuri-Cache
Referer-Policy
N-Cache
X-Generation-Time
X-Drupal-Cache-Tags
X-Generated-By
X-Drupal-Cache-Contexts
X-CDN-Forward
X-Cdn-Origin
X-Sucuri-ID
X-App-Version
X-MP-GENERATED-AT
Xserver
CDN-RequestId
CF-IPCountry
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-F-Cache
Source
X-Xfnlog-Site
X-Tx-Id
X-TA-CDN-Provider
Ohc-Cache-HIT
Node
X-Wix-Request-Id
X-Mly-Id
Cache
X-Via-SSL
X-Via-CDN
X-Via-Edge
Edge-Copy-Time
X-Cache-Debug
X-AIR-PT
X-Cache-Rule
X-VC-TTL
X-Pad
X-RCS-CacheZone
X-NODE
X-VCT
X-INCAP-ABP
X-Varnish-Beresp-Ttl
Cache-Provider
X-Site-Version
X-Locale
X-NWS-UUID-VERIFY
X-Browser-Name
X-Tcp-Rtt
X-XRDS-Location
X-ElasticPress-Query
Locale
X-GEO
X-Is-Desktop
X-Urbn-Context-Path
X-Geo-Region
X-Urbn-Site-Id
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
Sslversion
Host-ID
X-Slack-Shared-Secret-Outcome
X-Ec-GeoHdr
X-Origin-Time
X-Litespeed-Tag
X-D
X-FC-Vary-Parameters
Xc-Version
X-Ig-Push-State
X-Bug-Bounty
X-Proxied-Request
X-Org
X-Cache-NE
X-Jobs
X-Nyt-Route
Fl-Custom-Application
Rendered-Blocks
X-S-Cookie
MD5-Digest
X-Platform-Server
X-ScT
X-Rojux
Meta-Geo-Continent
Ngx.Var.Host
X-UA
Odigeo-Trace-Id
X-Geolocation
Producers
X-SD-PageType
X-Conf
X-Slack-Backend
X-PAYTM-SRV-ID
X-Proto
X-Cache-Grace
Redirect-Candidate
X-External-Request-Id
Mail-Subject
Lang
X-Path
We-Hiring
X-Aed
X-Aicache-OS
Candidate-Md5Url
X-GeoIP-Country-Code
X-Gdpr
X-Backend-Instance
X-A-Dgt
X-A-Wwc
Expect-Staple
X-B-Cookie
DCR-Processing-Time-Ms
Cluster
X-Application
X-Destination
X-Vdms-Version
X-No-Session
X-Developer
DCR-Decision-By
X-GeoIP-Region-Code
X-Ig-Origin-Region
X-A-Dcw
X-A-Dam
X-HS-Content-Campaign-Id
X-BCube-Filmed-By
X-Cache-Operation
BehaviorPad-Version
Fastly-Backend-Name
X-Debug-Cache-Fetch
Web-Mar-Region
Fastly-GeoIP-CountryCode
X-Ec-Fail
X-Mvc-Supplant-Cachable
X-A-Ccd
X-Debug-Cache-Store
X-GeoCountry
X-DPWN-IS-SECURE
X-A
X-GeoCode
X-Bc-Bl
X-Vtex-Remote-Cache
X-Bl-Debug
X-B-Cache
X-Signature
X-Oracle-Dms-Ecid
Cdncip
Debug
Gh-Request-Id
Ha-Gx-Prefs
X-Cache-Id
Gannett-Cam-Experience-Id
Fastly-SSL
HA-Ipaddr
X-Cache-Info
Content-Script-Type
Content-Style-Type
L5d-Success-Class
X-Powered-By-VTEX-Cache
Cdnsip
TDXMobile
X-AB-Test
X-Accel-Expires-Debug
X-Access
Wxu-Next-Region
Wxu-Next-Hostname
V-Age
X-Mvc-Supplant-OutputCached
Wxu-Next-Commit
X-AK-Request-ID
X-Micro-Cache
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Block-Status
X-Auto-Login
X-App-Name
X-Amz-Meta-Cb-Modifiedtime
X-Amz-Storage-Class
X-Location
User-Cache-Control
X-NMSegId
Product
X-Platform
Req-Svc-Chain
Platform
X-Policy
Origin
Origin-Agent-Cluster
PFcat
RNT-Machine
RNT-Time
Thinkindot-CacheControl-Type
X-Op-Id-All
X-Node-Id
Thinkindot-CacheControl
X-Loc
Server-Host
X-Origin-Expires
X-Cache-Date
NM-Fastcgi-Cache
Azure-InstanceId
X-Hash
X-HN
X-Generated-On
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Esi-Check
X-Epic-Correlation-Id
X-Hnp-Log
X-Clientip
