Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
Via
X-XSS-Protection
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
X-Xss-Protection
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
X-Drupal-Cache
X-Generator
Server-Timing
X-Cache-Status
P3p
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Request-ID
X-FRAME-OPTIONS
X-Iinfo
X-Check
X-Drupal-Dynamic-Cache
X-Content-Security-Policy
Permissions-Policy
X-Ua-Compatible
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-CDN
X-AspNetMvc-Version
Accept-CH
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
X-Amz-Request-Id
Request-Context
X-Amz-Id-2
X-Backend
X-Hacker
Accept-CH-Lifetime
X-Turbo-Charged-By
Keep-Alive
X-Proxy-Cache
Cf-Apo-Via
X-Via
X-Cache-Group
X-Rq
EagleId
X-Age
X-Server
X-UA-Device
X-Dispatcher
X-Vhost
X-Amz-Version-Id
X-AH-Environment
X-Dns-Prefetch-Control
X-Ws-Request-Id
X-Varnish-Cache
X-Litespeed-Cache
Grace
X-Server-Powered-By
X-WebKit-CSP
Allow
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
X-Cache-Lookup
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-Page-Speed
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Device
EagleEye-TraceId
X-Backend-Server
X-Akam-SW-Version
X-Host
X-Response-Time
Surrogate-Control
X-Cloud-Trace-Context
Cf-Railgun
X-Readtime
X-Server-Id
X-Node
X-HW
Xkey
Request-Id
X-Ruxit-JS-Agent
X-LiteSpeed-Cache
X-Country
X-Url
X-Nginx-Cache-Status
X-Application-Context
X-NWS-LOG-UUID
X-Content-Type
Content-Location
Cache-Tag
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
X-Trace
Service-Worker-Allowed
X-Amz-Server-Side-Encryption
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Times
X-PC
X-Vname
X-TtlSet
X-Mcache
X-Midtier
X-Edge
X-Rack-Cache
X-Country-Code
Rating
X-Oneagent-Js-Injection
Surrogate-Key
X-Server-Name
X-Browser-Type
X-ESI
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Abt-Application-Version
X-Cnection
X-Element-Page-Cache
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Exp-Id
X-Exp-Variant
X-Ser
X-Cache-TTL
Edge-Control
X-GitHub-Request-Id
X-Powered-By-Plesk
Nginx-Cache
X-D2id
Verso
X-Ac
X-Dw-Request-Base-Id
X-ARC
X-Vcap-Request-Id
X-Client-IP
X-MS-InvokeApp
X-ORACLE-DMS-RID
X-Daa-Tunnel
Accept-Ch-Lifetime
X-Ttl
X-Upstream
X-Navigation-Version
X-Amz-Rid
X-Goog-Hash
X-Aspnet-Version
X-CST
X-Powered-CMS
X-Middleton-Response
Response
X-B3-TraceId
X-Instrumentation
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kinsta-Cache
X-Edge-Location-Klb
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-SID
X-Cache-Key
X-Amzn-Trace-Id
X-NF-Request-ID
X-Forwarded-For
X-ECACHE
X-Ua-Device
RTSS
X-Ruxit-Js-Agent
X-Mod-Pagespeed
X-Ratelimit-Limit
X-FastCGI-Cache
SPRequestDuration
X-Wormhole-Sdk
SPIisLatency
AR-CACHE
Edge-Cache-Tag
Cache-Status
X-Server-ID
X-Version
X-ORACLE-DMS-ECID
Public-Key-Pins
X-Mg-S
X-Ratelimit-Remaining
S
Cross-Origin-Resource-Policy
X-Ezoic-Cdn
X-SharePointHealthScore
SPRequestGuid
X-MSEdge-Ref
Realpath
X-Shield-Request-Id
