Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
CF-Cache-Status
Cf-Request-Id
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
Age
X-XSS-Protection
Content-Security-Policy
Alt-Svc
Report-To
NEL
Referrer-Policy
X-Xss-Protection
Access-Control-Allow-Origin
Accept-CH
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Runtime
X-AspNet-Version
X-Drupal-Cache
Server-Timing
X-Generator
X-Cache-Status
P3p
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
Permissions-Policy
X-Iinfo
X-FRAME-OPTIONS
X-Drupal-Dynamic-Cache
X-Request-ID
X-Ua-Compatible
Feature-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Accept-CH-Lifetime
Upgrade
Content-Encoding
Status
X-CDN
Access-Control-Max-Age
X-AspNetMvc-Version
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Backend
X-UA-Device
X-Amz-Id-2
X-Hacker
Cf-Apo-Via
X-Cache-Group
X-Age
X-Vhost
X-Proxy-Cache
X-Turbo-Charged-By
EagleId
Keep-Alive
X-Rq
X-Via
X-Dispatcher
X-Server
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
Xkey
X-Varnish-Cache
X-Litespeed-Cache
X-WebKit-CSP
Grace
X-Server-Powered-By
X-OneAgent-JS-Injection
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Check
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Page-Speed
X-Cache-Lookup
X-Cloud-Trace-Context
X-Device
X-Dns-Prefetch-Control
X-Akam-SW-Version
X-Backend-Server
X-Host
Surrogate-Control
EagleEye-TraceId
X-Response-Time
X-Readtime
Cf-Railgun
X-Node
X-HW
X-Ruxit-JS-Agent
Request-Id
X-Country
X-LiteSpeed-Cache
X-Country-Code
X-Server-Id
Content-Location
X-Nginx-Cache-Status
X-Url
Cache-Tag
X-Content-Type
X-Nginx-Upstream-Cache-Status
Service-Worker-Allowed
Fastly-Restarts
X-Trace
Cross-Origin-Opener-Policy
X-Clacks-Overhead
X-Rack-Cache
X-Application-Context
X-Amz-Server-Side-Encryption
X-Times
X-NWS-LOG-UUID
X-TtlSet
X-PC
X-Vname
Surrogate-Key
X-Edge
X-Midtier
X-Mcache
Rating
X-Server-Name
X-Cache-TTL
X-Sol
Pagespeed
Display
X-Middleton-Display
X-Server-ID
X-Cnection
X-Powered-By-Plesk
X-Element-Page-Cache
X-Abt-Application-Version
X-Browser-Type
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Id
X-Kinja-Server
X-GitHub-Request-Id
X-ESI
Nginx-Cache
X-Vcap-Request-Id
X-ECACHE
Edge-Control
X-D2id
Verso
X-Ac
X-ORACLE-DMS-RID
X-Ser
X-MS-InvokeApp
X-Client-IP
X-Ratelimit-Limit
X-Amz-Rid
X-Wormhole-Sdk
X-Middleton-Response
Response
X-Ratelimit-Remaining
X-Oneagent-Js-Injection
X-CST
X-B3-TraceId
X-Goog-Hash
X-ARC
X-Powered-CMS
X-Dw-Request-Base-Id
X-FTR-Request-ID
X-Navigation-Version
X-Edge-Location-Klb
X-Kinsta-Cache
