Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
X-Xss-Protection
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
P3p
X-FRAME-OPTIONS
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-Drupal-Dynamic-Cache
X-Request-ID
X-Ua-Compatible
Feature-Policy
Accept-CH-Lifetime
X-Content-Security-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
Cf-Apo-Via
X-Hacker
X-Age
X-Cache-Group
X-Vhost
X-Proxy-Cache
EagleId
X-Turbo-Charged-By
Keep-Alive
X-Rq
X-Via
X-Dispatcher
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
Xkey
X-Varnish-Cache
X-Litespeed-Cache
X-WebKit-CSP
Grace
X-Server-Powered-By
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Check
X-Dns-Prefetch-Control
X-Device
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-HW
X-Node
Request-Id
X-Ruxit-JS-Agent
X-Server-Id
X-Country-Code
X-Country
Content-Location
X-Nginx-Cache-Status
Cache-Tag
X-Content-Type
X-LiteSpeed-Cache
X-Nginx-Upstream-Cache-Status
X-Url
Service-Worker-Allowed
Fastly-Restarts
X-Clacks-Overhead
X-Trace
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Application-Context
X-Amz-Server-Side-Encryption
X-Times
X-NWS-LOG-UUID
Surrogate-Key
X-PC
X-Vname
X-TtlSet
Rating
X-Midtier
X-Mcache
X-Edge
X-Server-Name
X-Cache-TTL
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Oneagent-Js-Injection
X-Cnection
X-Powered-By-Plesk
X-Element-Page-Cache
X-Abt-Application-Version
X-Kinja
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Browser-Type
X-Kinja-Server
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-GitHub-Request-Id
X-ESI
Nginx-Cache
X-Vcap-Request-Id
Edge-Control
X-ECACHE
X-Ruxit-Js-Agent
X-D2id
X-Ac
X-ORACLE-DMS-RID
Verso
X-MS-InvokeApp
X-Ser
X-Server-ID
X-Ratelimit-Limit
X-Amz-Rid
X-Client-IP
X-Wormhole-Sdk
Response
X-Middleton-Response
X-Ratelimit-Remaining
X-FTR-Request-ID
X-CST
X-Goog-Hash
X-ARC
X-Powered-CMS
X-B3-TraceId
X-Navigation-Version
X-Dw-Request-Base-Id
X-Kinsta-Cache
X-Edge-Location-Klb
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Upstream
X-Forwarded-For
Origin-Trial
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
X-FastCGI-Cache
X-Mod-Pagespeed
X-Cache-Key
X-Content-Digest
Edge-Cache-Tag
RTSS
Cache-Status
Public-Key-Pins
AR-SID
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Ezoic-Cdn
X-NF-Request-ID
X-Version
X-Ttl
X-SharePointHealthScore
SPRequestGuid
X-Daa-Tunnel
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Fastly-Request-ID
X-Mg-S
Realpath
X-MSEdge-Ref
X-Recruiting
X-ORACLE-DMS-ECID
X-Shield-Request-Id
S
X-T
Front-End-Https
Fastcgi-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Accel-Expires
X-Distributor
Cross-Origin-Resource-Policy
X-Cached
AR-CACHE
X-Xrds-Location
Arr-Disable-Session-Affinity
X-Azure-Ref
Access-Control-Request-Method
X-TTL
Akamai-GRN
X-Varnish-TTL
X-Correlation-Id