X-T
Fastcgi-Cache
X-Content-Digest
X-Cached
X-Recruiting
X-Accel-Expires
Access-Control-Request-Method
Accept-Ch
X-Newrelic-App-Data
X-Distributor
TP-Cache
X-Correlation-Id
Arr-Disable-Session-Affinity
Count-Hit
X-Kong-Upstream-Latency
X-Id
X-Kong-Proxy-Latency
Front-End-Https
X-Debug
X-Request-Processing-Time
X-Request-Received
X-Content-Security-Policy-Report-Only
Server-Node
X-Ua-Browser
X-HS-Hub-Id
X-VARITI-CCR
X-HS-Content-Id
X-HS-Cache-Config
X-LLID
MicrosoftSharePointTeamServices
X-Frontend
X-HS-Combine-CSS
X-Varnish-TTL
X-Azure-Ref
X-PressLabs-Stats
Cache-Tags
X-Ismobilevalue
X-Cluster-Name
X-Hits
Payment
X-Fastly-Request-ID
X-Forwarded-Proto
X-LB-Cache
X-Amz-Replication-Status
X-Varnish-Backend
X-Goog-Metageneration
X-GUploader-UploadID
X-Varnish-Ttl
Filterid
X-Microsite
X-Request-Handler-Origin-Region
X-Unique-Id
X-FB-Debug
X-Git-Hash
Host
X-Protected-By
Cleartype
X-Www-Served-By
X-Logged-In
X-Varnish-Server
X-Activity-Id
X-Az
X-Ratelimit-Reset
X-AppVersion
Content-Disposition
X-App-Server
X-Hostname
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-NGENIX-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
Access-Control-Allow-Method
X-Geo-Country
Retry-After
X-Origin-Server
X-Page-Id
X-DIS-Request-ID
X-WP-CF-Super-Cache-Cache-Control
X-ECache
X-WP-CF-Super-Cache
X-Load-Cache
X-RateLimit-Remaining
X-Goog-Stored-Content-Length
MS-Author-Via
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Upgrade-Enabled
Accept-Charset
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Nf-Request-Id
Akamai-GRN
Fastly-SIE
X-ASPNET-VERSION
Section-Io-Cache
Fastly-SWR
X-Type
X-Pinterest-Rid
X-TT
Viewport
Pinterest-Version
Pinterest-Generated-By
X-Fb-Rlafr
X-TTL
X-Cache-Control
X-Fastcgi-Cache
Origin-Trial
Content-MD5
Amp-Access-Control-Allow-Source-Origin
X-Grace
X-Content-Options
X-B
X-B3-Sampled
X-Ah-Environment
Version
X-Cambria-Cache-Control
X-Template
X-Origin-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Request-Guid
X-Revision
TCN
X-Amz-Meta-S3cmd-Attrs
X-Trace-Id
Frame-Options
X-Vcl-Version
X-Fastly-Request-Id
Healthy
X-Envoy-Decorator-Operation
X-Contextid
X-Magnolia-Registration
X-Device-Type
X-Cdn
X-CSRF-Token
X-Xrds-Location
X-Source
X-WP-CF-Super-Cache-Active
DC
X-Cache-Age
X-Backend-Name
Server-Name
X-Aspnetmvc-Version
X-Webkit-CSP
X-Seen-By
X-Px
X-Proxy
X-Mobile
X-Varnish-Grace
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-0
X-RM-Cache-TTL
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-App-Environment
X-Tumblr-User
X-Rule
X-Status
X-Mg-Request-UUID
X-Debug-Info
Access-Control-Request-Headers
X-Storage
X-Framework
NGB
X-Adobe-Content
SD-X-WS
Cross-Origin-Window-Policy
X-Region
X-Proxy-Cache-Info
X-NYM-Debug-Backend
X-Adobe-Loc
X-UUID
X-Environment-Context
X-L-Path
X-Node-Name
X-ServerID
X-Debug-IsPreview
X-Cacheable-TTL
X-G
X-Debug-IsConnected
X-Rid
X-Instance
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Dynamic
X-HTML-Minification-Powered-By
