Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
Accept-CH
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
P3p
Server-Timing
X-Generator
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
Permissions-Policy
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
X-Ua-Compatible
Feature-Policy
Access-Control-Expose-Headers
Upgrade
Content-Encoding
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
X-Check
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Turbo-Charged-By
X-Cache-Group
X-Proxy-Cache
Keep-Alive
X-Age
X-Rq
X-Via
X-UA-Device
EagleId
X-Server
X-Dispatcher
Accept-CH-Lifetime
X-Vhost
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Varnish-Cache
X-Litespeed-Cache
Grace
X-Server-Powered-By
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Allow
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-Cache-Lookup
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Page-Speed
Xkey
X-Cloud-Trace-Context
X-Device
X-Backend-Server
X-Akam-SW-Version
X-Host
EagleEye-TraceId
Surrogate-Control
X-Response-Time
X-Readtime
Cf-Railgun
X-Server-Id
X-Node
X-HW
Request-Id
X-Ruxit-JS-Agent
X-Country
X-LiteSpeed-Cache
X-Url
X-Nginx-Cache-Status
Content-Location
X-Content-Type
Cache-Tag
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
Service-Worker-Allowed
X-Application-Context
X-Country-Code
X-Trace
Fastly-Restarts
X-NWS-LOG-UUID
Cross-Origin-Opener-Policy
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Times
X-Vname
X-TtlSet
X-PC
X-Midtier
X-Mcache
X-Edge
Surrogate-Key
Rating
X-Server-Name
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Browser-Type
X-Cache-TTL
X-Element-Page-Cache
X-Cnection
X-Abt-Application-Version
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Kinja-Server
Nginx-Cache
X-Powered-By-Plesk
X-ESI
X-GitHub-Request-Id
X-Oneagent-Js-Injection
Edge-Control
X-Vcap-Request-Id
X-D2id
Verso
X-Ser
X-Ac
X-ECACHE
X-MS-InvokeApp
X-Client-IP
X-ORACLE-DMS-RID
X-ARC
X-Dw-Request-Base-Id
X-Amz-Rid
X-Middleton-Response
Response
X-CST
X-Ruxit-Js-Agent
X-Wormhole-Sdk
X-Goog-Hash
X-Powered-CMS
X-Navigation-Version
X-Ratelimit-Limit
X-Kinsta-Cache
X-Edge-Location-Klb
X-Upstream
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-B3-TraceId
X-Forwarded-For
X-Ratelimit-Remaining
X-Amzn-Trace-Id
X-FastCGI-Cache
Accept-Ch-Lifetime
X-Daa-Tunnel
X-Cache-Key
RTSS
SPRequestDuration
SPIisLatency
X-Mod-Pagespeed
AR-PoweredBy
Edge-Cache-Tag
AR-ATIME
AR-Request-ID
AR-SID
Cache-Status
Public-Key-Pins
X-Server-ID
X-Content-Digest
X-Ttl
X-Version
X-Ezoic-Cdn
X-ORACLE-DMS-ECID
X-Mg-S
X-NF-Request-ID
X-SharePointHealthScore
SPRequestGuid
Realpath
S
X-MSEdge-Ref
X-T
X-Shield-Request-Id
Cross-Origin-Resource-Policy
AR-CACHE
Fastcgi-Cache
X-Recruiting
X-Fastly-Request-ID
X-Cached
Front-End-Https
X-Accel-Expires
X-Distributor
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ua-Device
Origin-Trial
Access-Control-Request-Method
