Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
X-Xss-Protection
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
P3p
X-FRAME-OPTIONS
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-Drupal-Dynamic-Cache
X-Request-ID
X-Ua-Compatible
Feature-Policy
Accept-CH-Lifetime
X-Content-Security-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-AspNetMvc-Version
Request-Context
X-Robots-Tag
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Age
X-Cache-Group
X-Vhost
X-Proxy-Cache
X-Turbo-Charged-By
EagleId
Keep-Alive
X-Rq
X-Via
X-Dispatcher
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
Xkey
X-Varnish-Cache
X-Litespeed-Cache
X-WebKit-CSP
Grace
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Check
X-Dns-Prefetch-Control
X-Device
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-HW
X-Node
X-Ruxit-JS-Agent
Request-Id
X-Server-Id
X-Country
X-Country-Code
Content-Location
X-Nginx-Cache-Status
X-Url
Cache-Tag
X-Content-Type
X-LiteSpeed-Cache
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
Fastly-Restarts
X-Clacks-Overhead
X-Trace
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Application-Context
X-Amz-Server-Side-Encryption
X-Times
X-NWS-LOG-UUID
Surrogate-Key
X-Vname
X-PC
X-TtlSet
Rating
X-Mcache
X-Edge
X-Midtier
X-Server-Name
X-Cache-TTL
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Powered-By-Plesk
X-Cnection
X-Element-Page-Cache
X-Abt-Application-Version
X-Browser-Type
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-GitHub-Request-Id
X-ESI
Nginx-Cache
X-Vcap-Request-Id
Edge-Control
X-D2id
X-Ac
X-ORACLE-DMS-RID
Verso
X-MS-InvokeApp
X-Ser
X-Server-ID
X-ECACHE
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-Client-IP
X-Amz-Rid
Response
X-Middleton-Response
X-Wormhole-Sdk
X-FTR-Request-ID
X-Ratelimit-Remaining
X-Goog-Hash
X-ARC
X-CST
X-Powered-CMS
X-B3-TraceId
X-Navigation-Version
X-Ruxit-Js-Agent
X-Dw-Request-Base-Id
X-Edge-Location-Klb
X-Kinsta-Cache
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Upstream
X-ASPNET-VERSION
X-Forwarded-For
Origin-Trial
X-Amzn-Trace-Id
SPIisLatency
SPRequestDuration
X-FastCGI-Cache
X-Mod-Pagespeed
X-Cache-Key
X-Content-Digest
RTSS
Cache-Status
Public-Key-Pins
Edge-Cache-Tag
AR-Request-ID
AR-ATIME
AR-PoweredBy
AR-SID
X-Ezoic-Cdn
X-Aspnetmvc-Version
X-Ttl
X-SharePointHealthScore
SPRequestGuid
X-Version
X-Daa-Tunnel
X-ORACLE-DMS-ECID
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-NF-Request-ID
X-Mg-S
X-MSEdge-Ref
Realpath
X-T
Front-End-Https
X-Recruiting
S
X-Shield-Request-Id
X-Fastly-Request-ID
Fastcgi-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-Distributor
Cross-Origin-Resource-Policy
X-Cached
X-Xrds-Location
AR-CACHE
X-Nf-Request-Id
Arr-Disable-Session-Affinity
X-TTL
X-Azure-Ref
Access-Control-Request-Method
