Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
CF-Ray
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
X-Drupal-Cache
X-Generator
Server-Timing
P3p
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
X-Check
Permissions-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-Ua-Compatible
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
Accept-CH
X-Backend
X-Hacker
X-Turbo-Charged-By
X-Cache-Group
Cf-Apo-Via
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
X-Age
EagleId
X-Server
X-Dispatcher
X-UA-Device
X-Vhost
X-Amz-Version-Id
X-AH-Environment
Accept-CH-Lifetime
X-Ws-Request-Id
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Litespeed-Cache
Allow
X-Swift-CacheTime
X-Pingback
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-WebKit-CSP
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Page-Speed
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Device
X-Backend-Server
EagleEye-TraceId
X-Akam-SW-Version
X-Host
X-Response-Time
Surrogate-Control
X-Cloud-Trace-Context
Cf-Railgun
X-Readtime
X-Node
X-Server-Id
X-HW
X-LiteSpeed-Cache
Xkey
X-Ruxit-JS-Agent
Request-Id
X-Country
X-Url
X-Nginx-Cache-Status
X-NWS-LOG-UUID
X-Application-Context
X-Content-Type
Cache-Tag
Content-Location
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
Service-Worker-Allowed
X-Trace
X-Amz-Server-Side-Encryption
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Times
X-PC
X-TtlSet
X-Vname
X-Rack-Cache
X-Edge
X-Mcache
X-Midtier
X-Country-Code
Rating
Surrogate-Key
X-Server-Name
X-Browser-Type
X-Middleton-Display
X-Sol
Display
Pagespeed
X-Cache-TTL
X-Cnection
X-Element-Page-Cache
X-ESI
X-Oneagent-Js-Injection
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Abt-Application-Version
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Ser
Nginx-Cache
X-GitHub-Request-Id
X-Powered-By-Plesk
Edge-Control
X-D2id
Verso
X-Ac
X-Dw-Request-Base-Id
X-Vcap-Request-Id
X-ARC
X-Client-IP
X-MS-InvokeApp
X-ECACHE
Accept-Ch-Lifetime
X-ORACLE-DMS-RID
X-Aspnet-Version
X-Daa-Tunnel
X-B3-TraceId
X-CST
X-Navigation-Version
Response
X-Middleton-Response
X-Goog-Hash
X-Amz-Rid
X-Powered-CMS
X-Upstream
X-Kinsta-Cache
X-Edge-Location-Klb
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-Server-Lifecycle-Phase
X-NF-Request-ID
X-Ua-Device
X-Amzn-Trace-Id
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-Cache-Key
AR-SID
X-Forwarded-For
X-Ttl
RTSS
X-Wormhole-Sdk
X-Mod-Pagespeed
X-Server-ID
X-Ratelimit-Limit
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
Cache-Status
X-Version
X-Ratelimit-Remaining
X-ORACLE-DMS-ECID
Public-Key-Pins
X-Ruxit-Js-Agent
X-FastCGI-Cache
AR-CACHE
X-Mg-S
X-Ezoic-Cdn
S
Cross-Origin-Resource-Policy
Realpath
SPRequestGuid
X-Shield-Request-Id
X-SharePointHealthScore
X-Content-Digest
X-MSEdge-Ref
Fastcgi-Cache
X-T
X-Cached
X-Recruiting
X-Accel-Expires
Access-Control-Request-Method
X-Distributor
X-Fastly-Request-ID