X-Azure-Ref
TP-Cache
X-Newrelic-App-Data
Arr-Disable-Session-Affinity
X-Request-Received
X-Request-Processing-Time
Pinterest-Generated-By
Pinterest-Version
X-Ua-Browser
Count-Hit
X-Pinterest-Rid
X-Id
X-HS-Content-Id
X-Debug
X-TTL
X-HS-Cache-Config
X-HS-Hub-Id
X-Varnish-TTL
X-LLID
X-Nf-Request-Id
Server-Node
Cache-Tags
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
X-Ismobilevalue
X-PressLabs-Stats
X-Cluster-Name
X-Correlation-Id
X-VARITI-CCR
X-Frontend
X-FTR-Request-ID
X-Hits
X-HS-Combine-CSS
X-GUploader-UploadID
X-Aspnetmvc-Version
X-Varnish-Backend
X-NGENIX-Cache
X-Amz-Replication-Status
X-Xrds-Location
Payment
X-Protected-By
Accept-Ch
X-Goog-Metageneration
X-Microsite
X-Request-Handler-Origin-Region
X-LB-Cache
X-Unique-Id
Akamai-GRN
Cleartype
X-Varnish-Server
X-FB-Debug
X-Logged-In
X-Activity-Id
X-Az
X-Git-Hash
X-AppVersion
X-Tt-Trace-Host
X-Forwarded-Proto
Content-Disposition
X-Ratelimit-Reset
X-Tt-Trace-Tag
X-Www-Served-By
Host
X-Page-Id
X-Hostname
Filterid
X-DIS-Request-ID
X-Jurisdiction
X-Varnish-Ttl
X-HP-Trace-Id
X-Cambria-Cache-Control
X-HP-Webp
X-Amz-Apigw-Id
X-Amzn-RequestId
X-App-Server
X-Template
X-Geo-Country
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
Frame-Options
Access-Control-Allow-Method
Amp-Access-Control-Allow-Source-Origin
X-Origin-Server
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Aspnet-Version
X-Upgrade-Enabled
Version
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Load-Cache
MS-Author-Via
X-Type
X-Fastcgi-Cache
Viewport
X-ASPNET-VERSION
Section-Io-Cache
Fastly-SIE
Fastly-SWR
X-Content-Options
Accept-Charset
X-Fb-Rlafr
Retry-After
X-Cache-Control
X-TT
X-B3-Sampled
X-Rid
X-B
X-Ah-Environment
Trailer
X-Grace
Content-MD5
X-Envoy-Decorator-Operation
X-TraceId
X-Source
X-SRCache-Store-Status
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-SRCache-Fetch-Status
X-Cache-Age
X-Vcl-Version
X-Device-Type
Server-Name
X-Request-Guid
X-Trace-Id
X-Revision
X-Language
X-TEC-API-VERSION
X-Cdn
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Buckets
Healthy
X-Magnolia-Registration
X-Mobile
X-Px
TCN
X-WP-CF-Super-Cache-Active
X-Webkit-CSP
X-EdgeConnect-Cache-Status
X-Backend-Name
X-CSRF-Token
X-Akamai-Edgescape
X-HS-Prerendered
X-Origin-Cache
X-B3-Traceid
X-Varnish-Grace
X-Contextid
X-Amz-Meta-S3cmd-Attrs
X-App-Environment
X-Status
X-Tumblr-Pixel-1
X-NYM-Debug-Backend
X-L-Path
X-ProcessESI
X-Instance
X-RemovedCookies
X-Tumblr-Pixel-0
X-Environment-Context
X-Tumblr-User
X-Debug-Info
X-RM-Cache-TTL
X-Tumblr-Pixel
X-Rule
X-FW-Dynamic
X-FW-Server
Access-Control-Request-Headers
X-Proxy
X-Storage
X-FW-Serve
X-ServerID
X-Framework
X-FW-Static
X-Mg-Request-UUID
X-Region
X-FW-Type
X-FW-Version
NGB
SD-X-WS
GEO-INFO
X-Proxy-Cache-Info
X-UUID
X-Node-Name
X-Cache-Time
Cross-Origin-Window-Policy
X-FW-Hash
X-Content-Powered-By
MS-CV
Ms-Operation-Id
X-Cacheable-TTL
X-Datadog-Sampling-Priority
X-Edge-Location
X-Datadog-Parent-Id