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Upstream
X-Forwarded-For
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
SPRequestDuration
SPIisLatency
Origin-Trial
X-Cache-Key
X-Mod-Pagespeed
X-Content-Digest
Edge-Cache-Tag
RTSS
Cache-Status
Public-Key-Pins
X-NF-Request-ID
AR-Request-ID
AR-PoweredBy
AR-SID
AR-ATIME
X-Ezoic-Cdn
X-Ttl
X-FastCGI-Cache
X-Daa-Tunnel
X-Version
X-ORACLE-DMS-ECID
X-SharePointHealthScore
SPRequestGuid
X-Fastly-Request-ID
X-Mg-S
Realpath
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
S
X-MSEdge-Ref
X-Shield-Request-Id
X-T
Front-End-Https
X-Recruiting
Fastcgi-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Expires
X-Xrds-Location
Cross-Origin-Resource-Policy
X-Distributor
X-Cached
AR-CACHE
Arr-Disable-Session-Affinity
Access-Control-Request-Method
X-Azure-Ref
X-Request-Received
X-Request-Processing-Time
TP-Cache
X-Correlation-Id
X-Id
Count-Hit
X-HS-Content-Id
X-Debug
X-HS-Hub-Id
X-Ua-Browser
Cache-Tags
X-TTL
X-HS-Cache-Config
Akamai-GRN
X-Ismobilevalue
X-Cluster-Name
X-LLID
X-Newrelic-App-Data
X-TraceId
X-NGENIX-Cache
Server-Node
X-Content-Security-Policy-Report-Only
X-GUploader-UploadID
MicrosoftSharePointTeamServices
X-Nf-Request-Id
X-Hits
X-Varnish-TTL
X-Frontend
X-Varnish-Backend
X-VARITI-CCR
X-Protected-By
X-HS-Combine-CSS
X-Aspnetmvc-Version
X-Amz-Replication-Status
X-PressLabs-Stats
Accept-Ch
X-Fastcgi-Cache
X-Goog-Metageneration
X-LB-Cache
X-Microsite
X-Request-Handler-Origin-Region
Payment
X-Unique-Id
X-Ratelimit-Reset
X-Page-Id
X-DIS-Request-ID
X-Git-Hash
X-FB-Debug
X-Varnish-Server
X-Varnish-Ttl
Cleartype
Content-Disposition
X-Www-Served-By
X-Logged-In
X-AppVersion
X-Az
X-Activity-Id
X-HP-Trace-Id
X-Tt-Trace-Tag
X-HP-Webp
X-Jurisdiction
X-Tt-Trace-Host
X-Hostname
X-Cambria-Cache-Control
X-Template
Host
X-Amzn-RequestId
X-Amz-Apigw-Id
Filterid
Amp-Access-Control-Allow-Source-Origin
X-Forwarded-Proto
X-App-Server
X-Geo-Country
Version
Accept-Charset
X-Load-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Envoy-Decorator-Operation
X-Goog-Generation
X-Goog-Stored-Content-Length
Frame-Options
X-Cache-Age
X-Aspnet-Version
X-Type
X-WP-CF-Super-Cache-Cache-Control
X-Source
X-WP-CF-Super-Cache
Access-Control-Allow-Method
Fastly-SIE
X-TEC-API-ORIGIN
Fastly-SWR
X-TEC-API-VERSION
X-TEC-API-ROOT
X-ASPNET-VERSION
Section-Io-Cache
X-Upgrade-Enabled
Trailer
X-Fb-Rlafr
X-Content-Options
X-TT
Viewport
X-Origin-Server
X-HS-Prerendered
X-B
Server-Name
X-B3-Sampled
X-Grace
X-Ah-Environment
X-Language