X-Varnish-TTL
X-Request-Received
X-Request-Processing-Time
X-Id
Cache-Tags
X-Correlation-Id
TP-Cache
Count-Hit
X-Ua-Browser
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Debug
X-Cluster-Name
X-Ismobilevalue
X-TraceId
X-LLID
X-Newrelic-App-Data
X-NGENIX-Cache
Server-Node
X-PressLabs-Stats
Akamai-GRN
X-GUploader-UploadID
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
X-Frontend
X-Protected-By
X-Varnish-Backend
X-Hits
Accept-Ch
X-VARITI-CCR
X-HS-Combine-CSS
X-Amz-Replication-Status
X-Goog-Metageneration
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Unique-Id
X-Page-Id
X-Ratelimit-Reset
X-DIS-Request-ID
Payment
X-Git-Hash
Cleartype
X-FB-Debug
X-Hostname
X-AppVersion
X-Activity-Id
X-Az
X-Cambria-Cache-Control
X-HP-Trace-Id
X-Varnish-Server
X-HP-Webp
X-Logged-In
X-Jurisdiction
X-Www-Served-By
X-Tt-Trace-Host
Content-Disposition
X-Tt-Trace-Tag
X-Template
Host
X-Amzn-RequestId
X-Amz-Apigw-Id
Filterid
X-Forwarded-Proto
X-App-Server
X-Fastcgi-Cache
Amp-Access-Control-Allow-Source-Origin
X-Geo-Country
Version
X-Varnish-Ttl
X-Aspnet-Version
Accept-Charset
X-Load-Cache
X-Envoy-Decorator-Operation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
Frame-Options
Trailer
X-Cache-Age
X-Source
X-Type
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Ah-Environment
Fastly-SIE
Fastly-SWR
Viewport
X-Content-Options
Section-Io-Cache
X-Upgrade-Enabled
Access-Control-Allow-Method
X-TT
X-Fb-Rlafr
X-HS-Prerendered
Server-Name
X-B3-Sampled
X-Grace
X-Origin-Server
X-B
X-Language
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-Cache-Control
X-Device-Type
X-Buckets
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Rid
Retry-After
X-Px
X-TEC-API-ORIGIN
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Cdn
MS-Author-Via
Content-MD5
X-Mobile
X-Magnolia-Registration
X-Request-Guid
TCN
X-Vcl-Version
X-Revision
X-Trace-Id
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Akamai-Edgescape
Protected
Healthy
X-WP-CF-Super-Cache-Active
X-Backend-Name
Upgrade-Insecure-Requests
Charset
Cross-Origin-Embedder-Policy-Report-Only
SD-X-WS
X-App-Environment
X-Response-Served-From
X-Instance
X-Original-Request-Id
X-Debug-Info
X-Proxy
X-RM-Cache-TTL
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-ProcessESI
X-Is-Bot
X-Status
X-RemovedCookies
X-Rendered-As
X-Tumblr-Pixel-0
X-ServerID
X-Storage
X-Framework
X-NYM-Debug-Backend
X-Mg-Request-UUID
X-Node-Name
X-Cacheable-TTL
Access-Control-Request-Headers
X-Adobe-Loc
X-Cache-Time
X-Adobe-Content
X-UUID
X-Region
X-Rule
X-CSRF-Token
Cross-Origin-Window-Policy
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-Datadog-Sampling-Priority
X-Edge-Location
X-Debug-IsConnected
X-Datadog-Sampled
X-Debug-IsPreview
Refresh
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-FW-Static