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Content-Id
TP-Cache
Cache-Tags
Count-Hit
X-HS-Cache-Config
X-Id
X-Debug
X-Ua-Browser
X-Ismobilevalue
X-TraceId
X-Cluster-Name
X-NGENIX-Cache
X-LLID
X-Nf-Request-Id
Server-Node
MicrosoftSharePointTeamServices
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
X-Aspnetmvc-Version
X-Varnish-Backend
X-Frontend
X-Newrelic-App-Data
X-PressLabs-Stats
X-VARITI-CCR
X-Protected-By
Accept-Ch
X-HS-Combine-CSS
X-Amz-Replication-Status
X-Hits
X-Goog-Metageneration
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Unique-Id
X-Ratelimit-Reset
X-Page-Id
X-DIS-Request-ID
Payment
X-FB-Debug
X-Git-Hash
Cleartype
X-Logged-In
X-AppVersion
X-Az
X-Activity-Id
X-Tt-Trace-Tag
X-Tt-Trace-Host
Content-Disposition
X-Hostname
X-Varnish-Server
X-Www-Served-By
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Cambria-Cache-Control
X-Template
Host
X-Amz-Apigw-Id
X-Amzn-RequestId
Filterid
Amp-Access-Control-Allow-Source-Origin
X-Forwarded-Proto
X-Fastcgi-Cache
X-App-Server
X-Geo-Country
X-Aspnet-Version
X-Varnish-Ttl
Version
X-Load-Cache
X-ASPNET-VERSION
Accept-Charset
X-Envoy-Decorator-Operation
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
Mrf-Cache-Status
Trailer
X-Source
MRF-Tech
Frame-Options
X-B3-TraceId-Primal
X-WP-CF-Super-Cache-Cache-Control
X-Type
X-WP-CF-Super-Cache
Fastly-SWR
X-Ah-Environment
Fastly-SIE
Section-Io-Cache
Viewport
X-HS-Prerendered
X-Upgrade-Enabled
X-TT
Access-Control-Allow-Method
X-Content-Options
X-Fb-Rlafr
Server-Name
X-Grace
X-B3-Sampled
X-Origin-Server
X-Language
X-Cache-Age
X-B
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Device-Type
X-Cache-Control
X-Buckets
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Rid
X-Px
Retry-After
MS-Author-Via
X-TEC-API-VERSION
X-Cdn
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Tec-Api-Version
Content-MD5
X-Tec-Api-Origin
X-Tec-Api-Root
X-Magnolia-Registration
X-Mobile
X-Request-Guid
X-Vcl-Version
TCN
X-Trace-Id
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Revision
X-Akamai-Edgescape
Protected
X-WP-CF-Super-Cache-Active
Healthy
X-Backend-Name
Cross-Origin-Embedder-Policy-Report-Only
Charset
X-Proxy
Upgrade-Insecure-Requests
X-Instance
X-Original-Request-Id
SD-X-WS
X-Response-Served-From
X-RM-Cache-TTL
X-Debug-Info
X-App-Environment
X-NYM-Debug-Backend
X-RemovedCookies
X-ProcessESI
X-Tumblr-User
X-Status
X-Rendered-As
X-Tumblr-Pixel
X-ServerID
X-Is-Bot
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-FW-Type
X-FW-Serve
X-FW-Server
NGB
X-FW-Static
X-Adobe-Loc
Access-Control-Request-Headers
X-Cacheable-TTL
X-CSRF-Token
X-Cache-Time
X-Framework
X-FW-Dynamic
Cross-Origin-Window-Policy
X-FW-Hash
X-FW-Version
X-Node-Name
X-Storage
X-UUID
X-Adobe-Content
X-Mg-Request-UUID
X-Rule
X-Debug-IsConnected
Refresh
X-Edge-Location
Ms-Operation-Id
MS-CV