X-Content-Powered-By
X-FW-Hash
X-Yottaa-Optimizations
X-Is-Bot
GEO-INFO
X-Yottaa-Metrics
X-Akamai-Edgescape
X-FW-Type
Paypal-Debug-Id
X-Rendered-As
X-FW-Version
X-Datadog-Sampled
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-RTag
X-User-Agent
Ms-Operation-Id
MS-CV
X-Datadog-Sampling-Priority
X-CLOUD-TRACE-CONTEXT
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-EdgeConnect-Cache-Status
Countrycode
Front
X-Language
Webserver
X-Cache-Time
Upgrade-Insecure-Requests
X-WebKit-CSP-Report-Only
X-Buckets
Charset
X-B3-Traceid
Protected
X-Whom
X-N
OT-Force-Account-Verify
X-IPS-LoggedIn
X-Akamai-Request-ID2
X-VC
X-Cache-Status-Check
X-Lambda-Id
X-AB
Country
X-Edge-Location
Section-Io-Id
X-CACHE-GROUP
Refresh
Priority
X-TT-LOGID
Trailer
X-Time
X-VHOST
X-Hl-Ver
X-Hcs-Proxy-Type
X-Via-JSL
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Backend
X-Amzn-Remapped-Content-Length
X-Reqid
X-WP-CF-Super-Cache-Cookies-Bypass
X-XRDS-LOCATION
X-HS-Prerendered
Alternate-Protocol
X-B3-SpanId
Accept-Language
X-Wix-Request-Id
Liferay-Portal
Xet-Cookie
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-DataDome
Onion-Location
X-Generated-By
X-Accel-Version
X-Scope-Id
X-Fetched-On
X-FB-TRIP-ID
X-Rn-Rsrv
X-Cache-Host
X-Auth-Group-Type
X-Frame-Option
Meta-Geo
Environment
X-JoinUs
X-Tb
X-Origin-Date
Fastcgi-Useragent
Filters
X-Request-URI
Uber-Trace-Id
ServerID
From-Origin
X-Rewrite-Enabled
X-SaId
X-Tumblr-Pixel-2
X-UPSTREAM-Address
X-VC-Cache
X-Web-Node
X-Skip-Cache
X-Format
X-ProxyCache-Key
TWC-Privacy
X-ProxyCache-Status
X-R9-Blue-Green-Version
Webcakes-App-Version
X-Origin-Hint
X-Webstats-RespID
Webcakes-Region
TWC-GeoIP-LatLong
Atl-Traceid
X-Hosted-By
Property-Id
Expiry
X-Logging-Id
TWC-Connection-Speed
X-BYPASS-REASON
TWC-GeoIP-Country
TWC-Device-Class
TWC-Locale-Group
Webcakes-App-Name
X-Cache-Expired-At
X-Cache-Action
X-Varnish-Age
X-Director
X-Say-TTL
X-Connection-Hash
X-Say-Cacheable
X-Redis-Cache
X-SayCDN-TTL
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Loop
X-Tncms
X-IPLB-Instance
X-Httpd
X-Cluster-Node
LB
X-Restarts
X-IPLB-Request-ID
X-Real-IP
X-Server-W
X-Cms-Context
Web-Mar-Node
X-Served-From
X-Forwarded-Host
X-Adobe-Source
X-Handled-By
X-Vcache
X-RID
Apigw-Requestid
X-Soup
X-Mode
Selected-Fe
ServedBy
Mn-Server-Ip
X-PHP-Host
X-Labrador-Cache-Channel
X-Timing-Wait
X-Proxy-Build
X-Nginx-Cache
Url
X-S
X-Detected-As
X-Servername
DB-Nickname
X-Cluster
X-Original-Request-Id
X-Response-Served-From
Xserver
X-Origin
Referer-Policy
X-Origin-TTL
SRV
CF-IPCountry
X-Origin-CC
X-Proxied
N-Cache
X-Zipkin-Id
X-Cloudmap
X-Extlb
X-Lagoon
X-Routing-Service
X-Hit
X-LSADC-Cache
Cross-Origin-Embedder-Policy-Report-Only
X-Rocket-Nginx-Serving-Static
X-SRV
X-Xfnlog-Site
X-UA
CDN-RequestId
X-Upstream-Ct
X-Upstream-Ht
X-XRDS-Location
Cross-Origin-Embedder-Policy
X-Ms-Request-Id
X-Ms-Version
X-Webkit-Csp
X-Tumblr-Pixel-3
X-VCT
X-Cache-Debug
Source
X-TraceId
X-Proxy-Cache-Status
X-RCS-CacheZone
X-NWS-UUID-VERIFY