X-FW-Version
X-Yottaa-Metrics
X-Proxy-Cache-Info
X-Yottaa-Optimizations
X-FW-Type
X-FW-Server
X-Whom
X-ECache
X-G
OT-Force-Account-Verify
MS-CV
NGB
X-RTag
Ms-Operation-Id
GEO-INFO
X-Content-Powered-By
X-Lambda-Id
X-Environment-Context
X-L-Path
Section-Io-Id
X-Resp-Is-Stale
X-Contextid
Webserver
X-B3-Traceid
X-Amzn-Remapped-Content-Length
X-Reqid
X-CCDN-CacheTTL
X-TT-LOGID
X-CCDN-Origin-Time
DC
Countrycode
X-Hcs-Proxy-Type
X-Server-W
X-User-Agent
X-Origin-Cache
Paypal-Debug-Id
X-VC
X-HTML-Minification-Powered-By
X-Amz-Meta-S3cmd-Attrs
X-Real-IP
Alternate-Protocol
X-WebKit-CSP-Report-Only
Front
X-Time
Cross-Origin-Opener-Policy-Report-Only
X-DataDome
X-HS-CF-Cache-Status
Priority
X-Seen-By
WPO-Cache-Status
WPO-Cache-Message
Ohc-File-Size
SRV
X-B3-SpanId
Accept-Ch-Lifetime
X-WP-CF-Super-Cache-Cookies-Bypass
X-Hl-Ver
X-Rocket-Nginx-Serving-Static
Liferay-Portal
X-Origin-CC
X-Origin-TTL
Backend
Xet-Cookie
X-Mode
X-IPS-LoggedIn
X-Akamai-Request-ID2
Onion-Location
Filters
Fastcgi-Useragent
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-RateLimit-Remaining
X-JoinUs
X-Origin-Hint
Meta-Geo
X-UPSTREAM-Address
X-Format
X-FB-TRIP-ID
X-Cache-Action
TWC-Privacy
Webcakes-Region
TWC-Locale-Group
X-SaId
X-Say-Cacheable
Webcakes-App-Version
X-Rn-Rsrv
X-Redis-Cache
Webcakes-App-Name
Web-Mar-Node
X-Rewrite-Enabled
X-Cache-Host
X-Say-TTL
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Device-Class
X-SayCDN-TTL
ServerID
Property-Id
TWC-GeoIP-Country
X-AB
X-DynaTrace
X-Cache-Expired-At
X-Varnish-Age
X-Accel-Version
X-Vcache
X-Labrador-Cache-Channel
X-Loop
X-Hosted-By
X-Detected-As
Country
DB-Nickname
From-Origin
X-Director
X-Fetched-On
X-VC-Cache
X-Ms-Request-Id
X-Handled-By
Uber-Trace-Id
X-Ms-Version
X-R9-Blue-Green-Version
Environment
X-Cache-Status-Check
X-Tncms
X-Nginx-Cache
X-N
X-Scope-Id
X-Origin-Date
X-PHP-Host
X-Soup
X-Tb
X-Skip-Cache
X-IPLB-Instance
X-Forwarded-Host
X-Varnish-Cache-Hits
X-Frame-Option
X-Httpd
X-Servername
X-Cluster-Node
Mn-Server-Ip
Expiry
Url
X-Varnish-Beresp-Grace
X-Cms-Context
X-Connection-Hash
X-Web-Node
X-Logging-Id
X-Adobe-Source
Atl-Traceid
X-Restarts
X-Webstats-RespID
X-IPLB-Request-ID
X-Served-From
X-ProxyCache-Status
X-BYPASS-REASON
X-Auth-Group-Type
ServedBy
Selected-Fe
X-Timing-Wait
Apigw-Requestid
X-Proxy-Build
X-ProxyCache-Key
X-Fastly-Request-Id
X-S
X-Routing-Service
X-Origin
X-Zipkin-Id
X-Proxied
X-Cluster
X-Cloudmap
X-Extlb
X-Hit
Surrogated-Key
X-Azure-Ref-OriginShield
X-RateLimit-Limit-Second
X-Worker
X-RateLimit-Remaining-Second
Cross-Origin-Embedder-Policy
X-LSADC-Cache
LB
X-SRV
Accept-Language
X-Cache-Hit
X-Request-URI
X-Sucuri-Cache
X-Lagoon
Referer-Policy
X-Generation-Time
X-CDN-Forward
X-Drupal-Cache-Tags
N-Cache
X-Drupal-Cache-Contexts
X-Generated-By
X-Cdn-Origin
X-App-Version
X-Sucuri-ID