X-Cache-Control
X-Device-Type
X-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Buckets
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
Retry-After
MS-Author-Via
X-Px
Content-MD5
X-Magnolia-Registration
X-Request-Guid
X-Vcl-Version
X-Mobile
X-Cdn
TCN
X-Trace-Id
X-Revision
X-EdgeConnect-Cache-Status
X-Varnish-Grace
X-Akamai-Edgescape
Protected
Healthy
X-WP-CF-Super-Cache-Active
X-Backend-Name
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Accept-Ch-Lifetime
X-Proxy
Upgrade-Insecure-Requests
X-Response-Served-From
X-Original-Request-Id
X-Instance
X-RM-Cache-TTL
X-Debug-Info
Charset
SD-X-WS
X-App-Environment
Cross-Origin-Embedder-Policy-Report-Only
X-NYM-Debug-Backend
X-CSRF-Token
X-Is-Bot
X-Tumblr-Pixel
X-Status
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-ProcessESI
X-ServerID
X-RemovedCookies
X-Rendered-As
Cross-Origin-Window-Policy
X-Adobe-Content
Access-Control-Request-Headers
X-Mg-Request-UUID
X-UUID
X-Region
X-Node-Name
X-Adobe-Loc
X-Cacheable-TTL
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-FW-Type
X-Framework
X-FW-Version
X-Storage
NGB
X-Content-Powered-By
X-Debug-IsConnected
X-Cache-Time
Ms-Operation-Id
MS-CV
X-Proxy-Cache-Info
X-RTag
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Whom
X-Rule
Refresh
X-Debug-IsPreview
X-Datadog-Sampling-Priority
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Edge-Location
GEO-INFO
X-Datadog-Trace-Id
X-G
OT-Force-Account-Verify
X-L-Path
X-Environment-Context
X-Lambda-Id
X-Contextid
Section-Io-Id
Webserver
X-Resp-Is-Stale
X-Amzn-Remapped-Content-Length
X-Reqid
X-Origin-Cache
DC
X-B3-Traceid
Countrycode
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Amz-Meta-S3cmd-Attrs
X-CCDN-Origin-Time
X-User-Agent
Paypal-Debug-Id
X-HTML-Minification-Powered-By
X-VC
X-Server-W
Alternate-Protocol
X-Time
SRV
X-Real-IP
Front
X-B3-SpanId
X-DataDome
Priority
X-TT-LOGID
X-Seen-By
X-ECache
Cross-Origin-Opener-Policy-Report-Only
X-Nginx-Cache
X-HS-CF-Cache-Status
WPO-Cache-Status
WPO-Cache-Message
X-WP-CF-Super-Cache-Cookies-Bypass
X-Hl-Ver
X-Origin-TTL
X-Origin-CC
Ohc-File-Size
X-Rocket-Nginx-Serving-Static
X-WebKit-CSP-Report-Only
Liferay-Portal
Xet-Cookie
X-IPS-LoggedIn
X-Mode
Backend
X-Akamai-Request-ID2
X-AB
X-JoinUs
TWC-GeoIP-Country
X-FB-TRIP-ID
Onion-Location
TWC-Device-Class
ServerID
TWC-Connection-Speed
X-UPSTREAM-Address
Property-Id
Fastcgi-Useragent
Meta-Geo
X-Format
X-Rewrite-Enabled
X-Say-Cacheable
X-Say-TTL
Web-Mar-Node
Environment
Webcakes-App-Name
X-SayCDN-TTL
X-Cache-Host