X-Datadog-Sampled
X-Debug-IsConnected
X-RTag
X-Debug-IsPreview
X-Rendered-As
X-Is-Bot
X-Datadog-Trace-Id
X-G
X-Adobe-Loc
X-Yottaa-Optimizations
Protected
X-Adobe-Content
X-Yottaa-Metrics
Upgrade-Insecure-Requests
Charset
X-Whom
Cross-Origin-Embedder-Policy-Report-Only
DC
Countrycode
X-ECache
X-Original-Request-Id
Refresh
X-Response-Served-From
Webserver
X-RateLimit-Remaining
Paypal-Debug-Id
X-HTML-Minification-Powered-By
OT-Force-Account-Verify
X-Lambda-Id
X-User-Agent
X-Seen-By
Section-Io-Id
Front
X-VC
X-Reqid
X-Amzn-Remapped-Content-Length
X-WebKit-CSP-Report-Only
Alternate-Protocol
SRV
X-VHOST
X-Server-W
X-TT-LOGID
X-IPS-LoggedIn
Priority
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Akamai-Request-ID2
X-Cache-Status-Check
X-Real-IP
X-WP-CF-Super-Cache-Cookies-Bypass
X-Fastly-Request-Id
X-AB
X-Nginx-Cache
Country
X-Time
X-N
Backend
Liferay-Portal
X-Mode
Xet-Cookie
Onion-Location
X-Format
X-FB-TRIP-ID
X-Cache-Host
X-Rewrite-Enabled
X-Tumblr-Pixel-2
X-UPSTREAM-Address
X-SaId
X-Rn-Rsrv
X-Origin-Hint
Webcakes-Region
X-JoinUs
TWC-Privacy
Property-Id
TWC-Connection-Speed
Meta-Geo
Filters
Fastcgi-Useragent
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-App-Name
Environment
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Version
ServerID
X-Cache-Expired-At
X-Origin-Date
X-Cache-Action
X-R9-Blue-Green-Version
X-Restarts
X-Redis-Cache
X-Cluster-Node
X-Connection-Hash
X-Fetched-On
X-Frame-Option
X-Hl-Ver
X-Hosted-By
X-IPLB-Request-ID
X-IPLB-Instance
X-Say-Cacheable
X-Say-TTL
Uber-Trace-Id
Web-Mar-Node
Mn-Server-Ip
From-Origin
DB-Nickname
Expiry
X-Rocket-Nginx-Serving-Static
X-Accel-Version
X-Skip-Cache
X-Scope-Id
X-Varnish-Age
X-Tb
X-SayCDN-TTL
Atl-Traceid
X-Director
X-BYPASS-REASON
X-Logging-Id
X-Vcache
X-VC-Cache
X-Varnish-Cache-Hits
X-Web-Node
X-Webstats-RespID
X-PHP-Host
X-Labrador-Cache-Channel
X-Varnish-Beresp-Grace
X-Tncms
Apigw-Requestid
X-Httpd
X-Handled-By
X-Loop
X-ProxyCache-Key
X-Soup
X-ProxyCache-Status
X-Forwarded-Host
X-Cms-Context
X-Proxy-Build
X-Servername
X-Timing-Wait
X-Cluster
X-B3-SpanId
Url
X-Request-URI
X-Served-From
ServedBy
X-Origin-TTL
X-Origin-CC
Selected-Fe
X-DataDome
X-Adobe-Source
X-Auth-Group-Type
X-S
X-Routing-Service
X-Detected-As
WPO-Cache-Status
WPO-Cache-Message
Accept-Language
X-Origin
X-Extlb
X-Cloudmap
X-Zipkin-Id
X-Proxied
X-DynaTrace
X-Ms-Request-Id
X-Ms-Version
Cross-Origin-Embedder-Policy
X-Hit
Referer-Policy
X-Tumblr-Pixel-3
N-Cache
Cross-Origin-Opener-Policy-Report-Only
X-Generated-By
X-LSADC-Cache
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Expires
X-Azure-Ref-OriginShield
X-XRDS-Location
VIX-Pulpo-Node
Surrogated-Key
Xserver
VIX-Pulpo-Upstream-Status
X-Worker
X-Wix-Request-Id
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Lagoon
X-Xfnlog-Site
Ohc-File-Size
X-SRV
LB
X-Sucuri-Cache
X-Generation-Time
X-Webkit-Csp
X-NWS-UUID-VERIFY
CF-IPCountry
X-App-Version
X-HS-CF-Cache-Status