X-MP-GENERATED-AT
Xserver
CDN-RequestId
CF-IPCountry
X-Xfnlog-Site
Ohc-Cache-HIT
X-Tx-Id
Source
X-TA-CDN-Provider
X-F-Cache
Node
Cache
X-AIR-PT
VIX-Pulpo-Node
X-Mly-Id
X-VC-TTL
VIX-Pulpo-Upstream-Status
X-Wix-Request-Id
X-Via-CDN
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-Cache-Rule
X-Cache-Debug
X-NODE
X-RCS-CacheZone
X-INCAP-ABP
X-UA
Cache-Provider
X-Pad
X-Site-Version
X-VCT
X-XRDS-Location
X-Varnish-Beresp-Ttl
X-Locale
X-Oracle-Dms-Ecid
X-ElasticPress-Query
X-GEO
Wxu-Next-Commit
Web-Mar-Region
We-Hiring
Sslversion
X-A-Wwc
X-A-Dgt
X-AB-Test
X-Access
X-Aed
X-A-Dcw
X-A-Dam
Wxu-Next-Region
X-A
X-A-Ccd
Wxu-Next-Hostname
Ngx.Var.Host
Expect-Staple
DCR-Processing-Time-Ms
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Fastly-SSL
DCR-Decision-By
Cluster
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Request-Url
BehaviorPad-Version
Candidate-Md5Url
Fl-Custom-Application
Ha-Gx-Prefs
Origin
Odigeo-Trace-Id
PFcat
Producers
Redirect-Candidate
Meta-Geo-Continent
MD5-Digest
Host-ID
HA-Ipaddr
L5d-Success-Class
Lang
Mail-Subject
Rendered-Blocks
X-BCube-Filmed-By
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-Jobs
X-Op-Id-All
X-Org
X-Path
X-Origin-Time
X-Is-Tablet
X-Is-Supported-Browser
X-HS-Content-Campaign-Id
X-HN
X-Ig-Origin-Region
X-Ig-Push-State
X-Is-Mobile
X-Is-Desktop
X-PAYTM-SRV-ID
X-Platform-Server
X-Tcp-Rtt
X-Slack-Shared-Secret-Outcome
X-VarnishDD-TTL
X-Vdms-Version
Xc-Version
X-Vtex-Remote-Cache
X-Slack-Backend
X-Section
X-Proxied-Request
X-Proto
X-Rojux
X-S-Cookie
X-SD-PageType
X-ScT
X-Geolocation
X-GeoIP-Region-Code
X-Cache-Operation
X-Cache-NE
X-Cached-By
X-CGP
X-Csrf-Jwt
X-Conf
X-Bug-Bounty
X-Browser-Name
X-B-Cookie
X-Application
X-Backend-Instance
X-Bc-Bl
X-Bl-Debug
Apple-News-Services-Handled
X-D
X-Debug-Cache-Fetch
X-Gdpr
X-FC-Vary-Parameters
X-Geo-Region
X-GeoCode
X-GeoIP-Country-Code
X-GeoCountry
X-External-Request-Id
X-Eu-Site
X-Destination
X-Debug-Cache-Store
X-Developer
X-DPWN-IS-SECURE
X-Ec-GeoHdr
X-Ec-Fail
X-Aicache-OS
X-Cache-Grace
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-NWS-UUID-VERIFY
X-NGINX-Cache
X-GoCache-CacheStatus
X-Hash
X-Human
X-GeoIP-City
X-Gzip
X-GeoIP
X-Generated-On
X-Gamma-Serve
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
Server-Host
Req-Svc-Chain
X-Origin-Expires
X-NodeID
X-Platform
X-Policy
X-Powered-By-VTEX-Cache
Origin-Agent-Cluster
X-Node-Id
Product
X-Location
X-Loc
X-Micro-Cache
X-Mvc-Supplant-OutputCached
X-NMSegId
X-Level-Front-Cache
X-Esi-Check
X-Cache-Id
X-Cache-Date
X-Accel-Expires-Debug
X-Cache-Info
X-CacheTTL
X-AK-Request-ID
X-Akamai-Device-Characteristics
X-Auto-Login
X-B-Cache
X-BBC-Edge-Cache-Status
X-App-Name
X-Amz-Storage-Class
X-Litespeed-Tag
X-Clientip
X-Ec-Custom-Error
V-Age
X-Epic-Correlation-Id
NM-Fastcgi-Cache