X-Content-Powered-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Debug-IsPreview
X-RTag
X-Region
X-Proxy-Cache-Info
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
GEO-INFO
X-Datadog-Sampled
X-Datadog-Trace-Id
X-G
X-Whom
OT-Force-Account-Verify
X-L-Path
X-Environment-Context
X-Lambda-Id
X-Resp-Is-Stale
Section-Io-Id
Webserver
X-Contextid
X-B3-Traceid
X-Reqid
X-Amzn-Remapped-Content-Length
X-TT-LOGID
Countrycode
DC
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Origin-Cache
X-Server-W
X-HTML-Minification-Powered-By
X-User-Agent
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
X-ECache
X-Real-IP
Alternate-Protocol
Cross-Origin-Opener-Policy-Report-Only
Front
X-WebKit-CSP-Report-Only
X-HS-CF-Cache-Status
X-Time
Priority
SRV
X-B3-SpanId
X-VC
X-DataDome
X-Seen-By
Ohc-File-Size
WPO-Cache-Message
WPO-Cache-Status
Accept-Ch-Lifetime
X-WP-CF-Super-Cache-Cookies-Bypass
Liferay-Portal
X-Hl-Ver
X-Rocket-Nginx-Serving-Static
X-Origin-CC
X-Mode
X-Origin-TTL
Backend
Xet-Cookie
X-IPS-LoggedIn
X-Akamai-Request-ID2
Onion-Location
X-Rewrite-Enabled
TWC-Locale-Group
X-Say-Cacheable
X-Origin-Hint
X-Rn-Rsrv
TWC-Device-Class
X-Redis-Cache
Meta-Geo
Filters
Fastcgi-Useragent
X-Format
X-JoinUs
X-RateLimit-Remaining
ServerID
Property-Id
TWC-Connection-Speed
X-SaId
X-AB
Webcakes-App-Name
X-FB-TRIP-ID
Webcakes-App-Version
X-Tumblr-Pixel-3
Webcakes-Region
X-UPSTREAM-Address
TWC-GeoIP-LatLong
Web-Mar-Node
X-Cache-Host
X-Cache-Action
TWC-Privacy
X-SayCDN-TTL
X-Say-TTL
TWC-GeoIP-Country
X-Tumblr-Pixel-2
Expiry
X-Accel-Version
X-Vcache
X-IPLB-Request-ID
X-Hosted-By
X-Handled-By
X-IPLB-Instance
Uber-Trace-Id
X-Fetched-On
X-Cache-Expired-At
Country
X-Cms-Context
X-R9-Blue-Green-Version
X-PHP-Host
X-Origin-Date
X-Restarts
X-Tncms
X-Scope-Id
X-Skip-Cache
X-Soup
X-Ms-Version
X-Director
Mn-Server-Ip
X-Cluster-Node
X-Labrador-Cache-Channel
X-VC-Cache
X-Connection-Hash
X-Ms-Request-Id
X-Loop
X-Detected-As
From-Origin
DB-Nickname
X-N
X-Tb
X-Nginx-Cache
X-Cache-Status-Check
X-DynaTrace
Environment
Apigw-Requestid
X-Forwarded-Host
X-Frame-Option
X-Httpd
Url
X-Servername
X-Web-Node
X-BYPASS-REASON
X-ProxyCache-Status
X-Webstats-RespID
X-Adobe-Source
Atl-Traceid
X-ProxyCache-Key
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Logging-Id
X-Varnish-Age
X-Proxy-Build
ServedBy
Selected-Fe
X-Auth-Group-Type
X-Cluster
X-Timing-Wait
X-Served-From
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-Origin
X-S
X-Cloudmap
X-Extlb
X-Hit
X-Azure-Ref-OriginShield
Surrogated-Key
Cross-Origin-Embedder-Policy
X-RateLimit-Remaining-Second
X-Worker
X-RateLimit-Limit-Second
X-LSADC-Cache
LB
X-SRV
X-CDN-Forward
X-Cache-Hit
X-Request-URI
Accept-Language
X-Lagoon
X-Sucuri-Cache
X-HOST
Referer-Policy
X-Generation-Time
N-Cache
X-Drupal-Cache-Tags
X-Fastly-Request-Id
X-Generated-By
X-Drupal-Cache-Contexts
X-Cdn-Origin
X-App-Version
X-Sucuri-ID