TWC-Privacy
Country
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Cache-Status-Check
X-Rn-Rsrv
X-SaId
Webcakes-Region
X-Tumblr-Pixel-2
X-Cache-Action
X-Origin-Hint
X-N
Webcakes-App-Version
X-Redis-Cache
DB-Nickname
X-Skip-Cache
X-Accel-Version
X-Tumblr-Pixel-3
Uber-Trace-Id
Expiry
X-Vcache
X-Soup
X-Director
X-VC-Cache
X-Tncms
X-Connection-Hash
X-IPLB-Request-ID
X-Cms-Context
X-PHP-Host
X-Labrador-Cache-Channel
X-Loop
X-Ms-Request-Id
X-Origin-Date
X-Cluster-Node
X-Restarts
X-IPLB-Instance
X-Scope-Id
X-Cache-Expired-At
Mn-Server-Ip
X-Ms-Version
X-Detected-As
X-Hosted-By
X-Handled-By
X-Fetched-On
X-Varnish-Age
From-Origin
X-Tb
X-DynaTrace
X-Frame-Option
X-Varnish-Beresp-Grace
Url
X-Logging-Id
X-Varnish-Cache-Hits
Atl-Traceid
Apigw-Requestid
X-Servername
X-Adobe-Source
X-ProxyCache-Key
X-R9-Blue-Green-Version
X-ProxyCache-Status
X-Forwarded-Host
X-Webstats-RespID
X-BYPASS-REASON
X-Httpd
X-Web-Node
X-Timing-Wait
X-RateLimit-Remaining
X-Auth-Group-Type
X-Served-From
X-Cluster
Filters
Selected-Fe
ServedBy
X-Proxy-Build
X-Proxied
X-Routing-Service
X-Cloudmap
X-Extlb
X-S
X-Origin
X-Zipkin-Id
X-Hit
Surrogated-Key
X-Azure-Ref-OriginShield
X-SRV
Cross-Origin-Embedder-Policy
Accept-Language
X-LSADC-Cache
LB
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Worker
X-Request-URI
X-Lagoon
X-Cache-Hit
Referer-Policy
X-CDN-Forward
X-Sucuri-Cache
N-Cache
X-Drupal-Cache-Tags
X-Generation-Time
X-Generated-By
X-Drupal-Cache-Contexts
X-App-Version
X-Cdn-Origin
X-Fastly-Request-Id
Xserver
X-Sucuri-ID
CF-IPCountry
X-MP-GENERATED-AT
X-Tx-Id
X-Xfnlog-Site
CDN-RequestId
VIX-Pulpo-Upstream-Status
X-AIR-PT
X-F-Cache
Source
VIX-Pulpo-Node
Node
X-TA-CDN-Provider
Ohc-Cache-HIT
X-Wix-Request-Id
Cache
X-Mly-Id
X-Via-CDN
X-Cache-Debug
X-Via-SSL
Edge-Copy-Time
X-Cache-Rule
X-Via-Edge
X-Varnish-Beresp-Ttl
X-VC-TTL
X-RCS-CacheZone
X-UA
X-INCAP-ABP
Cache-Provider
X-NODE
X-VCT
X-Site-Version
X-Pad
X-Locale
X-NWS-UUID-VERIFY
X-Tcp-Rtt
X-Geo-Region
X-GEO
X-Urbn-Site-Id
Locale
X-XRDS-Location
X-Is-Mobile
X-Is-Supported-Browser
X-Browser-Name
X-Is-Desktop
X-Urbn-Context-Path
X-Is-Tablet
Origin
Odigeo-Trace-Id
Producers
Redirect-Candidate
PFcat
Ha-Gx-Prefs
Cluster
DCR-Decision-By
DCR-Processing-Time-Ms
Expect-Staple
Candidate-Md5Url
BehaviorPad-Version
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Fastly-GeoIP-CountryCode
Fastly-SSL
Lang
Mail-Subject
MD5-Digest
Meta-Geo-Continent
L5d-Success-Class
Host-ID
Fl-Custom-Application
Rendered-Blocks
HA-Ipaddr
Ngx.Var.Host
X-Backend-Instance
