Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
Pragma
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
CF-Ray
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
X-Generator
Server-Timing
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Check
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Permissions-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
Accept-CH
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Backend
X-Hacker
X-Turbo-Charged-By
X-Cache-Group
Keep-Alive
X-Proxy-Cache
Cf-Apo-Via
X-Via
X-Rq
EagleId
Accept-CH-Lifetime
X-Server
X-Age
X-UA-Device
X-Dispatcher
X-Vhost
X-Amz-Version-Id
X-AH-Environment
X-Ws-Request-Id
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
X-Litespeed-Cache
X-Server-Powered-By
X-WebKit-CSP
Allow
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Pingback
X-Cache-Lookup
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-Page-Speed
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Device
EagleEye-TraceId
X-Backend-Server
X-Akam-SW-Version
X-Host
X-Response-Time
Surrogate-Control
X-Cloud-Trace-Context
Cf-Railgun
X-Readtime
X-Node
X-HW
X-Server-Id
Xkey
X-LiteSpeed-Cache
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Url
X-Nginx-Cache-Status
X-Application-Context
X-NWS-LOG-UUID
X-Content-Type
Cache-Tag
Content-Location
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
X-Amz-Server-Side-Encryption
Service-Worker-Allowed
X-Trace
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Times
X-Vname
X-TtlSet
X-PC
X-Edge
X-Midtier
X-Mcache
X-Rack-Cache
X-Country-Code
X-Oneagent-Js-Injection
Rating
Surrogate-Key
X-Browser-Type
X-Server-Name
X-ESI
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Cache-TTL
X-Abt-Application-Version
X-Cnection
X-Element-Page-Cache
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Build
X-Ser
Edge-Control
X-GitHub-Request-Id
X-Powered-By-Plesk
Nginx-Cache
X-D2id
Verso
X-Ac
X-Dw-Request-Base-Id
X-ARC
X-Vcap-Request-Id
X-Client-IP
Accept-Ch-Lifetime
X-MS-InvokeApp
X-ORACLE-DMS-RID
X-Aspnet-Version
X-Daa-Tunnel
X-B3-TraceId
X-Upstream
X-Navigation-Version
X-Amz-Rid
X-Goog-Hash
X-ECACHE
X-CST
X-Powered-CMS
Response
X-Middleton-Response
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-PDP-UNCACHING-HASH
X-Edge-Location-Klb
X-Server-ID
X-Kinsta-Cache
X-Ttl
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-SID
X-Ua-Device
X-Cache-Key
X-Amzn-Trace-Id
X-Ruxit-Js-Agent
X-Forwarded-For
X-NF-Request-ID
X-Ratelimit-Limit
RTSS
X-Mod-Pagespeed
X-Wormhole-Sdk
X-Ratelimit-Remaining
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
Cache-Status
AR-CACHE
X-Version
X-ORACLE-DMS-ECID
Public-Key-Pins
X-Mg-S
X-FastCGI-Cache
S
Cross-Origin-Resource-Policy
X-Ezoic-Cdn
Realpath
X-Shield-Request-Id
X-SharePointHealthScore
SPRequestGuid
X-MSEdge-Ref
Fastcgi-Cache
X-Content-Digest
X-T
X-Cached
X-Recruiting
Access-Control-Request-Method
X-Accel-Expires
X-Distributor