X-Varnish-TTL
X-Newrelic-App-Data
X-Kong-Upstream-Latency
Front-End-Https
X-Kong-Proxy-Latency
Count-Hit
TP-Cache
X-Debug
X-Request-Received
X-Request-Processing-Time
Arr-Disable-Session-Affinity
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
Server-Node
X-Id
X-Ua-Browser
X-Azure-Ref
X-LLID
X-VARITI-CCR
X-Correlation-Id
X-HS-Combine-CSS
X-Frontend
X-PressLabs-Stats
Cache-Tags
X-Cluster-Name
X-Ismobilevalue
X-Hits
Payment
Accept-Ch
X-GUploader-UploadID
X-LB-Cache
X-Amz-Replication-Status
X-Goog-Metageneration
X-Varnish-Backend
X-Forwarded-Proto
X-TTL
X-Request-Handler-Origin-Region
X-Microsite
X-Protected-By
Filterid
X-FB-Debug
Host
X-Git-Hash
X-Unique-Id
X-Logged-In
Cleartype
X-Www-Served-By
Content-Disposition
X-Activity-Id
X-AppVersion
X-Varnish-Server
X-Az
X-Ratelimit-Reset
X-Tt-Trace-Tag
X-App-Server
X-Tt-Trace-Host
X-Hostname
X-NGENIX-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Fastcgi-Cache
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Varnish-Ttl
X-Page-Id
X-Pinterest-Rid
Mrf-Cache-Status
Pinterest-Generated-By
Pinterest-Version
X-B3-TraceId-Primal
MRF-Tech
X-DIS-Request-ID
Access-Control-Allow-Method
Origin-Trial
Retry-After
X-Geo-Country
X-Origin-Server
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Cambria-Cache-Control
X-ASPNET-VERSION
X-Upgrade-Enabled
X-Load-Cache
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
Akamai-GRN
MS-Author-Via
X-Template
Accept-Charset
X-Type
X-Ah-Environment
Fastly-SIE
X-Fb-Rlafr
Fastly-SWR
Viewport
X-Cache-Control
X-TT
Section-Io-Cache
X-Content-Options
X-RateLimit-Remaining
X-B
Content-MD5
X-B3-Sampled
Frame-Options
X-CLOUD-TRACE-CONTEXT
X-Xrds-Location
Version
X-Grace
X-Nf-Request-Id
X-Request-Guid
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Trace-Id
X-Revision
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Vcl-Version
Amp-Access-Control-Allow-Source-Origin
Healthy
X-Cdn
X-Amz-Meta-S3cmd-Attrs
X-Origin-Cache
X-Envoy-Decorator-Operation
TCN
X-Magnolia-Registration
X-Contextid
X-Device-Type
X-Source
X-CSRF-Token
X-Rid
X-Tec-Api-Root
X-Aspnetmvc-Version
X-Tec-Api-Version
X-Tec-Api-Origin
X-Webkit-CSP
X-WP-CF-Super-Cache-Active
Server-Name
X-Cache-Age
X-Backend-Name
X-Px
DC
X-Mobile
X-Proxy
X-Language
X-Tumblr-Pixel-1
X-RemovedCookies
X-Webkit-Csp
X-Tumblr-Pixel-0
X-Tumblr-User
X-ProcessESI
X-Tumblr-Pixel
X-App-Environment
X-Varnish-Grace
X-Buckets
X-Environment-Context
X-Seen-By
X-RM-Cache-TTL
X-Rule
X-L-Path
X-Storage
X-Status
X-Proxy-Cache-Info
X-Instance
X-Framework
X-Akamai-Edgescape
X-Region
SD-X-WS
Cross-Origin-Window-Policy
Access-Control-Request-Headers
X-UUID
X-Cacheable-TTL
X-Content-Powered-By
X-Node-Name
NGB
X-ServerID
X-G
X-FW-Server
X-Datadog-Sampled
X-Datadog-Trace-Id
X-Debug-Info
X-RTag
X-Debug-IsPreview
X-Debug-IsConnected
X-Datadog-Parent-Id
X-FW-Version
GEO-INFO
MS-CV
Ms-Operation-Id
X-Is-Bot
X-Adobe-Content