X-Fastly-Backend
X-Dispatcher-Server
X-DefHash
X-Core-Value
X-Content-Age
X-CUA
X-Date
X-DefElseHash
X-Fmm-Version
Platform
Content-Script-Type
X-VG-WebCache
X-Viewer-Country
X-Vmg-Version
X-VServer
Content-Style-Type
Debug
X-V-Cache
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Director
Cdnsip
Cdncip
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Zen-Fury
X-Wikidot-Static-Cache
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Wikidot-Backend
Canary
Gannett-Cam-Experience-Id
X-Varnish-Remaining-TTL
X-Signature
X-Thinkindot-L3
L
X-Scheme
X-Request-Host
X-Request-Time
Gh-Request-Id
X-Shield-Cache-Expires
X-User
Akamai-Mon-Iucid-Del
X-ShardId
X-Alternate-Cache-Key
X-Shopify-Stage
X-No-Session
X-ShopId
X-Ua-Device
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-SB
X-Pool
X-Cdn-Srv
XM
X-Pubstack
Yak-Timeinfo
X-TH-Server
X-Bip
X-Origin-Response-Time
X-Cache-Aspx
X-Block-Status
X-Request-Start
X-Content-Length
X-Thanos
X-SVT-ORM-VERSION
X-Edge-Server
X-Via-Fastly
X-TIM-N
X-VG-TLSProxy
X-IsAdmin
X-Gen-Mode
X-Req
X-Men
X-SVT-ORM-RULES
X-We-Are-Hiring
X-Varnish-Authentication
X-B3-Trace-ID
X-Server-IP
X-Hnp-Log
X-Sn-Servicetimems
X-Varnish-Beresp-Status
X-Depends
X-Contensis-Viewer-Groups
X-Internal-TTL
DSUID
NGX
Country-Code
W
Content-Secure-Policy
User-Cache-Control
Cdn-Request-Time
Cdn-Host
CDCHOST
Origin-EX
Origin-CC
RNT-Time
ServerName
RNT-Machine
X-Amz-Meta-Cb-Modifiedtime
Release
Req-ID
Mime-Version
X-URL
X-Service
X-Via-JSL
IsBot
X-SIPLIST1
X-Irp-Debug
X-Tb-Optimization-Total-Bytes-Saved
Tube-Got-Eval
X-HOST
Ssr
Tube-Get-Contents
Sid
Tube-Return
Tube-Got-Results
User-Agent
X-UA-Device-Type
X-RID
CDN-EdgeStorageId
CDN-CachedAt
Click-Count-Error
CDN-RequestPullCode
Click-Count-Action-Start
CDN-Cache
X-Vgn-Hpd-Reason
CDN-RequestPullSuccess
X-Cache-FS-Status
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
X-Acquia-Purge-Cdn-Unconfigured
X-Moov-T
X-CACHE-GROUP
X-Moov-Xdn-Caching-Status
X-LB-NoCache
X-Var-Ttl
X-Moov-Xdn-Version
X-Varnishpool
X-Varnish-Hits
X-Old-Content-Length
Pramga
GeoIP-Latitude
N1-Cache
Fastly-Drupal-HTML
X-DC
X-Api-Version
X-ORCA-Accelerator
X-RequestId
X-Cs
X-ZONE
X-HITS
X-Proxy-Cache-Status
X-Refresh
X-HubSpot-Correlation-Id
X-Action
X-Servedbyhost
CloudFront-Viewer-Country
Esi-Enabled
X-APP
TWC-GeoIP-DMA
Cache-Hits
TWC-GeoIP-Region
TWC-GeoIP-City
AMP-Access-Control-Allow-Source-Origin
X-Vercel-Id
Location
C-Via
X-Wa
X-Upstream-Ct
X-Nc
X-Upstream-Ht
X-Cache-VC
X-Thinkindot-L1
X-Vercel-Cache
X-Newrelic-Synthetics
X-Dc
Cdn-Requestid
X-B3-Spanid
X-Via-Popv
X-Cache-Bucket
X-Via-Popn
X-Via-Poph
X-LiteSpeed-Tag
X-HA-Backend
Server-ID
X-DynaTrace-JS-Agent
X-Webkit-CSP
X-Parent-Response-Time
Cache-Key
X-Proxy-CacheRZ
X-B3-Parentspanid
X-LB-ID
XkeyRZ
X-LiteSpeed-Cache-Control
X-NewRelic-App-Data