X-Azure-Ref-OriginShield
X-F-Cache
X-DynaTrace
X-RateLimit-Limit
X-B-Cache
X-Signature
X-Geo-Region
X-Is-Mobile
X-Is-Supported-Browser
X-Is-Tablet
WPO-Cache-Status
X-Tcp-Rtt
Surrogated-Key
X-Browser-Name
WPO-Cache-Message
X-Is-Desktop
X-Urbn-Context-Path
X-Urbn-Site-Id
X-RateLimit-Limit-Second
X-Worker
X-RateLimit-Remaining-Second
Locale
X-No-Session
Node
X-Generation-Time
X-Cdn-Origin
X-Sucuri-Cache
X-ShardId
X-ShopId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-FTR-Request-ID
X-Drupal-Cache-Contexts
TP-L2-Cache
X-Locale
X-Tx-Id
X-Sucuri-ID
X-Cdn-Forward
X-NODE
X-Drupal-Cache-Tags
X-Site-Version
X-NGINX-Cache
X-Optimistic-Header
X-Cache-Rule
X-Service
X-Cache-Operation
X-GeoIP
Thinkindot-CacheControl-Type
X-DefElseHash
X-GeoCountry
Origin-Agent-Cluster
X-Debug-Cache-Store
X-Debug-Cache-Fetch
A
Azure-RegionName
Azure-SiteName
Azure-InstanceId
X-Conf
Thinkindot-CacheControl
X-Contensis-Viewer-Groups
X-D
X-Gdpr
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
Sslversion
X-Ec-Fail
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Developer
Azure-SlotName
Producers
X-GeoCode
TDXMobile
Rendered-Blocks
Redirect-Candidate
X-Depends
X-DefHash
X-Cache-Info
DCR-Processing-Time-Ms
X-Aed
Expect-Staple
DCR-Decision-By
X-Aicache-OS
Cluster
Content-Secure-Policy
X-AK-Request-ID
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
X-A-Ccd
X-A
Host-ID
X-A-Dam
X-A-Dcw
X-A-Wwc
Gannett-Cam-Experience-Id
X-A-Dgt
We-Hiring
Mail-Subject
X-Bug-Bounty
X-BCube-Filmed-By
Odigeo-Trace-Id
X-Cache-Aspx
Lang
BehaviorPad-Version
X-Cache-NE
Candidate-Md5Url
Ngx.Var.Host
X-Bc-Bl
Meta-Geo-Continent
MD5-Digest
X-Amz-Storage-Class
X-App-Name
Cdnsip
X-Backend-Instance
Cdncip
Azure-Version
X-GeoIP-City
X-Request-Time
X-Proxy-CacheRZ
X-Scheme
X-ScT
X-We-Are-Hiring
X-Shield-Cache-Expires
X-Proxied-Request
X-Proto
X-Origin-Expires
X-Org
X-Origin-Response-Time
X-Origin-Time
X-Platform-Server
X-PAYTM-SRV-ID
X-Thinkindot-L3
X-TIM-N
Cache
Xc-Version
X-VG-WebCache
X-Viewer-Country
X-Vtex-Remote-Cache
X-Vmg-Version
XkeyRZ
X-Vdms-Version
X-Varnish-CookieHashed-On
X-Varnish-Authentication
X-Varnish-CookieINHashed-On
X-Varnish-Director
X-Varnish-Remaining-TTL
X-Nyt-Route
X-Rojux
X-LiteSpeed-Tag
X-Mly-Id
X-Internal-TTL
X-Ig-Push-State
X-Loc
X-Mvc-Supplant-Cachable
X-ElasticPress-Query
X-Ig-Origin-Region
X-Mvc-Supplant-OutputCached
X-INCAP-ABP
X-Jobs
Sid
Mime-Version
X-App-Version
Web-Mar-Region
X-Hash
X-VarnishDD-TTL
Wxu-Next-Commit
X-Varnishpool
W
X-HS-Content-Campaign-Id
X-Eu-Site
X-Var-Ttl
X-V-Cache
X-Varnish-Beresp-Status
X-Fastly-Backend
Wxu-Next-Region
X-HN
Wxu-Next-Hostname
X-Gamma-Serve
X-GeoIP-Country-Code
X-Generated-On
X-Via-Fastly
Server-Host
RNT-Time
X-Wikidot-Backend
RNT-Machine
X-Wikidot-Static-Cache
X-GeoIP-Region-Code
Tube-Get-Contents
X-Human
V-Age
X-Fmm-Version
User-Agent
Tube-Return
Tube-Got-Eval
Tube-Got-Results
X-VG-TLSProxy
X-GoCache-CacheStatus
X-SVT-ORM-VERSION
X-CacheTTL
X-CGP
X-Pool
X-Ec-Custom-Error