X-NYM-Debug-Backend
X-Adobe-Loc
X-HTML-Minification-Powered-By
X-Datadog-Sampling-Priority
X-FW-Dynamic
X-FW-Hash
X-Rendered-As
X-Mg-Request-UUID
X-FW-Serve
X-FW-Type
X-FW-Static
X-ECache
X-EdgeConnect-Cache-Status
Paypal-Debug-Id
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-User-Agent
X-Cache-Time
Upgrade-Insecure-Requests
Trailer
Countrycode
Webserver
Charset
Front
Protected
X-Fastly-Request-Id
X-Whom
X-WebKit-CSP-Report-Only
X-Edge-Location
OT-Force-Account-Verify
X-Lambda-Id
Refresh
X-N
X-VC
Section-Io-Id
X-HS-Prerendered
X-IPS-LoggedIn
X-VHOST
X-Cache-Status-Check
X-AB
X-Akamai-Request-ID2
Country
X-TT-LOGID
X-Reqid
X-B3-Traceid
X-Time
Priority
Backend
X-Amzn-Remapped-Content-Length
Alternate-Protocol
X-B3-SpanId
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Hl-Ver
Xet-Cookie
X-WP-CF-Super-Cache-Cookies-Bypass
Liferay-Portal
X-Server-W
X-Response-Served-From
X-Original-Request-Id
X-Via-JSL
Onion-Location
Accept-Language
X-Mode
SRV
Environment
X-Real-IP
X-Cache-Host
X-JoinUs
X-Accel-Version
X-Tumblr-Pixel-2
X-UPSTREAM-Address
X-Frame-Option
X-Auth-Group-Type
X-FB-TRIP-ID
X-Fetched-On
X-Skip-Cache
Filters
ServerID
VIX-Pulpo-Upstream-Status
X-Rn-Rsrv
Cross-Origin-Embedder-Policy-Report-Only
X-SaId
X-Rewrite-Enabled
VIX-Pulpo-Node
Meta-Geo
X-Scope-Id
Uber-Trace-Id
Webcakes-Region
X-Format
Webcakes-App-Version
X-Redis-Cache
X-Varnish-Age
Webcakes-App-Name
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-IPLB-Instance
X-Tb
X-Logging-Id
X-IPLB-Request-ID
X-Varnish-Cache-Hits
X-R9-Blue-Green-Version
X-Cache-Action
X-Restarts
X-Cache-Expired-At
TWC-Connection-Speed
X-Connection-Hash
Property-Id
Atl-Traceid
From-Origin
Expiry
X-Cluster-Node
X-VC-Cache
TWC-Device-Class
TWC-Locale-Group
X-Request-URI
TWC-Privacy
TWC-GeoIP-Country
X-Nginx-Cache
TWC-GeoIP-LatLong
X-Origin-Hint
X-Director
X-Soup
Apigw-Requestid
Mn-Server-Ip
Web-Mar-Node
X-Cms-Context
X-Handled-By
X-Hosted-By
X-Httpd
X-Loop
X-Say-TTL
X-Vcache
X-Wix-Request-Id
X-Varnish-Beresp-Grace
X-SayCDN-TTL
X-Served-From
X-Say-Cacheable
X-Tncms
X-Forwarded-Host
Fastcgi-Useragent
X-Web-Node
X-Adobe-Source
X-Origin-Date
X-Proxy-Build
X-PHP-Host
X-Labrador-Cache-Channel
Selected-Fe
X-Timing-Wait
Url
ServedBy
X-Cluster
X-Cloudmap
X-Routing-Service
X-Zipkin-Id
X-S
X-Servername
X-Webstats-RespID
X-Proxied
X-Detected-As
X-Origin-TTL
X-Generated-By
X-Origin
DB-Nickname
X-Extlb
X-Origin-CC
X-TraceId
Referer-Policy
X-LSADC-Cache
N-Cache
Xserver
X-FTR-Request-ID
X-Lagoon
X-DataDome
X-Rocket-Nginx-Serving-Static
X-XRDS-Location
X-Hit
CF-IPCountry
LB
Cross-Origin-Embedder-Policy
X-Ms-Request-Id
X-Xfnlog-Site
X-SRV
X-Ms-Version
X-DynaTrace
X-Tumblr-Pixel-3
X-NWS-UUID-VERIFY
X-XRDS-LOCATION
X-RateLimit-Limit
X-Upstream-Ct
X-RID
X-Upstream-Ht
X-Cache-Debug
X-VCT
X-Proxy-Cache-Status
X-RCS-CacheZone
X-Azure-Ref-OriginShield
Source
WPO-Cache-Status
WPO-Cache-Message
Surrogated-Key