Source
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Cdn-Origin
X-RCS-CacheZone
X-Cache-Debug
X-F-Cache
X-Cache-Hit
X-VCT
X-MP-GENERATED-AT
X-Sucuri-ID
Node
CDN-RequestId
X-Resp-Is-Stale
X-Via-JSL
X-Tx-Id
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-No-Session
X-Tcp-Rtt
X-Proxy-Cache-Status
X-Is-Mobile
X-Is-Desktop
X-Is-Supported-Browser
X-Signature
X-NODE
X-Is-Tablet
X-Browser-Name
X-B-Cache
X-Geo-Region
X-Cache-Rule
Cache
X-TA-CDN-Provider
X-Varnish-Beresp-Ttl
X-Mly-Id
X-ElasticPress-Query
X-INCAP-ABP
X-CDN-Forward
X-Cache-Operation
X-FC-Vary-Parameters
X-Access
X-AB-Test
X-A-Wwc
Cache-Provider
X-Eu-Site
Apple-News-Services-Request-Url
X-Aed
BehaviorPad-Version
Candidate-Md5Url
X-Gdpr
X-VarnishDD-TTL
X-A-Dam
X-A-Ccd
X-A-Dcw
X-Ec-Fail
X-Vdms-Version
X-A-Dgt
X-GeoCode
X-Vtex-Remote-Cache
X-Aicache-OS
X-Backend-Instance
X-Conf
X-App-Name
X-Bc-Bl
X-CGP
X-Bug-Bounty
X-BCube-Filmed-By
X-Cache-NE
Apple-News-Services-Handled
X-Csrf-Jwt
X-Developer
Xc-Version
Apple-News-Services-Parsed-Url
X-Debug-Cache-Store
Apple-News-Services-Host
X-D
X-Debug-Cache-Fetch
Cluster
X-Cache-Info
DCR-Processing-Time-Ms
Sslversion
X-Jobs
Rendered-Blocks
Mail-Subject
X-Path
X-PAYTM-SRV-ID
X-Proto
X-Ig-Push-State
User-Agent
X-Platform-Server
MD5-Digest
X-Origin-Time
Origin
Odigeo-Trace-Id
X-Ec-GeoHdr
X-Op-Id-All
Ngx.Var.Host
X-Nyt-Route
Redirect-Candidate
Meta-Geo-Continent
X-Mvc-Supplant-Cachable
PFcat
X-Ig-Origin-Region
Lang
Expect-Staple
X-Section
Fastly-Backend-Name
Fl-Custom-Application
Wxu-Next-Region
X-GeoCountry
DCR-Decision-By
X-Org
X-A
X-TIM-N
X-ScT
Wxu-Next-Hostname
We-Hiring
X-Proxied-Request
W
L5d-Success-Class
X-Rojux
X-HN
Ha-Gx-Prefs
HA-Ipaddr
Host-ID
Wxu-Next-Commit
Content-Secure-Policy
Fastly-GeoIP-CountryCode
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Upstream-Ct
X-Sorting-Hat-PodId
X-Shopify-Stage
X-UA
X-ShardId
X-ShopId
X-Upstream-Ht
X-Alternate-Cache-Key
Mime-Version
Producers
Product
Platform
X-We-Are-Hiring
Origin-Agent-Cluster
X-Wikidot-Backend
X-Core-Value
X-Contensis-Viewer-Groups
Server-Host
X-Clientip
RNT-Time
RNT-Machine
X-Wikidot-Static-Cache
Req-Svc-Chain
X-Content-Length
X-Slack-Shared-Secret-Outcome
X-Shield-Cache-Expires
X-Varnishpool
Gh-Request-Id
X-Epic-Correlation-Id
X-Esi-Check
Gannett-Cam-Experience-Id
L
X-Slack-Backend
NM-Fastcgi-Cache
X-Cdn-Srv
X-Depends
X-Powered-By-VTEX-Cache
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Date
X-Thinkindot-L3
X-B3-Trace-ID
X-Via-Fastly
X-BBC-Edge-Cache-Status
Web-Mar-Region
V-Age
X-Viewer-Country
X-Auto-Login
X-Amz-Storage-Class
X-Accel-Expires-Debug
X-Varnish-Director
X-AK-Request-ID
X-Akamai-Device-Characteristics
X-VG-WebCache
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Aspx
X-Cache-Grace
TDXMobile
Thinkindot-CacheControl
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-CacheTTL
X-Cached-By
Thinkindot-CacheControl-Type
X-V-Cache
X-Varnish-Authentication