A
X-Tt-Logid
Fastly-Drupal-Html
X-Presslabs-Stats
X-CS
X-PERF
HostName
X-ApacheServer
X-COUNTRY
X-Nananana
X-Zone
X-Webkit-Csp
WP-Super-Cache
X-WA-Info
X-DataCenter
X-Ua
X-Endurance-Cache-Level
X-Srv
X-Cdn-Forward
X-Litespeed-Cache-Control
X-CACHE-AGE
X-Webkit-Csp-Report-Only
X-Nitro-Cache
Proxy-Firewall
X-Render-Time
GeoIp-Country-Code
SID
RewriteTestHook
Cache-Contol
RewriteTeamHook
X-Ion-Healthy
X-Fpc
X-Uri
Uri
TP-L2-Cache
X-Jungle-Id
X-API-Version
X-Ion-Hop
True-Client-IP
Log-Origin
My-App
Server-Hostname
AKAMAI-GRN
True-Client-Country-4JS
Cmsid
X-Datadome
X-From
Server-Ext
X-Up
Resin-Trace
Cmstype
Sever-Int
True-Client-Ip
X-Optimistic-Header
X-Service-Response-Time
Sm-Log-Id
X-CLOUD-TRACE-CONTEXT
X-Test
GeoIP-Country-Code
X-Ssense-Gql
X-Varnish-Beresp-TTL
X-Ssense-Shipping-Surcharge-Enabled
CacheControlHeader
X-SERVER-NAME
X-FPC
X-Udemy-Cache-App-Namespace
X-Stale
Is-Eu
Adler-Geo
Tcn
SEZNAM-JOBS-OFFER
X-Datacenter
Cdn
X-Dispatcher-Number
Srv
X-Pass-Why
X-Client-Ip
WZWS-RAY
X-RateLimit-Limit
X-Nginx-Cache-Key
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Dynatrace-Js-Agent
Lb
X-Oracle-Dms-Rid
X-APP-VERSION
X-Air-Pt
Hostname
X-Debug-Service
Server-Id
X-Fastly-Cache-Status
T-Server
X-Geo-Header
X-Air-Hostname
Origin-Site
X-Air-Source
X-Custom-Header
X-Air-Trace-Id
X-AWS-Id
X-TX-ID
X-LJ-Flow-ID
X-VWS-Id
X-ND-Cache
NtCoent-Length
X-Varnish-Hostname
X-SRCache-Key
X-Vc
X-Provided-By
X-WA
X-Lb-Id
Edge-Cache
X-Akamai-Pragma-Client-IP
X-Correlation-ID
Serverhost
X-CMSURLCustom
X-Cache-Server
Cf-Ipcountry
X-Fastly-Backend-Reqs
X-VCL-Version
Vc-Max-Age
X-App
X-Cache-Ttl
X-NC
X-Ha-Backend
X-Via-PopN
X-Via-PopV
X-Html-Minification-Powered-By
Pics-Label
X-Oracle-DMS-ECID
X-Via-PopH
Pragrma
ServerHost
X-XRDS-LOCATION
X-Esi
Geoip-Latitude
X-Rocket-Build-Number
X-Sigma
X-Cdn-Cache-Status
X-Sigma-Backend
X-Region-Sid
YJS-ID
Epwk-X-Cache
S-Rt
Machine
Powered-By
X-Forwarded-Site
X-LAGOON
Av-Poweredby
Nord-Request-ID
Ms-Author-Via
X-Requestid
X-ServedByHost
WebServer
Cloudfront-Viewer-Country
Vix-Hermes-Req-Id
X-Traceid
X-Cache-TTL-Remaining
Cache-Tv-Group
WWW-Authenticate
CountryCode
Xkey-La3
X-Ckpd-Fst-Backend
X-HS-Status
Xkeylog
X-Lb-Nocache
Warning
X-MSEdge-Flight
X-Sucuri-Id
X-MSEdge-Features
X-Fastly-Cache
X-Proxy-Cache-La3
MIME-Version
X-IAuth-Set-Uid
Thinkindot-Control
X-Wp-Cf-Super-Cache
FSS-Cache
DataCenter
X-Serial
X-Check-Cacheable
X-Akamai-ERPolicy
On-Server
Reporter
X-Wp-Cf-Super-Cache-Cache-Control
X-Akamai-ERRuleID
X-Cdn-Request-ID
Yjs-Id
Cneonction
Timeexpire
X-VTEX-Cache-Backend-Header-Time
X-Orig-Cache-Control
X-Dw-Trace-Id
X-Tncms-Bot-Tier
X-BBC-Origin-Response-Status
Thinkindot-Cache-Type
X-Td-Header-From-No-Data
X-Lsadc-Cache
X-Elasticpress-Query
X-VTEX-Cache-Backend-Connect-Time
X-Web-Server
X-Mg-Cache