X-UA
X-RateLimit-Remaining-Second
CDN-RequestId
X-RateLimit-Limit-Second
X-Worker
X-Is-Tablet
X-Tcp-Rtt
X-Browser-Name
X-Geo-Region
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Desktop
X-No-Session
X-Signature
X-Urbn-Context-Path
X-Urbn-Site-Id
X-B-Cache
Locale
X-F-Cache
X-Generation-Time
Node
X-Sucuri-Cache
X-App-Version
AMP-Access-Control-Allow-Source-Origin
X-Cdn-Origin
X-Drupal-Cache-Contexts
X-Sucuri-ID
X-Drupal-Cache-Tags
X-NODE
X-ShardId
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Cdn-Forward
X-Locale
X-MP-GENERATED-AT
Ohc-File-Size
Cross-Origin-Opener-Policy-Report-Only
X-Tx-Id
X-Cache-Operation
X-Site-Version
X-Cache-Rule
Content-Secure-Policy
Cluster
X-A-Dam
DCR-Decision-By
We-Hiring
X-A
X-A-Ccd
Azure-RegionName
Azure-SiteName
Candidate-Md5Url
BehaviorPad-Version
X-A-Wwc
Azure-SlotName
X-A-Dcw
Thinkindot-CacheControl-Type
X-A-Dgt
TDXMobile
Azure-InstanceId
Host-ID
Lang
A
DCR-Processing-Time-Ms
Gannett-Cam-Experience-Id
Expect-Staple
Fastly-Backend-Name
Fastly-GeoIP-CountryCode
Mail-Subject
MD5-Digest
Redirect-Candidate
Rendered-Blocks
Sslversion
X-Aed
Origin-Agent-Cluster
Odigeo-Trace-Id
Azure-Version
Meta-Geo-Continent
Ngx.Var.Host
Thinkindot-CacheControl
X-Cache-NE
X-Proxy-CacheRZ
X-Proxied-Request
X-Request-Time
X-Rojux
X-Scheme
X-Proto
X-Platform-Server
X-Origin-Expires
X-Org
X-Origin-Response-Time
X-Origin-Time
X-PAYTM-SRV-ID
X-ScT
X-Shield-Cache-Expires
X-Vtex-Remote-Cache
X-Vmg-Version
X-We-Are-Hiring
Xc-Version
XkeyRZ
X-Vdms-Version
X-Varnish-Remaining-TTL
X-Thinkindot-L3
X-TIM-N
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Nyt-Route
X-Mvc-Supplant-OutputCached
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-DefElseHash
X-DefHash
X-Developer
X-D
X-Conf
X-App-Name
X-Amz-Storage-Class
X-Backend-Instance
X-Bc-Bl
X-Cache-Info
X-Ec-Fail
X-Ec-GeoHdr
X-INCAP-ABP
X-Ig-Push-State
X-Jobs
X-Mly-Id
X-Mvc-Supplant-Cachable
X-Ig-Origin-Region
X-GeoCountry
X-Epic-Correlation-Id
X-FC-Vary-Parameters
X-Gdpr
X-GeoCode
X-Aicache-OS
X-BCube-Filmed-By
X-NGINX-Cache
X-Service
X-ElasticPress-Query
Mime-Version
X-Optimistic-Header
X-Varnish-Beresp-Ttl
X-Cache-Id
X-Cached-By
X-CacheTTL
X-Cache-Bucket
X-Bug-Bounty
X-Cache-Aspx
X-CGP
X-Cache-Grace
X-Contensis-Viewer-Groups
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Ec-Custom-Error
X-Edge-Server
X-Esi-Check
X-Depends
X-Date
X-Bl-Debug
X-Content-Age
X-Core-Value
X-Csrf-Jwt
X-Clientip
X-BBC-Edge-Cache-Status
Tube-Got-Results
Tube-Got-Eval
Tube-Return
User-Agent
V-Age
Tube-Get-Contents
Server-Host
Release
Req-Svc-Chain
RNT-Machine
RNT-Time
W
Web-Mar-Region
X-Akamai-Device-Characteristics
X-AK-Request-ID
X-Amz-Meta-Cb-Modifiedtime
X-Auto-Login
X-B3-Trace-ID
X-Acquia-Purge-Cdn-Unconfigured
X-Access
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Accel-Expires-Debug
X-Eu-Site
X-Gamma-Serve
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-UA-Device-Type