X-HN
X-Geolocation
X-GeoIP-Region-Code
X-Ig-Origin-Region
X-Ig-Push-State
X-Mvc-Supplant-Cachable
X-Jobs
X-GeoIP-Country-Code
X-GeoCountry
X-Ec-GeoHdr
X-Ec-Fail
X-Eu-Site
X-External-Request-Id
X-GeoCode
X-FC-Vary-Parameters
X-Op-Id-All
X-Org
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Section
X-VarnishDD-TTL
X-Vdms-Version
Xc-Version
X-Vtex-Remote-Cache
X-SD-PageType
X-ScT
X-PAYTM-SRV-ID
X-Path
X-Platform-Server
X-Proxied-Request
X-S-Cookie
X-Rojux
X-DPWN-IS-SECURE
X-Developer
X-AB-Test
X-A-Wwc
X-A-Dgt
X-Access
X-Aed
X-Application
X-Aicache-OS
X-A-Dcw
X-A-Dam
Web-Mar-Region
We-Hiring
Wxu-Next-Commit
Wxu-Next-Region
X-A-Ccd
X-A
X-B-Cookie
X-Bc-Bl
X-Csrf-Jwt
X-Conf
X-D
X-Debug-Cache-Fetch
X-Destination
X-Debug-Cache-Store
X-CGP
X-Cache-Operation
X-Bl-Debug
X-BCube-Filmed-By
X-Bug-Bounty
X-Cache-Grace
X-Cache-NE
X-Cache-Info
Sslversion
Wxu-Next-Hostname
X-No-Session
X-ElasticPress-Query
X-Signature
X-Oracle-Dms-Ecid
X-B-Cache
X-DefHash
X-DefElseHash
X-CUA
X-Content-Age
X-Content-Length
X-Core-Value
X-Dispatcher-Server
X-Date
X-Epic-Correlation-Id
X-Gdpr
X-Gen-Mode
X-Generated-On
X-GeoIP
X-Gamma-Serve
X-Fmm-Version
X-CacheTTL
X-Esi-Check
X-Fastly-Backend
X-Ec-Custom-Error
X-Cache-Date
Thinkindot-CacheControl-Type
User-Cache-Control
V-Age
X-Accel-Expires-Debug
Thinkindot-CacheControl
TDXMobile
RNT-Machine
RNT-Time
Server-Host
X-AK-Request-ID
X-Akamai-Device-Characteristics
X-BBC-Edge-Cache-Status
X-Block-Status
X-GoCache-CacheStatus
X-Litespeed-Tag
X-B3-Trace-ID
X-Auto-Login
X-Amz-Meta-Cb-Modifiedtime
X-Amz-Storage-Class
X-App-Name
X-Cache-Id
X-Gzip
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Director
X-Varnish-Remaining-TTL
X-V-Cache
X-User
X-SB
X-Scheme
X-Shield-Cache-Expires
X-Thinkindot-L3
X-VG-WebCache
X-Via-Fastly
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Zen-Fury
X-Cached-By
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Viewer-Country
X-Vmg-Version
X-VServer
X-Request-Time
X-Request-Host
X-Loc
X-Location
X-Micro-Cache
X-Mvc-Supplant-OutputCached
X-Level-Front-Cache
X-Human
X-Hash
X-Via-JSL
X-Hnp-Log
X-HS-Content-Campaign-Id
X-NMSegId
X-Node-Id
X-Policy
X-Powered-By-VTEX-Cache
X-Proto
X-Req
X-Platform
X-Origin-Time
X-NodeID
X-Nyt-Route
X-Origin-Expires
Req-Svc-Chain
X-GeoIP-City
Fastly-Backend-Name
Debug
Content-Style-Type
Gannett-Cam-Experience-Id
Gh-Request-Id
Origin-Agent-Cluster
NM-Fastcgi-Cache
L
Content-Script-Type
Cdnsip
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
Cdncip
Canary
Platform
CDCHOST