X-Cache-Id
X-Vmg-Version
X-Var-Ttl
X-VServer
Fastly-SSL
X-Edge-Server
X-NMSegId
X-Via-SSL
X-HS-Content-Campaign-Id
CDCHOST
X-Platform
X-Irp-Debug
Cdn-Host
X-SB
X-Via-CDN
X-GoCache-CacheStatus
X-Via-Edge
X-Hash
Cdn-Request-Time
Canary
X-Level-Front-Cache
X-Pad
X-Location
X-Req
X-Micro-Cache
X-Mvc-Supplant-OutputCached
X-Request-Time
Azure-InstanceId
Azure-RegionName
X-Locale
X-Loc
Azure-Version
Azure-SlotName
Azure-SiteName
X-GeoIP-Region-Code
X-Gzip
X-Origin-Expires
X-Bl-Debug
X-Generated-On
X-ORCA-Accelerator
Edge-Copy-Time
Content-Style-Type
X-Gamma-Serve
X-Geolocation
X-Fmm-Version
X-Fastly-Backend
Esi-Enabled
X-Policy
Debug
Content-Script-Type
X-SD-PageType
X-GeoIP-Country-Code
X-NodeID
X-GeoIP-City
X-Scheme
Cdnsip
X-GeoIP
X-Node-Id
Cdncip
Akamai-Mon-Iucid-Del
X-Varnish-Remaining-TTL
X-Cache-FS-Status
X-Origin-Response-Time
X-Varnish-Beresp-Status
X-Bip
X-Request-Start
X-Varnish-CookieHashed-On
X-Block-Status
X-Request-Host
X-Varnish-CookieINHashed-On
X-Tb-Optimization-Total-Bytes-Saved
X-Litespeed-Tag
X-DefHash
X-DefElseHash
X-Sn-Servicetimems
X-Ec-Custom-Error
X-Site-Version
X-Pool
X-Server-IP
X-SIPLIST1
X-Gen-Mode
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Service
X-Thanos
X-IsAdmin
X-UA-Device-Type
X-Internal-TTL
X-Human
X-CUA
X-Content-Age
X-Hnp-Log
X-Men
X-Pubstack
IsBot
NGX
X-B-Cookie
X-Destination
X-External-Request-Id
Origin-CC
Origin-EX
Req-ID
ServerName
Release
Pramga
CDN-EdgeStorageId
X-Application
CDN-Cache
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-PullZone
XM
Click-Count-Action-Start
CDN-CachedAt
DSUID
Country-Code
X-S-Cookie
Click-Count-Error
X-Cache-Date
Yak-Timeinfo
X-VG-TLSProxy
Tube-Return
Tube-Got-Eval
User-Cache-Control
Tube-Get-Contents
Tube-Got-Results
X-Acquia-Purge-Cdn-Unconfigured
Sid
X-LB-NoCache
X-GEO
Ssr
X-Varnish-Hits
X-Api-Version
X-NGINX-Cache
X-RID
X-HOST
X-User
X-Zen-Fury
X-B3-Spanid
X-VC-TTL
Ohc-Cache-HIT
AMP-Access-Control-Allow-Source-Origin
X-Cache-Bucket
A
X-CACHE-GROUP
XkeyRZ
X-Proxy-CacheRZ
Cache-Key
X-Refresh
X-CLOUD-TRACE-CONTEXT
X-ZONE
Cdn-Requestid
X-Cs
Fastly-Drupal-HTML
X-Oracle-Dms-Ecid
X-Servedbyhost
CloudFront-Viewer-Country
X-RequestId
GeoIP-Latitude
X-Cdn-Forward
X-Dc
X-Newrelic-Synthetics
X-Tt-Logid
X-HITS
X-AIR-PT
TP-L2-Cache
X-Wa
C-Via
X-DC
X-Nananana
X-APP
X-Vgn-Hpd-Reason
X-TH-Server
X-Nc
X-Optimistic-Header
X-Via-Poph
X-B3-Parentspanid
X-HA-Backend
X-Via-Popv
X-Via-Popn
Server-ID
X-Endurance-Cache-Level
X-Srv
X-Old-Content-Length
X-LB-ID
X-LiteSpeed-Tag
X-Air-Pt
X-RateLimit-Limit
X-DynaTrace-JS-Agent
Fastly-Drupal-Html
X-Moov-Xdn-Version
Proxy-Firewall
X-HubSpot-Correlation-Id
X-Moov-T
X-Moov-Xdn-Caching-Status
X-LiteSpeed-Cache-Control
HostName
X-Webkit-Csp-Report-Only
True-Client-Country-4JS
X-CS
X-Parent-Response-Time
X-Presslabs-Stats
Cdn
Server-Ext
Server-Hostname
Sever-Int
WP-Super-Cache
X-Test
X-COUNTRY
X-URL
X-Zone
X-XRDS-LOCATION
GeoIp-Country-Code