X-Newrelic-App-Data
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Correlation-Id
TP-Cache
Arr-Disable-Session-Affinity
Front-End-Https
Count-Hit
X-Id
X-Debug
X-Content-Security-Policy-Report-Only
Server-Node
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Ua-Browser
X-Fastly-Request-ID
MicrosoftSharePointTeamServices
X-Request-Received
X-Request-Processing-Time
X-LLID
X-VARITI-CCR
X-HS-Combine-CSS
X-Frontend
X-Azure-Ref
Cache-Tags
X-Varnish-TTL
X-Ismobilevalue
X-Cluster-Name
X-Hits
X-PressLabs-Stats
Payment
Accept-Ch
X-Varnish-Ttl
X-Amz-Replication-Status
X-LB-Cache
X-Forwarded-Proto
X-Varnish-Backend
X-GUploader-UploadID
X-Goog-Metageneration
X-Microsite
X-Request-Handler-Origin-Region
Filterid
X-Unique-Id
X-Protected-By
X-FB-Debug
X-Git-Hash
Host
X-Logged-In
Cleartype
X-Activity-Id
X-Az
X-Www-Served-By
Content-Disposition
X-Varnish-Server
X-AppVersion
X-Ratelimit-Reset
X-App-Server
X-Hostname
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-NGENIX-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-TTL
X-Fastcgi-Cache
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-DIS-Request-ID
Access-Control-Allow-Method
X-Page-Id
X-Geo-Country
Retry-After
X-Origin-Server
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Load-Cache
X-Nf-Request-Id
X-ASPNET-VERSION
X-Pinterest-Rid
X-Goog-Stored-Content-Length
X-Upgrade-Enabled
X-Goog-Stored-Content-Encoding
Pinterest-Version
X-Goog-Storage-Class
X-Goog-Generation
Pinterest-Generated-By
MS-Author-Via
Origin-Trial
Accept-Charset
X-Ah-Environment
Akamai-GRN
Fastly-SWR
Fastly-SIE
Section-Io-Cache
X-Type
Content-MD5
Viewport
X-Cambria-Cache-Control
X-Fb-Rlafr
X-TT
X-Cache-Control
X-Template
X-B3-Sampled
X-Content-Options
X-B
Version
X-Grace
Amp-Access-Control-Allow-Source-Origin
X-Request-Guid
Frame-Options
X-Revision
X-Trace-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
TCN
X-Amz-Meta-S3cmd-Attrs
X-Origin-Cache
Healthy
X-Cdn
X-Envoy-Decorator-Operation
X-Vcl-Version
X-Contextid
X-Xrds-Location
X-Magnolia-Registration
X-RateLimit-Remaining
X-Device-Type
X-ECache
X-CSRF-Token
X-Source
X-Aspnetmvc-Version
X-Webkit-CSP
X-WP-CF-Super-Cache-Active
Server-Name
DC
X-Px
X-Cache-Age
X-Backend-Name
X-Proxy
X-Seen-By
X-Mobile
X-Rid
X-Varnish-Grace
X-RM-Cache-TTL
X-ProcessESI
X-Fastly-Request-Id
X-App-Environment
X-RemovedCookies
Access-Control-Request-Headers
X-Environment-Context
X-L-Path
X-Framework
X-Debug-Info
X-Mg-Request-UUID
X-Tumblr-Pixel
X-Storage
X-Status
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Rule
X-Tumblr-User
X-FW-Version
X-FW-Type
X-FW-Serve
X-FW-Server
X-FW-Hash
X-Akamai-Edgescape
Cross-Origin-Window-Policy
NGB
SD-X-WS
X-Adobe-Loc
X-Cacheable-TTL
X-Content-Powered-By
X-G
X-HTML-Minification-Powered-By
X-Debug-IsPreview
X-Debug-IsConnected
X-FW-Dynamic
X-FW-Static
X-Adobe-Content
X-Proxy-Cache-Info
X-Node-Name
X-Region
X-ServerID
X-UUID
X-NYM-Debug-Backend