Xserver
X-MP-GENERATED-AT
X-Oracle-Dms-Ecid
CF-IPCountry
CDN-RequestId
X-URL
X-XRDS-Location
Ohc-Cache-HIT
X-Tx-Id
X-Xfnlog-Site
X-TA-CDN-Provider
Node
X-F-Cache
Source
X-AIR-PT
X-Mly-Id
X-VC-TTL
Cache
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Wix-Request-Id
X-Via-SSL
X-Via-CDN
Edge-Copy-Time
X-Via-Edge
X-Cache-Rule
X-NODE
X-Cache-Debug
X-Varnish-Beresp-Ttl
X-INCAP-ABP
X-UA
X-RCS-CacheZone
Cache-Provider
X-Pad
X-Site-Version
X-VCT
X-Locale
X-GEO
X-ElasticPress-Query
Wxu-Next-Region
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Hostname
MD5-Digest
Fastly-Backend-Name
Expect-Staple
Fastly-GeoIP-CountryCode
Fastly-SSL
Ha-Gx-Prefs
Fl-Custom-Application
DCR-Processing-Time-Ms
DCR-Decision-By
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Request-Url
BehaviorPad-Version
Cluster
Candidate-Md5Url
HA-Ipaddr
Host-ID
PFcat
Origin
Producers
Redirect-Candidate
Sslversion
Rendered-Blocks
Odigeo-Trace-Id
Ngx.Var.Host
Lang
L5d-Success-Class
Mail-Subject
X-A
Meta-Geo-Continent
We-Hiring
X-Browser-Name
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Mobile
X-Jobs
X-Mvc-Supplant-Cachable
X-Org
X-Op-Id-All
X-Nyt-Route
X-Is-Desktop
X-Ig-Push-State
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-GeoCountry
X-Geolocation
X-HN
X-Ig-Origin-Region
X-HS-Content-Campaign-Id
X-Origin-Time
X-Path
X-Tcp-Rtt
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-VarnishDD-TTL
X-Vdms-Version
Xc-Version
X-Vtex-Remote-Cache
X-Section
X-SD-PageType
X-Proto
X-Platform-Server
X-PAYTM-SRV-ID
X-Proxied-Request
X-Rojux
X-ScT
X-S-Cookie
X-GeoCode
X-Geo-Region
X-BCube-Filmed-By
X-Bc-Bl
X-Backend-Instance
X-Bl-Debug
Apple-News-Services-Handled
X-Cache-Grace
X-Bug-Bounty
X-B-Cookie
X-Application
X-A-Dgt
X-A-Dcw
X-A-Dam
X-AB-Test
X-Access
X-Aicache-OS
X-Aed
X-Cache-NE
X-Cache-Operation
X-Ec-GeoHdr
X-Ec-Fail
X-DPWN-IS-SECURE
X-Eu-Site
X-External-Request-Id
X-Gdpr
X-FC-Vary-Parameters
X-Developer
X-Destination
X-Conf
X-CGP
X-Cached-By
X-Csrf-Jwt
X-D
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-A-Ccd
X-A-Wwc
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-NWS-UUID-VERIFY
X-No-Session
X-NGINX-Cache
X-Micro-Cache
X-Varnish-CookieHashed-On
X-V-Cache
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
X-Mvc-Supplant-OutputCached
X-User
X-Cache-Id
X-Cache-Info
X-Varnish-CookieINHashed-On
X-Level-Front-Cache
Product
X-Clientip
X-VG-WebCache
X-Powered-By-VTEX-Cache
Platform
X-Varnish-Remaining-TTL
X-Loc
X-Varnish-Director
X-Thinkindot-L3
RNT-Time
RNT-Machine
X-Location
Req-Svc-Chain
Server-Host
X-Gen-Mode
X-B-Cache
X-Request-Host
X-Accel-Expires-Debug
X-Request-Time
X-Scheme
X-SB
X-Req
X-AK-Request-ID
X-Auto-Login
X-App-Name
X-Amz-Storage-Class
X-Amz-Meta-Cb-Modifiedtime
X-Akamai-Device-Characteristics
X-Policy
X-Shield-Cache-Expires
X-NodeID
User-Cache-Control
X-Node-Id