Product
Akamai-Mon-Iucid-Del
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Contensis-Viewer-Groups
X-Storefront-Renderer-Rendered
Ssr
X-Sn-Servicetimems
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Thanos
X-Clientip
X-Cache-FS-Status
X-Cache-Aspx
X-Bip
X-VG-TLSProxy
X-Varnish-Beresp-Status
X-Varnish-Authentication
X-Cdn-Srv
X-TIM-N
X-UA-Device-Type
Req-ID
X-Shopify-Stage
X-ShopId
Content-Secure-Policy
ServerName
Country-Code
Cdn-Request-Time
Click-Count-Error
Click-Count-Action-Start
X-Men
X-IsAdmin
X-Internal-TTL
Cdn-Host
DSUID
X-Server-IP
X-ShardId
NGX
X-Edge-Server
X-Request-Start
X-Origin-Response-Time
X-Pool
X-Pubstack
X-Depends
Release
Tube-Return
Origin-EX
Yak-Timeinfo
X-Acquia-Purge-Cdn-Unconfigured
W
X-Alternate-Cache-Key
Tube-Got-Eval
Tube-Got-Results
X-We-Are-Hiring
X-Service
XM
Tube-Get-Contents
Origin-CC
X-Ua-Device
Mime-Version
X-SIPLIST1
CDN-Cache
CDN-EdgeStorageId
Fastly-Drupal-HTML
CDN-RequestPullSuccess
X-Irp-Debug
X-LB-NoCache
CDN-RequestPullCode
CDN-RequestCountryCode
CDN-CachedAt
User-Agent
CDN-PullZone
X-DC
X-TH-Server
IsBot
X-Tb-Optimization-Total-Bytes-Saved
CDN-Uid
X-URL
X-RID
X-Varnishpool
X-Varnish-Hits
X-Var-Ttl
X-HOST
X-Vgn-Hpd-Reason
X-NGINX-Cache
X-Presslabs-Stats
X-Cs
X-CACHE-GROUP
X-Moov-Xdn-Version
Pramga
X-Moov-Xdn-Caching-Status
X-Old-Content-Length
X-Moov-T
GeoIP-Latitude
Sid
X-Proxy-Cache-Status
X-ORCA-Accelerator
N1-Cache
X-RequestId
X-Servedbyhost
CloudFront-Viewer-Country
X-HubSpot-Correlation-Id
X-Wa
Esi-Enabled
X-ZONE
X-HITS
X-Refresh
X-Nc
X-Tt-Logid
X-Upstream-Ht
X-Upstream-Ct
Cdn-Requestid
X-Api-Version
X-Action
X-Via-Popv
X-HA-Backend
X-Via-Popn
X-Via-Poph
C-Via
Server-ID
TWC-GeoIP-Region
X-LiteSpeed-Cache-Control
TWC-GeoIP-City
Cache-Hits
TWC-GeoIP-DMA
X-LiteSpeed-Tag
X-LB-ID
X-Thinkindot-L1
X-Vercel-Id
X-Cache-VC
X-Vercel-Cache
Location
X-Cache-Bucket
X-APP
X-Newrelic-Synthetics
X-DynaTrace-JS-Agent
X-Webkit-Csp-Report-Only
A
X-Parent-Response-Time
X-B3-Parentspanid
XkeyRZ
X-Proxy-CacheRZ
Cache-Key
HostName
X-Zone
X-Webkit-CSP
X-Nananana
X-NewRelic-App-Data
AMP-Access-Control-Allow-Source-Origin
SID
X-B3-Spanid
X-PERF
X-ApacheServer
X-Endurance-Cache-Level
X-Dc
X-COUNTRY
X-Webkit-Csp
X-API-Version
X-CS
WP-Super-Cache
X-Ua
X-Render-Time
Proxy-Firewall
X-WA-Info
X-Fpc
Fastly-Drupal-Html
X-Srv
X-CACHE-AGE
X-Cdn-Forward
X-Nitro-Cache
Uri
X-DataCenter
X-Uri
X-Litespeed-Cache-Control
X-Ion-Healthy
X-Ion-Hop
X-Jungle-Id
GeoIp-Country-Code
True-Client-Ip
TP-L2-Cache
RewriteTeamHook
Cache-Contol