X-Datadog-Sampled
X-Datadog-Parent-Id
MS-CV
X-Datadog-Sampling-Priority
X-Instance
GEO-INFO
X-Datadog-Trace-Id
X-Yottaa-Optimizations
X-Rendered-As
Paypal-Debug-Id
X-RTag
X-Yottaa-Metrics
X-CLOUD-TRACE-CONTEXT
X-Is-Bot
Ms-Operation-Id
X-Language
X-User-Agent
X-Buckets
X-Cache-Time
X-EdgeConnect-Cache-Status
Countrycode
Webserver
Upgrade-Insecure-Requests
Front
Charset
Protected
X-WebKit-CSP-Report-Only
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Whom
OT-Force-Account-Verify
X-N
X-Lambda-Id
X-VC
Trailer
X-IPS-LoggedIn
X-Edge-Location
Section-Io-Id
X-Akamai-Request-ID2
X-Cache-Status-Check
X-VHOST
X-AB
Refresh
Country
Priority
X-Time
X-TT-LOGID
X-B3-Traceid
X-HS-Prerendered
X-Reqid
X-B3-SpanId
X-Hl-Ver
X-WP-CF-Super-Cache-Cookies-Bypass
X-Amzn-Remapped-Content-Length
Alternate-Protocol
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Via-JSL
Backend
Xet-Cookie
Liferay-Portal
Accept-Language
X-Wix-Request-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Server-W
X-DataDome
X-Mode
X-Fetched-On
X-FB-TRIP-ID
X-JoinUs
Meta-Geo
X-Web-Node
X-Rn-Rsrv
X-Frame-Option
X-SaId
Onion-Location
Fastcgi-Useragent
Filters
From-Origin
Uber-Trace-Id
X-Accel-Version
X-Cache-Host
X-Generated-By
X-Tb
X-Auth-Group-Type
Environment
X-Scope-Id
X-Origin-Date
X-Request-URI
X-Skip-Cache
X-Rewrite-Enabled
X-UPSTREAM-Address
X-VC-Cache
X-Say-Cacheable
X-R9-Blue-Green-Version
X-Cluster-Node
X-ProxyCache-Status
X-Tumblr-Pixel-2
Webcakes-App-Name
Webcakes-App-Version
X-Cache-Action
X-BYPASS-REASON
X-ProxyCache-Key
Webcakes-Region
X-Cache-Expired-At
TWC-Locale-Group
Atl-Traceid
Apigw-Requestid
ServerID
Expiry
X-Origin-Hint
Property-Id
X-Real-IP
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Say-TTL
TWC-GeoIP-Country
X-Nginx-Cache
TWC-Device-Class
TWC-Privacy
X-Redis-Cache
X-Webstats-RespID
X-XRDS-LOCATION
X-Varnish-Beresp-Grace
X-Director
X-Logging-Id
X-Hosted-By
X-SayCDN-TTL
X-Connection-Hash
X-Forwarded-Host
X-Format
Mn-Server-Ip
X-Tncms
X-IPLB-Request-ID
LB
X-Labrador-Cache-Channel
X-Vcache
Web-Mar-Node
X-Varnish-Cache-Hits
X-Restarts
X-PHP-Host
X-Loop
X-Httpd
X-Cms-Context
X-Original-Request-Id
X-Response-Served-From
X-Varnish-Age
X-Adobe-Source
X-Soup
X-IPLB-Instance
X-Served-From
X-Handled-By
X-Proxy-Build
SRV
ServedBy
Selected-Fe
X-Timing-Wait
X-Cloudmap
X-Cluster
X-Servername
X-Proxied
X-Detected-As
DB-Nickname
X-Origin
X-Extlb
X-Routing-Service
X-S
X-Zipkin-Id
Url
Referer-Policy
X-Origin-CC
X-Origin-TTL
Xserver
Cross-Origin-Embedder-Policy-Report-Only
X-LSADC-Cache
N-Cache
X-RID
CF-IPCountry
X-XRDS-Location
X-Lagoon
X-Rocket-Nginx-Serving-Static
X-Hit
X-Webkit-Csp
X-Xfnlog-Site
X-Upstream-Ht
X-UA
X-SRV
Cross-Origin-Embedder-Policy
X-Upstream-Ct
X-NWS-UUID-VERIFY
X-Ms-Version
X-Ms-Request-Id
X-TraceId
X-DynaTrace
X-Cache-Debug
X-VCT
X-Tumblr-Pixel-3
Source
X-RCS-CacheZone
X-Proxy-Cache-Status
X-Azure-Ref-OriginShield
CDN-RequestId
WPO-Cache-Message
Surrogated-Key