Origin-Agent-Cluster
X-NMSegId
V-Age
X-Block-Status
X-B3-Trace-ID
X-Signature
X-Platform
X-BBC-Edge-Cache-Status
X-Origin-Expires
X-Cache-Date
X-Via-Fastly
Content-Script-Type
X-Epic-Correlation-Id
X-Esi-Check
X-GoCache-CacheStatus
X-GeoIP-City
Content-Style-Type
X-Gzip
X-Hnp-Log
X-Dispatcher-Server
X-Ec-Custom-Error
X-Viewer-Country
X-Hash
Cdnsip
Cdncip
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-Gamma-Serve
X-Generated-On
Azure-SlotName
Azure-Version
X-GeoIP
CDCHOST
Canary
X-Fmm-Version
X-Human
Debug
X-Wikidot-Backend
X-Vmg-Version
L
X-VTEX-Cache-Server
X-Wikidot-Static-Cache
X-Core-Value
X-VServer
X-Content-Age
NM-Fastcgi-Cache
X-VTEX-Cache-Time
X-Content-Length
X-Zen-Fury
X-CUA
X-DefHash
Gannett-Cam-Experience-Id
Gh-Request-Id
X-DefElseHash
X-Date
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-ShardId
X-COUNTRY
Akamai-Mon-Iucid-Del
X-Ua-Device
X-Sorting-Hat-ShopId
X-ShopId
X-Pool
X-HITS
X-IsAdmin
X-Fastly-Backend
X-Men
X-Cache-Aspx
X-Cache-FS-Status
X-Internal-TTL
X-Litespeed-Tag
X-Edge-Server
X-Bip
X-Cdn-Srv
X-CacheTTL
X-Depends
X-Origin-Response-Time
X-Contensis-Viewer-Groups
Tube-Got-Results
Origin-EX
Origin-CC
X-Pubstack
X-VG-TLSProxy
Release
X-Varnish-Authentication
X-Varnish-Beresp-Status
Req-ID
X-We-Are-Hiring
XM
Click-Count-Action-Start
Cdn-Request-Time
Cdn-Host
Click-Count-Error
X-TH-Server
Yak-Timeinfo
DSUID
Content-Secure-Policy
ServerName
NGX
Tube-Return
Tube-Got-Eval
X-SVT-ORM-VERSION
W
X-SVT-ORM-RULES
X-Request-Start
X-Sn-Servicetimems
Tube-Get-Contents
X-UA-Device-Type
X-Thanos
X-TIM-N
X-Acquia-Purge-Cdn-Unconfigured
X-Via-JSL
Mime-Version
X-Service
CDN-EdgeStorageId
X-Vgn-Hpd-Reason
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
CDN-RequestPullSuccess
CDN-CachedAt
Country-Code
X-Server-IP
CDN-Uid
X-SIPLIST1
X-RID
X-Tb-Optimization-Total-Bytes-Saved
X-LB-NoCache
Ssr
IsBot
User-Agent
X-Irp-Debug
CDN-Cache
Fastly-Drupal-HTML
X-Varnish-Hits
X-Varnishpool
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Old-Content-Length
X-Var-Ttl
X-Moov-T
X-CACHE-GROUP
Sid
GeoIP-Latitude
Pramga
N1-Cache
X-DC
X-Api-Version
X-NewRelic-App-Data
X-RequestId
CloudFront-Viewer-Country
X-Servedbyhost
X-Proxy-Cache-Status
X-Refresh
X-ORCA-Accelerator
X-Cs
X-ZONE
X-HubSpot-Correlation-Id
Esi-Enabled
X-Presslabs-Stats
X-APP
X-Wa
X-Action
X-Nc
Cache-Hits
TWC-GeoIP-DMA
TWC-GeoIP-Region
TWC-GeoIP-City
Server-ID
X-Vercel-Cache
X-Vercel-Id
X-Upstream-Ct
X-Thinkindot-L1
X-Upstream-Ht
X-Cache-VC
X-LiteSpeed-Tag
Location
C-Via
X-Newrelic-Synthetics
Cdn-Requestid
X-Dc
X-Cache-Bucket
X-Via-Popn
X-Via-Popv
X-HA-Backend
X-Via-Poph
X-CACHE-AGE
X-LiteSpeed-Cache-Control
X-Webkit-CSP
Cache-Key
X-Parent-Response-Time
A
X-Proxy-CacheRZ
X-CS
X-B3-Parentspanid
XkeyRZ
AMP-Access-Control-Allow-Source-Origin
X-Nananana
X-LB-ID
X-B3-Spanid
X-Tt-Logid
X-DynaTrace-JS-Agent