X-V-Cache
X-Var-Ttl
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Req
X-SB
X-SD-PageType
X-Section
X-Varnish-Authentication
X-Varnish-Director
X-Wikidot-Backend
X-VTEX-Cache-Time
X-Wikidot-Static-Cache
Yak-Timeinfo
Origin
X-VTEX-Cache-Server
X-Viewer-Country
X-VarnishDD-TTL
X-Varnishpool
X-VG-WebCache
X-Via-Fastly
X-Powered-By-VTEX-Cache
X-Pool
X-GoCache-CacheStatus
X-GeoIP-Region-Code
X-Gzip
X-HN
X-HS-Content-Campaign-Id
X-GeoIP-Country-Code
X-GeoIP-City
X-Fmm-Version
Product
X-Generated-On
X-GeoIP
X-Human
X-Internal-TTL
X-Op-Id-All
X-Path
X-Platform
X-Policy
X-Node-Id
X-NMSegId
X-Level-Front-Cache
X-Loc
X-Location
X-Micro-Cache
X-Fastly-Backend
X-Hash
Canary
Cache-Provider
NM-Fastcgi-Cache
HA-Ipaddr
Ha-Gx-Prefs
Cdnsip
Content-Style-Type
Gh-Request-Id
L
NGX
Debug
L5d-Success-Class
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Cache-Key
Cache
Apple-News-Services-Handled
Cdn-Host
PFcat
Cdncip
Click-Count-Error
Click-Count-Action-Start
Esi-Enabled
Cdn-Request-Time
DSUID
Content-Script-Type
Producers
TP-L2-Cache
X-Cache-Hit
Sid
X-Pad
CDN-Uid
X-Gen-Mode
X-CUA
X-NodeID
X-Content-Length
CDN-RequestPullCode
X-Cache-FS-Status
CDN-PullZone
CDN-CachedAt
X-Hnp-Log
CDN-EdgeStorageId
Fastly-SSL
CDN-RequestCountryCode
CDCHOST
X-Men
X-Bip
CDN-Cache
X-Block-Status
CDN-RequestPullSuccess
X-Request-Start
Platform
IsBot
Origin-EX
Origin-CC
User-Cache-Control
X-Cdn-Srv
X-Irp-Debug
X-AB-Test
ServerName
Ssr
X-SIPLIST1
X-Varnish-Beresp-Status
X-VG-TLSProxy
X-Server-IP
X-Sn-Servicetimems
Req-ID
X-Request-Host
Country-Code
X-Pubstack
X-Newrelic-Synthetics
X-Tb-Optimization-Total-Bytes-Saved
X-Thanos
Pramga
Akamai-Mon-Iucid-Del
X-HOST
Fl-Custom-Application
X-ORCA-Accelerator
XM
X-Dc
X-Api-Version
X-Varnish-Hits
X-CACHE-GROUP
X-Cs
X-LB-NoCache
X-VServer
X-AWS-Id
X-LiteSpeed-Tag
X-LJ-Flow-ID
X-TA-CDN-Provider
X-HS-CF-Cache-Status
True-Client-Country-4JS
X-GEO
X-VWS-Id
X-Air-Pt
C-Via
CloudFront-Viewer-Country
X-Cache-Date
X-Geolocation
X-Refresh
X-Test
X-Nananana
Proxy-Firewall
X-Provided-By
X-RequestId
Server-Hostname
Sever-Int
X-APP
Server-Ext
X-HITS
X-Litespeed-Tag
X-LiteSpeed-Cache-Control
X-Via-Edge
X-S-Cookie
X-Servedbyhost
Edge-Copy-Time
GeoIP-Latitude
Adler-Geo
Is-Eu
X-Via-CDN
X-IsAdmin
X-Via-SSL
X-Destination
X-External-Request-Id
X-Application
X-B-Cookie
X-B3-Spanid
X-Zone
X-Dispatcher-Number
X-Via-Popv
X-Via-Poph
X-Via-Popn
Fastly-Drupal-Html
X-HA-Backend
X-Nginx-Cache-Key
X-Tt-Logid
X-B3-Parentspanid
Fastly-Drupal-HTML
Cdn-Requestid
X-DC
S-Rt
X-Endurance-Cache-Level
X-ZONE
WZWS-RAY
X-LB-ID
X-Zen-Fury
X-User
X-DynaTrace-JS-Agent
Cache-Tv-Group
X-Nc
X-Wa
X-Custom-Header
X-Webkit-Csp-Report-Only
Server-ID
T-Server
X-Geo-Header
HostName
X-CDN-Forward
X-Srv
Cdn
X-Presslabs-Stats
X-COUNTRY
X-Oracle-Dms-Ecid
GeoIp-Country-Code
X-ND-Cache
X-URL
X-AIR-PT
X-Pass-Why
Ohc-Cache-HIT
X-CS
Vc-Max-Age
X-CMSURLCustom
X-VC-TTL