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Thinkindot-L3
Mime-Version
X-Request-Time
X-GoCache-CacheStatus
X-SB
X-Scheme
X-Csrf-Jwt
X-CUA
X-Shield-Cache-Expires
X-Core-Value
X-Level-Front-Cache
X-Content-Age
X-Gzip
X-Cached-By
X-Eu-Site
X-Date
X-Gen-Mode
X-Section
X-Gamma-Serve
X-Fastly-Backend
X-DefElseHash
X-VServer
X-VG-WebCache
X-V-Cache
X-CGP
X-User
X-Via-Fastly
Canary
X-VarnishDD-TTL
X-Ec-Custom-Error
X-CacheTTL
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Director
X-Varnish-Remaining-TTL
X-Dispatcher-Server
X-GeoIP-City
X-Human
X-Request-Host
X-Req
X-DefHash
X-Viewer-Country
X-GeoIP
X-Vmg-Version
Apple-News-Services-Handled
Apple-News-Services-Host
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Fmm-Version
Akamai-Mon-Iucid-Del
X-Storefront-Renderer-Rendered
X-NGINX-Cache
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Alternate-Cache-Key
X-ShardId
X-Sorting-Hat-ShopId
X-Akamai-Device-Characteristics
X-Pubstack
X-TIM-N
X-Request-Start
L
X-UA-Device-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Depends
Click-Count-Action-Start
Click-Count-Error
Cdn-Request-Time
X-Bip
X-Varnish-Authentication
X-Varnish-Beresp-Status
X-Edge-Server
Cdn-Host
DSUID
X-Men
CDCHOST
Country-Code
Content-Secure-Policy
X-VG-TLSProxy
X-Thanos
NGX
X-SVT-ORM-VERSION
Req-ID
X-Server-IP
Yak-Timeinfo
X-Internal-TTL
X-NodeID
X-IsAdmin
X-Via-JSL
X-Origin-Response-Time
ServerName
X-Sn-Servicetimems
X-Contensis-Viewer-Groups
X-SVT-ORM-RULES
X-Content-Length
Tube-Get-Contents
X-Cache-FS-Status
W
Origin-EX
Origin-CC
X-We-Are-Hiring
X-Pool
Tube-Got-Eval
Release
X-Zen-Fury
Tube-Return
Tube-Got-Results
X-Cache-Aspx
X-Service
X-Ua-Device
X-Irp-Debug
X-Cdn-Srv
CDN-Uid
CDN-EdgeStorageId
CDN-PullZone
X-Tb-Optimization-Total-Bytes-Saved
CDN-CachedAt
CDN-Cache
X-TH-Server
XM
CDN-RequestCountryCode
CDN-RequestPullCode
Ssr
CDN-RequestPullSuccess
User-Agent
X-URL
X-Vgn-Hpd-Reason
X-Varnishpool
X-RID
X-Var-Ttl
X-HOST
X-SIPLIST1
X-Cs
IsBot
Sid
X-LB-NoCache
Fastly-Drupal-HTML
X-CACHE-GROUP
X-Old-Content-Length
X-DC
X-Varnish-Hits
Pramga
X-Moov-Xdn-Version
X-Moov-T
X-Moov-Xdn-Caching-Status
X-Proxy-Cache-Status
GeoIP-Latitude
N1-Cache
X-Refresh
X-ORCA-Accelerator
X-HubSpot-Correlation-Id
X-Api-Version
Esi-Enabled
X-RequestId
X-Tt-Logid
X-HITS
CloudFront-Viewer-Country
X-ZONE
X-Servedbyhost
X-Upstream-Ct
X-Upstream-Ht
X-Presslabs-Stats
X-APP
X-Via-Poph
X-Via-Popn
AMP-Access-Control-Allow-Source-Origin
X-CLOUD-TRACE-CONTEXT
X-Via-Popv
X-Wa
X-HA-Backend
C-Via
Cdn-Requestid
X-Action
X-Nc
X-Newrelic-Synthetics
Cache-Hits
X-Vercel-Id
X-Thinkindot-L1
Location
X-Cache-VC
X-LB-ID
X-Vercel-Cache
Server-ID
X-Cache-Bucket
TWC-GeoIP-Region
TWC-GeoIP-City
TWC-GeoIP-DMA
X-LiteSpeed-Cache-Control
X-DynaTrace-JS-Agent
X-Proxy-CacheRZ
X-Parent-Response-Time
HostName
A
XkeyRZ
X-LiteSpeed-Tag
X-Dc
Cache-Key
X-Zone
X-Ua
X-Webkit-CSP
X-NewRelic-App-Data
X-B3-Parentspanid
X-Nananana
X-B3-Spanid