WPO-Cache-Status
X-Geo-Region
X-Is-Mobile
X-Is-Desktop
X-Is-Supported-Browser
X-Tcp-Rtt
X-Is-Tablet
X-Browser-Name
X-Worker
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-No-Session
X-B-Cache
X-F-Cache
X-Signature
Node
X-Sucuri-Cache
X-FTR-Request-ID
X-Cdn-Origin
X-RateLimit-Limit
X-Generation-Time
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShardId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-ShopId
X-NODE
X-Tx-Id
X-Drupal-Cache-Tags
X-Sucuri-ID
X-Drupal-Cache-Contexts
X-Locale
X-App-Version
X-Cdn-Forward
TP-L2-Cache
X-Site-Version
X-Service
X-Optimistic-Header
X-Cache-Operation
X-Cache-Rule
A
X-GeoIP-City
X-Jobs
X-GeoCountry
X-Epic-Correlation-Id
Azure-InstanceId
Azure-RegionName
X-GeoCode
X-Ig-Origin-Region
X-GeoIP
Candidate-Md5Url
X-MP-GENERATED-AT
X-Internal-TTL
X-INCAP-ABP
Azure-SlotName
X-Amz-Storage-Class
Azure-SiteName
BehaviorPad-Version
Azure-Version
X-FC-Vary-Parameters
X-Debug-Cache-Fetch
TDXMobile
X-Bug-Bounty
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-BCube-Filmed-By
Sslversion
X-Cache-Aspx
Redirect-Candidate
Producers
Rendered-Blocks
X-Cache-NE
X-Cache-Info
X-Bc-Bl
X-Backend-Instance
X-Aed
X-A-Wwc
X-Aicache-OS
X-AK-Request-ID
X-App-Name
X-A-Dgt
X-A-Dcw
We-Hiring
X-A
X-A-Ccd
X-A-Dam
X-Conf
X-Contensis-Viewer-Groups
Fastly-Backend-Name
Expect-Staple
Fastly-GeoIP-CountryCode
X-Developer
Gannett-Cam-Experience-Id
X-DPWN-IS-SECURE
DCR-Processing-Time-Ms
X-Ec-GeoHdr
Cdnsip
X-Ec-Fail
Content-Secure-Policy
DCR-Decision-By
X-Depends
X-DefHash
Meta-Geo-Continent
MD5-Digest
Ngx.Var.Host
Odigeo-Trace-Id
Origin-Agent-Cluster
Mail-Subject
X-D
X-DefElseHash
Host-ID
X-Debug-Cache-Store
Lang
Cdncip
X-Ig-Push-State
X-Varnish-Authentication
X-Platform-Server
X-Viewer-Country
X-Scheme
X-ScT
X-Vmg-Version
X-Origin-Expires
X-Origin-Response-Time
X-NGINX-Cache
X-PAYTM-SRV-ID
X-Proto
X-Rojux
X-Varnish-CookieINHashed-On
X-Request-Time
X-Varnish-Remaining-TTL
X-Varnish-Director
AMP-Access-Control-Allow-Source-Origin
X-Vdms-Version
X-Varnish-CookieHashed-On
X-Proxied-Request
X-VG-WebCache
X-Proxy-CacheRZ
X-Org
X-Path
X-Mly-Id
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-ElasticPress-Query
XkeyRZ
X-Loc
X-Thinkindot-L3
Xc-Version
X-TIM-N
X-We-Are-Hiring
X-Vtex-Remote-Cache
X-Shield-Cache-Expires
Mime-Version
Ohc-File-Size
X-Varnish-Beresp-Ttl
Cache
X-CGP
Origin-CC
X-V-Cache
X-Core-Value
NGX
Req-Svc-Chain
PFcat
X-CacheTTL
Origin
X-Cached-By
X-Var-Ttl
X-Clientip
Product
Origin-EX
X-Varnish-Beresp-Status
X-Content-Age
Platform
Release
X-UA-Device-Type
X-Csrf-Jwt
NM-Fastcgi-Cache
X-Bl-Debug
Wxu-Next-Hostname
Wxu-Next-Region
X-VTEX-Cache-Time
Wxu-Next-Commit
Web-Mar-Region
W
X-VTEX-Cache-Server
Cross-Origin-Opener-Policy-Report-Only
X-Wikidot-Backend
X-Akamai-Device-Characteristics
Yak-Timeinfo
X-Acquia-Purge-Cdn-Unconfigured
X-Access
X-Wikidot-Static-Cache
X-Accel-Expires-Debug
X-B3-Trace-ID
V-Age
X-Varnishpool
X-VG-TLSProxy
X-VarnishDD-TTL