X-Cache-Server
X-Parent-Response-Time
X-CACHE-AGE
X-HubSpot-Correlation-Id
X-Vgn-Hpd-Reason
WP-Super-Cache
X-TH-Server
X-Datadome
SID
True-Client-IP
Resin-Trace
X-DataCenter
X-Moov-Xdn-Caching-Status
X-Moov-T
X-Moov-Xdn-Version
X-NewRelic-App-Data
X-Fpc
X-API-Version
Pics-Label
Powered-By
Vix-Hermes-Req-Id
X-Old-Content-Length
X-Varnish-Beresp-TTL
Uri
X-Ckpd-Fst-Backend
True-Client-Ip
X-Fastly-Cache
SEZNAM-JOBS-OFFER
X-Srcache-Store-Status
X-TX-ID
X-Srcache-Fetch-Status
X-APP-VERSION
On-Server
Srv
X-SERVER-NAME
X-FPC
Serverhost
X-Cache-VC
X-FTR-Backend-Server
Location
X-FTR-Backend
X-FTR-Expires
X-FTR-Balancer
ServerHost
X-FTR-Cache-Status
X-Country-Code-Real
X-Vercel-Id
X-Action
X-Thinkindot-L1
Thinkindot-Control
X-Vercel-Cache
X-Client-Ip
AKAMAI
X-PHP-Backend
GeoIP-Country-Code
X-Amz-Meta-Opti
X-Cache-TTL-Remaining
X-Air-Source
X-Dynatrace-Js-Agent
X-Air-Hostname
X-Air-Trace-Id
Server-Id
X-Stale
X-Oracle-Dms-Rid
N1-Cache
X-Litespeed-Cache-Control
Hostname
Magicmarker
X-Debug-Service
Av-Poweredby
X-Datacenter
Cl-Cache
X-Cdn-Cache-Status
X-Info
X-Resp-Is-Stale
X-PERF
X-WA
X-Fastly-Backend-Reqs
X-NC
X-Fastly-Cache-Status
X-ApacheServer
X-Vc
X-Service-Response-Time
Sm-Log-Id
X-V
Tcn
Time-Cloud-Cache
X-Ee-Origin
X-Render-Time
X-Cms-Device
X-Ee-Generated-By
X-Save-Cache
X-Lb-Id
X-Vary-Devices
X-Udemy-Cache-App-Namespace
X-WA-Info
X-Ee-Request-Id
X-Ee-Request-Date
Store-Cloud-Cache
X-VTEX-Cache-Backend-Connect-Time
X-Geo
X-Ssense-Shipping-Surcharge-Enabled
X-IAuth-Set-Uid
X-Ssense-Gql
X-CDN-Cache-Status
X-VTEX-Cache-Backend-Header-Time
Xkeylog
Xkey-La3
X-Proxy-Cache-La3
CDN
X-Cache-Ttl
X-Ha-Backend
Cache-Hits
TWC-GeoIP-City
X-Via-PopV
X-Rollout
X-Eligible
X-Ua
X-Via-PopN
X-Github-Request-Id
X-Via-PopH
TWC-GeoIP-DMA
X-Oracle-DMS-ECID
X-Correlation-ID
X-Uri
X-New
X-Nitro-Cache
TWC-GeoIP-Region
Geoip-Latitude
X-Esi
X-Ion-Hop
X-ServedByHost
Cache-Contol
RewriteTeamHook
X-Jungle-Id
RewriteTestHook
X-Region-Sid
X-VCL-Version
X-Ion-Healthy
X-Forwarded-Site
Machine
X-Limited
Log-Origin
X-App
X-Akamai-Pragma-Client-IP
Cloudfront-Viewer-Country
Cmsid
Lb
WWW-Authenticate
X-Traceid
Cmstype
WebServer
Cneonction
X-Lb-Nocache
My-App
Server-Info
CountryCode
Pragrma
X-Dw-Trace-Id
Edge-Cache
X-Requestid
Cf-Ipcountry
X-LAGOON
X-EC-Lua
X-From
X-MSEdge-Flight
X-Ftr-Request-Id
X-MSEdge-Features
X-Container-Uri
X-Up
X-Git-Commit
Reporter
X-HS-Status
X-Akamai-Transformed
X-Check-Cacheable
Permission-Policy
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-SRCache-Key
X-Serial
Warning
FSS-Cache
X-Cdn-Request-ID
X-Varnish-Hostname
X-Pod
CacheControlHeader
X-Sucuri-Id
X-BBC-Origin-Response-Status
X-Elasticpress-Query
X-Tncms-Bot-Tier
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
CF-Cached-On
X-Fastly-Cache-Hits
X-Ramcache
X-Ms-Blob-Type
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Timeexpire
PICS-Label
X-Ms-Lease-Status
X-Orig-Cache-Control