X-Level-Front-Cache
X-Pubstack
X-Cache-Bucket
X-Cache-Grace
X-Policy
X-Location
X-Csrf-Jwt
X-Op-Id-All
X-Date
X-Core-Value
X-Content-Age
X-Micro-Cache
X-Clientip
X-Req
X-Bl-Debug
X-SVT-ORM-RULES
X-Edge-Server
Yak-Timeinfo
X-Node-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Tb-Optimization-Total-Bytes-Saved
X-Access
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
X-SD-PageType
X-BBC-Edge-Cache-Status
Req-Svc-Chain
X-B3-Trace-ID
X-Section
X-Akamai-Device-Characteristics
X-Slack-Backend
X-Accel-Expires-Debug
PFcat
Content-Style-Type
Debug
Content-Script-Type
Click-Count-Error
Click-Count-Action-Start
DSUID
Esi-Enabled
L
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
Cdn-Request-Time
Cdn-Host
X-Path
X-MP-GENERATED-AT
X-Pad
AMP-Access-Control-Allow-Source-Origin
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Canary
Cache-Provider
Cache-Key
Apple-News-Services-Request-Url
L5d-Success-Class
Apple-News-Services-Host
Release
NGX
Platform
Product
Ohc-File-Size
X-Dc
X-Air-Pt
X-Api-Version
X-Cache-Id
CDN-Cache
Origin-EX
CDN-CachedAt
CDN-EdgeStorageId
X-Bip
X-Thanos
CDN-PullZone
X-Cache-FS-Status
X-Cdn-Srv
X-NodeID
Origin
X-Cached-By
X-CUA
X-UA-Device-Type
Pramga
Origin-CC
CDN-RequestCountryCode
Ssr
X-NMSegId
X-Dispatcher-Server
CDN-RequestPullSuccess
XM
Fastly-SSL
X-VTEX-Cache-Server
CDN-RequestPullCode
X-Men
X-Gzip
X-Platform
X-Server-IP
X-Powered-By-VTEX-Cache
NM-Fastcgi-Cache
Country-Code
X-Auto-Login
X-Esi-Check
CDN-Uid
X-SB
X-Request-Host
Cross-Origin-Opener-Policy-Report-Only
X-Amz-Meta-Cb-Modifiedtime
X-VTEX-Cache-Time
X-Cache-Hit
X-LiteSpeed-Cache-Control
X-Newrelic-Synthetics
X-Varnish-Beresp-Ttl
X-SIPLIST1
X-Request-Start
IsBot
ServerName
Req-ID
X-Block-Status
X-Gen-Mode
CDCHOST
User-Cache-Control
X-Content-Length
X-Hnp-Log
X-HOST
X-Provided-By
Fl-Custom-Application
X-Irp-Debug
X-AB-Test
X-Varnish-Hits
True-Client-Country-4JS
X-AWS-Id
X-LJ-Flow-ID
Akamai-Mon-Iucid-Del
X-VWS-Id
X-Test
X-RequestId
X-ORCA-Accelerator
X-GEO
GeoIP-Latitude
X-Cs
Server-Ext
Proxy-Firewall
C-Via
Is-Eu
X-TA-CDN-Provider
Server-Hostname
X-APP
Adler-Geo
Sever-Int
X-B3-Spanid
Fastly-Drupal-Html
X-VServer
S-Rt
X-Nananana
X-Servedbyhost
X-Dispatcher-Number
X-HITS
X-LB-NoCache
X-Refresh
X-B3-Parentspanid
CloudFront-Viewer-Country
X-HS-CF-Cache-Status
Cache-Tv-Group
Edge-Copy-Time
X-Via-Edge
X-Via-CDN
X-Cache-Date
X-Nginx-Cache-Key
WZWS-RAY
X-Via-SSL
X-Geolocation
X-ZONE
T-Server
X-External-Request-Id
X-S-Cookie
X-Zone
X-IsAdmin
X-Custom-Header
X-Application
X-B-Cookie
Fastly-Drupal-HTML
X-Geo-Header
X-Destination
X-Pass-Why
X-Endurance-Cache-Level
X-DC
X-Via-Poph
X-Zen-Fury
X-Via-Popv
X-Via-Popn
X-LB-ID
X-Wa
X-ND-Cache
X-HA-Backend
X-Nc
X-Tt-Logid
X-DynaTrace-JS-Agent
Vc-Max-Age
HostName
GeoIp-Country-Code
X-Cache-Server
X-CMSURLCustom
X-CS
X-Webkit-Csp-Report-Only
X-User
X-CDN-Forward
X-Litespeed-Tag
X-Srv
Cdn
Cdn-Requestid
X-Presslabs-Stats
X-URL
Server-ID
X-COUNTRY
X-Oracle-Dms-Ecid