RewriteTestHook
Log-Origin
My-App
Cmstype
Server-Hostname
Cmsid
Sever-Int
True-Client-Country-4JS
X-Optimistic-Header
Server-Ext
GeoIP-Country-Code
Sm-Log-Id
X-Service-Response-Time
True-Client-IP
X-Datadome
X-Test
X-Up
Resin-Trace
X-From
Cdn
X-CLOUD-TRACE-CONTEXT
CacheControlHeader
Adler-Geo
X-Ssense-Gql
X-Dispatcher-Number
X-Datacenter
X-Ssense-Shipping-Surcharge-Enabled
Is-Eu
SEZNAM-JOBS-OFFER
X-Pass-Why
X-SERVER-NAME
X-Stale
WZWS-RAY
Tcn
X-Nginx-Cache-Key
X-Client-Ip
X-Varnish-Beresp-TTL
X-Udemy-Cache-App-Namespace
X-FPC
X-RateLimit-Limit
X-Srcache-Store-Status
X-Dynatrace-Js-Agent
X-Srcache-Fetch-Status
Srv
X-Custom-Header
X-AWS-Id
Lb
T-Server
X-Oracle-Dms-Rid
X-Geo-Header
X-LJ-Flow-ID
X-APP-VERSION
X-VWS-Id
X-Provided-By
X-Air-Source
X-Air-Pt
Hostname
X-Air-Trace-Id
X-Air-Hostname
X-Fastly-Cache-Status
X-Debug-Service
X-ND-Cache
Origin-Site
X-TX-ID
X-App
X-Varnish-Hostname
X-Cache-Server
X-SRCache-Key
X-CMSURLCustom
Server-Id
NtCoent-Length
Serverhost
Vc-Max-Age
X-Vc
X-Fastly-Backend-Reqs
X-VCL-Version
Edge-Cache
X-Akamai-Pragma-Client-IP
AKAMAI-GRN
Pics-Label
X-Lb-Id
Cf-Ipcountry
X-Correlation-ID
X-Cache-Ttl
S-Rt
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Ha-Backend
Powered-By
X-NC
Pragrma
YJS-ID
X-Cdn-Cache-Status
X-WA
ServerHost
X-Html-Minification-Powered-By
Av-Poweredby
X-Oracle-DMS-ECID
X-Esi
Cache-Tv-Group
X-XRDS-LOCATION
Vix-Hermes-Req-Id
Machine
X-Sigma
X-Forwarded-Site
X-Rocket-Build-Number
Geoip-Latitude
X-Region-Sid
Epwk-X-Cache
X-Sigma-Backend
X-Cache-TTL-Remaining
X-LAGOON
X-Ckpd-Fst-Backend
Ms-Author-Via
WWW-Authenticate
X-Requestid
X-ServedByHost
Cloudfront-Viewer-Country
WebServer
Xkeylog
X-Traceid
X-Fastly-Cache
Nord-Request-ID
X-Proxy-Cache-La3
Xkey-La3
CountryCode
X-MSEdge-Flight
MIME-Version
X-Sucuri-Id
On-Server
X-Akamai-ERRuleID
Thinkindot-Control
X-MSEdge-Features
Warning
X-HS-Status
X-Akamai-ERPolicy
X-IAuth-Set-Uid
X-Wp-Cf-Super-Cache
DataCenter
FSS-Cache
Reporter
X-Wp-Cf-Super-Cache-Cache-Control
X-Lb-Nocache
X-Check-Cacheable
X-Serial
X-Lsadc-Cache
X-Vary-Devices
Store-Cloud-Cache
X-Cdn-Request-ID
AKAMAI
Timeexpire
X-Mg-Cache
X-Akamai-Transformed
X-Orig-Cache-Control
X-Ee-Request-Date
X-Ee-Request-Id
X-PHP-Backend
X-Save-Cache
X-Tncms-Bot-Tier
X-Ee-Generated-By
Time-Cloud-Cache
X-Ee-Origin
X-Elasticpress-Query
X-BBC-Origin-Response-Status
X-Web-Server
X-Cms-Device
X-VTEX-Cache-Backend-Connect-Time
X-Td-Header-From-No-Data
Thinkindot-Cache-Type
X-Amz-Meta-Opti
Cneonction
X-Dw-Trace-Id
X-VTEX-Cache-Backend-Header-Time