HostName
X-ApacheServer
X-Zone
X-PERF
X-Webkit-Csp
X-Endurance-Cache-Level
Fastly-Drupal-Html
SID
X-DataCenter
X-Render-Time
X-Ua
X-WA-Info
WP-Super-Cache
X-Srv
X-Fpc
GeoIp-Country-Code
Proxy-Firewall
X-Webkit-Csp-Report-Only
X-Uri
X-Nitro-Cache
X-Litespeed-Cache-Control
X-API-Version
RewriteTeamHook
X-Jungle-Id
X-Ion-Healthy
X-Ion-Hop
RewriteTestHook
Cache-Contol
Uri
X-Cdn-Forward
True-Client-IP
TP-L2-Cache
My-App
Cmsid
Log-Origin
Cmstype
X-Up
X-From
X-Datadome
Sever-Int
Server-Ext
Server-Hostname
True-Client-Country-4JS
True-Client-Ip
Resin-Trace
X-Optimistic-Header
X-Service-Response-Time
Sm-Log-Id
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
X-Test
CacheControlHeader
X-CLOUD-TRACE-CONTEXT
GeoIP-Country-Code
X-SERVER-NAME
Tcn
X-Dispatcher-Number
X-Stale
Is-Eu
X-Udemy-Cache-App-Namespace
Adler-Geo
Cdn
SEZNAM-JOBS-OFFER
X-Datacenter
X-Dynatrace-Js-Agent
X-Varnish-Beresp-TTL
X-Pass-Why
X-Client-Ip
X-RateLimit-Limit
X-Nginx-Cache-Key
X-FPC
WZWS-RAY
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Lb
Srv
Hostname
X-Oracle-Dms-Rid
X-APP-VERSION
X-Air-Pt
X-Geo-Header
X-Fastly-Cache-Status
X-Debug-Service
X-Custom-Header
T-Server
X-Air-Trace-Id
Origin-Site
X-Vc
X-Air-Source
X-Air-Hostname
X-TX-ID
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
Server-Id
X-Lb-Id
X-ND-Cache
X-SRCache-Key
X-Varnish-Hostname
X-Provided-By
X-Correlation-ID
X-App
AKAMAI-GRN
X-Cache-Server
Edge-Cache
X-Akamai-Pragma-Client-IP
NtCoent-Length
Vc-Max-Age
X-VCL-Version
Cf-Ipcountry
Serverhost
X-CMSURLCustom
X-Fastly-Backend-Reqs
X-Cache-Ttl
X-Via-PopN
X-Ha-Backend
X-Via-PopH
X-Oracle-DMS-ECID
Pragrma
X-Html-Minification-Powered-By
X-NC
X-WA
X-Via-PopV
ServerHost
Pics-Label
X-Esi
X-XRDS-LOCATION
Powered-By
Epwk-X-Cache
Geoip-Latitude
S-Rt
X-Cdn-Cache-Status
YJS-ID
X-Sigma
X-Sigma-Backend
Machine
X-Rocket-Build-Number
X-Region-Sid
X-Forwarded-Site
X-LAGOON
Av-Poweredby
X-Requestid
Cloudfront-Viewer-Country
Cache-Tv-Group
X-ServedByHost
X-Traceid
Nord-Request-ID
WebServer
WWW-Authenticate
X-Cache-TTL-Remaining
Ms-Author-Via
Vix-Hermes-Req-Id
CountryCode
X-Fastly-Cache
X-Ckpd-Fst-Backend
Xkey-La3
X-HS-Status
X-Proxy-Cache-La3
Warning
Xkeylog
X-Sucuri-Id
X-MSEdge-Flight
MIME-Version
X-MSEdge-Features
Reporter
X-Akamai-ERRuleID
X-Serial
On-Server
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Thinkindot-Control
X-IAuth-Set-Uid
X-Lb-Nocache
X-Check-Cacheable
X-Akamai-ERPolicy
FSS-Cache
Datacenter
Yjs-Id
Coldstone-Viewer-Currency
Cneonction
DataCenter
X-BBC-Origin-Response-Status
Coldstone-Viewer-Country
Coldstone-Viewer-Country-Region-Name
X-Elasticpress-Query
X-Td-Header-From-No-Data
X-Web-Server
Thinkindot-Cache-Type
Timeexpire
X-Dw-Trace-Id
X-VTEX-Cache-Backend-Connect-Time
X-VTEX-Cache-Backend-Header-Time
X-Orig-Cache-Control
X-Mg-Cache
X-Lsadc-Cache
X-Tncms-Bot-Tier
X-Cdn-Request-ID