X-Datadome
Is-Eu
Adler-Geo
X-Action
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-CACHE-AGE
Location
WZWS-RAY
X-Nginx-Cache-Key
X-DataCenter
X-Thinkindot-L1
X-Dispatcher-Number
X-Fpc
X-Cache-VC
X-API-Version
SID
X-Provided-By
X-Ua
X-Vercel-Cache
X-Vercel-Id
X-NewRelic-App-Data
N1-Cache
X-Litespeed-Cache-Control
X-Geo-Header
True-Client-Ip
Cache-Hits
True-Client-IP
T-Server
TWC-GeoIP-City
TWC-GeoIP-Region
TWC-GeoIP-DMA
Uri
X-Custom-Header
X-Pass-Why
X-Stale
X-ApacheServer
SEZNAM-JOBS-OFFER
X-PERF
X-Datacenter
S-Rt
X-ND-Cache
X-Varnish-Beresp-TTL
X-Cache-Server
GeoIP-Country-Code
Resin-Trace
Cache-Tv-Group
Vc-Max-Age
X-CMSURLCustom
X-WA-Info
X-Render-Time
X-Cache-Ttl
X-SERVER-NAME
X-Nitro-Cache
Serverhost
Pics-Label
X-APP-VERSION
X-Uri
Tcn
X-FPC
X-Client-Ip
X-TX-ID
X-Service-Response-Time
X-Ssense-Gql
X-Ssense-Shipping-Surcharge-Enabled
Sm-Log-Id
RewriteTestHook
Cache-Contol
X-Ion-Hop
X-Jungle-Id
X-Ion-Healthy
Log-Origin
RewriteTeamHook
Powered-By
X-Correlation-ID
X-Srcache-Fetch-Status
X-Dynatrace-Js-Agent
X-Srcache-Store-Status
Srv
Cmsid
My-App
Vix-Hermes-Req-Id
X-Oracle-Dms-Rid
Hostname
Lb
Cmstype
Av-Poweredby
X-Fastly-Cache-Status
X-Fastly-Cache
X-Udemy-Cache-App-Namespace
X-Cache-TTL-Remaining
X-Ckpd-Fst-Backend
Server-Id
X-From
X-Air-Trace-Id
X-Debug-Service
X-Air-Source
X-Air-Hostname
X-Cdn-Cache-Status
CacheControlHeader
Thinkindot-Control
On-Server
X-Akamai-Pragma-Client-IP
X-Up
X-Lb-Id
X-Vc
X-Via-PopN
X-Ha-Backend
X-Via-PopH
X-Via-PopV
ServerHost
X-NC
X-WA
Cf-Ipcountry
X-App
X-Proxy-Cache-La3
X-PHP-Backend
X-Github-Request-Id
X-Fastly-Backend-Reqs
X-Save-Cache
Xkey-La3
X-Oracle-DMS-ECID
X-Vary-Devices
X-Ee-Request-Id
X-Ee-Request-Date
Store-Cloud-Cache
Geoip-Latitude
AKAMAI
Time-Cloud-Cache
X-Amz-Meta-Opti
X-Ee-Origin
Xkeylog
X-Cms-Device
X-LAGOON
X-Ee-Generated-By
X-Esi
NtCoent-Length
X-VTEX-Cache-Backend-Connect-Time
X-VCL-Version
X-VTEX-Cache-Backend-Header-Time
Cl-Cache
WWW-Authenticate
X-Info
Origin-Site
X-IAuth-Set-Uid
Magicmarker
X-ServedByHost
X-Traceid
Cloudfront-Viewer-Country
X-Html-Minification-Powered-By
Warning
X-Requestid
WebServer
CountryCode
X-MSEdge-Flight
X-Serial
X-Limited
X-Sucuri-Id
X-MSEdge-Features
X-Check-Cacheable
X-HS-Status
X-SRCache-Key
X-Dw-Trace-Id
Epwk-X-Cache
X-Varnish-Hostname
X-Geo
X-Lb-Nocache
X-Acquia-Application-UUID
Edge-Cache
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Acquia-Application-Trace
FSS-Cache
Reporter
X-Akamai-Transformed
X-CDN-Cache-Status
X-Acquia-Site
X-Pod
X-Acquia-Purge-Tags
X-Td-Header-From-No-Data
Yjs-Id
X-UP
X-Mg-Cache
X-Lsadc-Cache
X-Web-Server
Thinkindot-Cache-Type
CDN
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-New
X-Rollout
X-Tncms-Bot-Tier
Cneonction
CF-Cached-On
Timeexpire
X-Eligible
X-Ms-Lease-Status
X-Platform-Processor
X-Platform-Router
X-Elasticpress-Query
X-Platform-Cluster
X-Orig-Cache-Control
X-Ms-Blob-Type
X-Ramcache
X-BBC-Origin-Response-Status