Fastly-Drupal-Html
X-Webkit-Csp-Report-Only
X-PERF
X-ApacheServer
X-COUNTRY
X-Endurance-Cache-Level
X-Cdn-Forward
X-Webkit-Csp
X-CS
X-Render-Time
SID
WP-Super-Cache
Proxy-Firewall
X-WA-Info
X-Srv
X-CACHE-AGE
X-Litespeed-Cache-Control
X-API-Version
GeoIp-Country-Code
Uri
X-Nitro-Cache
X-DataCenter
X-Uri
X-Fpc
RewriteTestHook
RewriteTeamHook
Cache-Contol
TP-L2-Cache
X-Jungle-Id
X-Ion-Hop
X-Ion-Healthy
Cmsid
True-Client-IP
My-App
Server-Ext
Server-Hostname
True-Client-Country-4JS
Cmstype
True-Client-Ip
X-Optimistic-Header
Sever-Int
X-Datadome
X-Test
GeoIP-Country-Code
X-Up
Log-Origin
Resin-Trace
X-From
AKAMAI-GRN
Cdn
X-Service-Response-Time
Sm-Log-Id
X-Ssense-Shipping-Surcharge-Enabled
SEZNAM-JOBS-OFFER
Is-Eu
Adler-Geo
X-Dispatcher-Number
X-Varnish-Beresp-TTL
X-Datacenter
CacheControlHeader
X-Ssense-Gql
X-Pass-Why
X-SERVER-NAME
WZWS-RAY
Tcn
X-Udemy-Cache-App-Namespace
X-FPC
X-Nginx-Cache-Key
X-Stale
X-Client-Ip
X-RateLimit-Limit
Srv
X-Srcache-Store-Status
X-Dynatrace-Js-Agent
X-Srcache-Fetch-Status
X-APP-VERSION
X-LJ-Flow-ID
X-AWS-Id
X-Air-Pt
X-TX-ID
X-Geo-Header
Lb
X-Oracle-Dms-Rid
X-VWS-Id
T-Server
X-Custom-Header
X-ND-Cache
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Origin-Site
Server-Id
X-Fastly-Cache-Status
X-Provided-By
Hostname
X-Debug-Service
Cf-Ipcountry
X-SRCache-Key
Vc-Max-Age
Serverhost
NtCoent-Length
X-CMSURLCustom
X-App
X-Cache-Server
X-Varnish-Hostname
X-Vc
X-Lb-Id
X-VCL-Version
X-Fastly-Backend-Reqs
Edge-Cache
X-Akamai-Pragma-Client-IP
X-NC
X-Correlation-ID
Pics-Label
X-WA
S-Rt
X-Cache-Ttl
Av-Poweredby
ServerHost
X-Html-Minification-Powered-By
X-Via-PopV
X-Ha-Backend
X-Via-PopH
X-Oracle-DMS-ECID
X-Via-PopN
Powered-By
X-Cdn-Cache-Status
Pragrma
X-XRDS-LOCATION
X-Esi
Cache-Tv-Group
Machine
YJS-ID
Epwk-X-Cache
Vix-Hermes-Req-Id
X-Sigma-Backend
X-Sigma
X-Cache-TTL-Remaining
Geoip-Latitude
X-ServedByHost
X-Rocket-Build-Number
X-Forwarded-Site
X-Region-Sid
Cloudfront-Viewer-Country
X-LAGOON
Nord-Request-ID
X-Requestid
Xkey-La3
Xkeylog
X-Fastly-Cache
X-Proxy-Cache-La3
Ms-Author-Via
WWW-Authenticate
X-Ckpd-Fst-Backend
X-Traceid
WebServer
CountryCode
X-MSEdge-Flight
X-Sucuri-Id
Thinkindot-Control
On-Server
X-MSEdge-Features
X-Lb-Nocache
Warning
X-HS-Status
X-Wp-Cf-Super-Cache-Cache-Control
Reporter
X-IAuth-Set-Uid
DataCenter
X-Wp-Cf-Super-Cache
FSS-Cache
X-Check-Cacheable
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Serial
MIME-Version
Store-Cloud-Cache
X-Akamai-Transformed
Time-Cloud-Cache
X-Ee-Request-Date
X-Mg-Cache
X-Ee-Request-Id
Yjs-Id
X-Ee-Origin
X-Ee-Generated-By
X-Cdn-Request-ID
X-Cms-Device
X-Amz-Meta-Opti
X-Save-Cache
X-Tncms-Bot-Tier
X-Vary-Devices
X-Dw-Trace-Id
X-BBC-Origin-Response-Status
Cneonction
Timeexpire
X-Elasticpress-Query
X-Orig-Cache-Control
Thinkindot-Cache-Type
AKAMAI
X-Lsadc-Cache
X-VTEX-Cache-Backend-Header-Time
X-VTEX-Cache-Backend-Connect-Time
X-Td-Header-From-No-Data
X-Web-Server
X-PHP-Backend