X-Cache-Bucket
X-Cache-Id
X-Cache-Grace
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Fastly
User-Agent
X-BBC-Edge-Cache-Status
Tube-Return
Tube-Got-Results
Tube-Get-Contents
Tube-Got-Eval
Server-Host
X-Slack-Backend
X-Policy
X-Pool
X-Powered-By-VTEX-Cache
X-Platform
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Cache-Key
Cache-Provider
Cdn-Host
Cdn-Request-Time
X-Eu-Site
X-Fmm-Version
X-Gamma-Serve
Canary
X-Gdpr
Apple-News-Services-Handled
X-Generated-On
X-HS-Content-Campaign-Id
X-Nyt-Route
X-HN
X-Human
X-Node-Id
X-Micro-Cache
X-NMSegId
X-Hash
X-Pad
X-GeoIP-Country-Code
X-Origin-Time
X-GeoIP-Region-Code
X-GoCache-CacheStatus
X-Op-Id-All
X-Gzip
X-Esi-Check
X-Fastly-Backend
X-Pubstack
X-Section
Ha-Gx-Prefs
Esi-Enabled
X-Dispatcher-Server
Debug
DSUID
HA-Ipaddr
X-Level-Front-Cache
L5d-Success-Class
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
L
X-Date
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-SB
X-SD-PageType
X-Ec-Custom-Error
X-Req
X-Edge-Server
Click-Count-Error
Click-Count-Action-Start
Content-Style-Type
Content-Script-Type
Cluster
X-LiteSpeed-Tag
X-Location
X-Gen-Mode
X-NodeID
XM
X-Thanos
X-Men
X-CUA
X-Cache-FS-Status
X-Block-Status
X-SIPLIST1
X-Content-Length
X-Server-IP
X-Auto-Login
X-Cdn-Srv
X-Request-Host
X-Bip
X-Request-Start
X-Hnp-Log
X-Amz-Meta-Cb-Modifiedtime
Fastly-SSL
Country-Code
CDN-Uid
Gh-Request-Id
IsBot
RNT-Machine
Req-ID
Pramga
CDN-RequestPullSuccess
CDN-RequestPullCode
CDCHOST
X-Api-Version
Sid
CDN-Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-PullZone
RNT-Time
CDN-EdgeStorageId
User-Cache-Control
ServerName
Ssr
X-LiteSpeed-Cache-Control
X-Cache-Hit
X-Air-Pt
X-AB-Test
X-Irp-Debug
X-HOST
X-LJ-Flow-ID
X-AWS-Id
Akamai-Mon-Iucid-Del
X-Newrelic-Synthetics
X-VWS-Id
X-Dc
X-Varnish-Hits
X-CACHE-GROUP
True-Client-Country-4JS
Fl-Custom-Application
X-ORCA-Accelerator
X-Provided-By
X-Cs
X-GEO
X-RequestId
C-Via
Server-Ext
X-TA-CDN-Provider
X-Test
Sever-Int
GeoIP-Latitude
Server-Hostname
X-Nananana
Proxy-Firewall
X-VServer
Adler-Geo
X-HITS
Is-Eu
CloudFront-Viewer-Country
X-Servedbyhost
X-LB-NoCache
Fastly-Drupal-HTML
X-Presslabs-Stats
Edge-Copy-Time
X-Dispatcher-Number
X-Via-CDN
X-Cache-Date
X-Geolocation
X-Via-Edge
X-B3-Parentspanid
X-Nginx-Cache-Key
S-Rt
X-DC
X-HS-CF-Cache-Status
X-Via-SSL
X-Refresh
X-APP
X-B3-Spanid
WZWS-RAY
X-Tt-Logid
X-Via-Popn
X-S-Cookie
X-B-Cookie
X-External-Request-Id
X-IsAdmin
X-Destination
X-HA-Backend
Cache-Tv-Group
X-Application
X-Zone
X-Via-Poph
X-Via-Popv
Cdn-Requestid
X-Endurance-Cache-Level
X-ZONE
X-Geo-Header
X-Wa
T-Server
Fastly-Drupal-Html
X-Zen-Fury
X-Nc
X-LB-ID
X-Custom-Header
X-Pass-Why
X-DynaTrace-JS-Agent
Server-ID
HostName
X-ND-Cache
X-User
X-Webkit-Csp-Report-Only
X-Litespeed-Tag
X-CDN-Forward
Cdn
X-Cache-Server
X-COUNTRY
X-URL
X-CMSURLCustom
X-Oracle-Dms-Ecid
X-Srv
Vc-Max-Age
X-CS
GeoIp-Country-Code
X-CACHE-AGE
X-AIR-PT
X-Parent-Response-Time
Ohc-Cache-HIT