X-Parent-Response-Time
True-Client-IP
X-Varnish-Beresp-TTL
X-CACHE-AGE
Ohc-Cache-HIT
X-APP-VERSION
X-AIR-PT
Srv
X-HubSpot-Correlation-Id
Powered-By
X-DataCenter
Vix-Hermes-Req-Id
X-VC-TTL
SID
X-Fastly-Cache
X-Ckpd-Fst-Backend
WP-Super-Cache
X-Moov-Xdn-Caching-Status
X-Moov-Xdn-Version
X-Vgn-Hpd-Reason
X-NewRelic-App-Data
X-Moov-T
X-Fpc
Resin-Trace
On-Server
Uri
Pics-Label
X-TH-Server
X-API-Version
ServerHost
X-Old-Content-Length
SEZNAM-JOBS-OFFER
X-FPC
Thinkindot-Control
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Srcache-Fetch-Status
X-Srcache-Store-Status
True-Client-Ip
X-PHP-Backend
X-Vercel-Id
X-Vercel-Cache
AKAMAI
X-Amz-Meta-Opti
X-Cache-Ttl
X-Cache-TTL-Remaining
X-SERVER-NAME
Serverhost
X-TX-ID
X-Datadome
Server-Id
X-Client-Ip
Magicmarker
X-Action
Location
X-Thinkindot-L1
X-Cache-VC
GeoIP-Country-Code
X-Info
X-Dynatrace-Js-Agent
X-Oracle-Dms-Rid
Hostname
Cl-Cache
X-CDN-Cache-Status
X-Stale
X-NC
Av-Poweredby
N1-Cache
X-V
X-WA
X-Cdn-Cache-Status
X-Debug-Service
CDN
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-Rollout
X-FTR-Cache-Status
X-IAuth-Set-Uid
X-Eligible
X-FTR-Expires
X-New
X-Lb-Id
Sm-Log-Id
X-Service-Response-Time
X-Vc
Store-Cloud-Cache
X-Geo
X-Ee-Request-Date
X-Save-Cache
X-Vary-Devices
X-Datacenter
X-Ha-Backend
X-Ee-Request-Id
X-Ee-Origin
X-Forwarded-Site
X-Cms-Device
X-Ee-Generated-By
Time-Cloud-Cache
X-Via-PopV
X-Udemy-Cache-App-Namespace
X-Region-Sid
X-PERF
Machine
X-WA-Info
X-ApacheServer
X-Via-PopH
X-Fastly-Cache-Status
X-Via-PopN
X-VTEX-Cache-Backend-Connect-Time
X-VTEX-Cache-Backend-Header-Time
X-Resp-Is-Stale
X-Github-Request-Id
Server-Info
X-Lb-Nocache
X-Oracle-DMS-ECID
X-Git-Commit
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
X-Limited
X-Container-Uri
Cloudfront-Viewer-Country
X-Nitro-Cache
X-Fastly-Backend-Reqs
X-Render-Time
Xkey-La3
X-Proxy-Cache-La3
Xkeylog
X-ServedByHost
X-Litespeed-Cache-Control
X-App
X-Ftr-Request-Id
Tcn
X-VCL-Version
X-Uri
TWC-GeoIP-DMA
TWC-GeoIP-Region
TWC-GeoIP-City
Cache-Hits
RewriteTeamHook
X-EC-Lua
X-SRCache-Key
X-MSEdge-Features
Cache-Contol
RewriteTestHook
X-MSEdge-Flight
Log-Origin
Permission-Policy
Edge-Cache
WWW-Authenticate
X-Jungle-Id
X-Akamai-Pragma-Client-IP
X-Traceid
X-Varnish-Hostname
Geoip-Latitude
Cneonction
X-Ion-Hop
X-Ion-Healthy
WebServer
CountryCode
X-Correlation-ID
X-LAGOON
My-App
Pragrma
Cmsid
X-Akamai-Transformed
PICS-Label
Cmstype
X-HS-Status
X-Acquia-Application-UUID
X-From
FSS-Cache
Reporter
X-Dw-Trace-Id
X-Requestid
NtCoent-Length
X-Cdn-Request-ID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Pod
X-Acquia-Site
X-Serial
X-Check-Cacheable
X-Ua
X-Sucuri-Id
Cf-Ipcountry
X-UP
X-Elasticpress-Query
X-Up
X-BBC-Origin-Response-Status
X-Th-Server
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-Ramcache
CF-Cached-On
X-Fastly-Cache-Hits
X-Ad-Load-Variation
X-Web-Server
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Sqd-Stime
Warning
Timeexpire
X-Tncms-Bot-Tier
X-Sqd-Ctime
X-Orig-Cache-Control