X-Fpc
X-HubSpot-Correlation-Id
SID
X-VC-TTL
X-Moov-Xdn-Caching-Status
X-Moov-T
X-Vgn-Hpd-Reason
Vix-Hermes-Req-Id
Powered-By
WP-Super-Cache
Resin-Trace
True-Client-IP
X-DataCenter
X-TH-Server
X-Moov-Xdn-Version
X-NewRelic-App-Data
Uri
X-Fastly-Cache
X-Ckpd-Fst-Backend
Pics-Label
Srv
X-Varnish-Beresp-TTL
X-APP-VERSION
SEZNAM-JOBS-OFFER
X-Old-Content-Length
True-Client-Ip
On-Server
X-Srcache-Fetch-Status
X-API-Version
X-Srcache-Store-Status
ServerHost
Thinkindot-Control
X-SERVER-NAME
X-Vercel-Id
GeoIP-Country-Code
X-TX-ID
X-Vercel-Cache
X-PHP-Backend
X-Amz-Meta-Opti
Serverhost
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
AKAMAI
X-Cache-TTL-Remaining
X-FPC
X-Datadome
X-Client-Ip
X-Thinkindot-L1
Location
X-Action
X-Cache-VC
X-Dynatrace-Js-Agent
X-Oracle-Dms-Rid
Magicmarker
X-Info
Cl-Cache
Server-Id
X-Cdn-Cache-Status
X-Stale
Av-Poweredby
X-V
X-Debug-Service
Hostname
N1-Cache
X-CDN-Cache-Status
X-FTR-Expires
X-Datacenter
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-IAuth-Set-Uid
X-FTR-Backend-Server
X-WA
X-NC
X-FTR-Cache-Status
X-VCL-Version
X-Service-Response-Time
X-Vc
Sm-Log-Id
CDN
X-Ee-Generated-By
X-Cms-Device
Time-Cloud-Cache
X-Lb-Id
X-Ee-Request-Date
X-ApacheServer
X-Ee-Request-Id
X-Vary-Devices
X-Udemy-Cache-App-Namespace
Store-Cloud-Cache
X-Save-Cache
X-PERF
X-Fastly-Cache-Status
X-Ee-Origin
X-Geo
X-New
X-Rollout
X-Eligible
X-VTEX-Cache-Backend-Header-Time
X-VTEX-Cache-Backend-Connect-Time
X-Cache-Ttl
X-Limited
X-WA-Info
X-Proxy-Cache-La3
Xkey-La3
X-Nitro-Cache
X-Resp-Is-Stale
X-Forwarded-Site
X-App
X-Ssense-Shipping-Surcharge-Enabled
X-Ssense-Gql
Xkeylog
X-Via-PopN
Machine
X-Via-PopV
X-Render-Time
X-Oracle-DMS-ECID
X-Via-PopH
X-Fastly-Backend-Reqs
X-Github-Request-Id
X-Ha-Backend
X-Region-Sid
Server-Info
X-Litespeed-Cache-Control
Cloudfront-Viewer-Country
X-Uri
Tcn
X-ServedByHost
X-Lb-Nocache
TWC-GeoIP-Region
TWC-GeoIP-DMA
X-Container-Uri
Cache-Hits
X-Git-Commit
TWC-GeoIP-City
X-Akamai-Pragma-Client-IP
X-Traceid
X-Ftr-Request-Id
WebServer
WWW-Authenticate
X-EC-Lua
Cneonction
X-MSEdge-Flight
X-MSEdge-Features
Log-Origin
Edge-Cache
Geoip-Latitude
CountryCode
X-Correlation-ID
X-LAGOON
X-SRCache-Key
Pragrma
X-HS-Status
X-Dw-Trace-Id
Cache-Contol
X-Ion-Healthy
X-Ion-Hop
X-Jungle-Id
My-App
X-Varnish-Hostname
RewriteTestHook
Cmsid
RewriteTeamHook
Cmstype
Permission-Policy
X-Acquia-Application-Trace
Reporter
X-From
X-Up
X-Acquia-Application-UUID
X-Requestid
PICS-Label
X-Cdn-Request-ID
X-Acquia-Site
X-Acquia-Purge-Tags
X-Pod
X-Akamai-Transformed
X-Serial
X-Ua
FSS-Cache
X-Check-Cacheable
X-Sucuri-Id
Cf-Ipcountry
X-Ramcache
X-Elasticpress-Query
X-Ms-Lease-Status
CacheControlHeader
X-Ms-Blob-Type
X-BBC-Origin-Response-Status
X-Tncms-Bot-Tier
X-Platform-Router
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Fastly-Cache-Hits
CF-Cached-On
X-Orig-Cache-Control
X-Platform-Cluster
NtCoent-Length
Timeexpire
Warning
X-Platform-Processor
X-Web-Server