Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
Pragma
CF-RAY
X-Powered-By
X-Cache
X-XSS-Protection
Via
Age
Content-Security-Policy
Report-To
Alt-Svc
NEL
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Varnish
CF-Ray
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-AspNet-Version
P3p
X-Drupal-Cache
X-Generator
Server-Timing
X-Cache-Status
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
X-Check
Permissions-Policy
X-Content-Security-Policy
Access-Control-Expose-Headers
Feature-Policy
Upgrade
Content-Encoding
Status
X-Ua-Compatible
X-CDN
X-AspNetMvc-Version
Access-Control-Max-Age
Host-Header
Cf-Edge-Cache
X-Robots-Tag
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
Accept-CH
X-Backend
X-Hacker
X-Turbo-Charged-By
X-Cache-Group
Cf-Apo-Via
X-Proxy-Cache
Keep-Alive
X-Via
X-Rq
EagleId
X-Server
X-Age
X-Dispatcher
X-UA-Device
X-Dns-Prefetch-Control
X-Vhost
X-Amz-Version-Id
X-AH-Environment
Accept-CH-Lifetime
X-Ws-Request-Id
X-Varnish-Cache
Grace
X-Server-Powered-By
X-Litespeed-Cache
X-WebKit-CSP
Allow
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Cache-Lookup
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-Page-Speed
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Device
X-Backend-Server
EagleEye-TraceId
X-Akam-SW-Version
X-Cloud-Trace-Context
X-Host
X-Response-Time
Surrogate-Control
Cf-Railgun
X-Readtime
X-Node
X-HW
X-LiteSpeed-Cache
X-Server-Id
Xkey
Request-Id
X-Ruxit-JS-Agent
X-Country
X-Url
X-Nginx-Cache-Status
X-NWS-LOG-UUID
X-Application-Context
X-Content-Type
Cache-Tag
Content-Location
X-Nginx-Upstream-Cache-Status
X-Clacks-Overhead
Service-Worker-Allowed
X-Trace
X-Amz-Server-Side-Encryption
Fastly-Restarts
Cross-Origin-Opener-Policy
X-Times
X-PC
X-TtlSet
X-Vname
X-Rack-Cache
X-Midtier
X-Mcache
X-Edge
X-Country-Code
X-Oneagent-Js-Injection
Rating
Surrogate-Key
X-Server-Name
X-Browser-Type
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Cache-TTL
X-Cnection
X-Abt-Application-Version
X-Element-Page-Cache
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-ESI
X-Ser
Nginx-Cache
X-Powered-By-Plesk
Edge-Control
X-GitHub-Request-Id
X-D2id
Verso
X-Ac
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-ARC
Accept-Ch-Lifetime
X-Client-IP
X-MS-InvokeApp
X-ECACHE
X-Aspnet-Version
X-ORACLE-DMS-RID
X-Daa-Tunnel
X-CST
X-Navigation-Version
X-Amz-Rid
X-Goog-Hash
X-Upstream
X-Powered-CMS
X-Middleton-Response
Response
X-Erf-Bev-Bev
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-PDP-UNCACHING-HASH
X-Erf-Bev-Bev-Is-Generated
X-Edge-Location-Klb
X-Kinsta-Cache
X-Server-ID
X-B3-TraceId
X-Ua-Device
AR-ATIME
AR-Request-ID
AR-SID
AR-PoweredBy
X-Cache-Key
X-Amzn-Trace-Id
X-Forwarded-For
X-Ruxit-Js-Agent
X-Ttl
X-Ratelimit-Limit
X-NF-Request-ID
X-Wormhole-Sdk
RTSS
X-Mod-Pagespeed
X-Ratelimit-Remaining
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
Cache-Status
X-Version
X-ORACLE-DMS-ECID
Public-Key-Pins
AR-CACHE
X-Mg-S
X-Ezoic-Cdn
Cross-Origin-Resource-Policy
S
Realpath
SPRequestGuid
X-FastCGI-Cache
X-SharePointHealthScore
X-Shield-Request-Id
X-MSEdge-Ref
X-Content-Digest
Fastcgi-Cache
X-T
X-Cached
X-Recruiting
X-Accel-Expires
Access-Control-Request-Method
X-Distributor
X-Fastly-Request-ID
X-Newrelic-App-Data
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Front-End-Https
TP-Cache
X-Correlation-Id
Arr-Disable-Session-Affinity
Count-Hit
X-Debug
X-Request-Received
X-Request-Processing-Time
X-HS-Hub-Id
X-HS-Content-Id
X-Id
X-HS-Cache-Config
MicrosoftSharePointTeamServices
X-Varnish-TTL
Server-Node
X-Content-Security-Policy-Report-Only
X-Ua-Browser
X-Azure-Ref
X-LLID
X-VARITI-CCR
X-HS-Combine-CSS
X-Frontend
X-PressLabs-Stats
Cache-Tags
X-Cluster-Name
X-Ismobilevalue
X-Hits
Payment
Accept-Ch
X-Amz-Replication-Status
X-LB-Cache
X-GUploader-UploadID
X-Varnish-Backend
X-Forwarded-Proto
X-Goog-Metageneration
X-Fastcgi-Cache
X-TTL
X-Request-Handler-Origin-Region
X-Microsite
X-Protected-By
X-Git-Hash
Host
Filterid
X-FB-Debug
Cleartype
X-Logged-In
X-Unique-Id
Content-Disposition
X-Activity-Id
X-Www-Served-By
X-AppVersion
X-Az
X-Varnish-Server
X-Ratelimit-Reset
X-Varnish-Ttl
X-Tt-Trace-Host
X-App-Server
X-Tt-Trace-Tag
X-Hostname
X-NGENIX-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
Origin-Trial
X-Page-Id
X-DIS-Request-ID
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Geo-Country
Access-Control-Allow-Method
Retry-After
X-Nf-Request-Id
X-Origin-Server
X-Load-Cache
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-ASPNET-VERSION
X-Cambria-Cache-Control
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Upgrade-Enabled
X-Goog-Stored-Content-Length
Akamai-GRN
X-Template
MS-Author-Via
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Accept-Charset
Fastly-SWR
Section-Io-Cache
Fastly-SIE
X-Type
X-Ah-Environment
X-TT
X-Fb-Rlafr
Viewport
X-Cache-Control
X-Content-Options
X-B3-Sampled
X-B
Version
X-Grace
Content-MD5
Amp-Access-Control-Allow-Source-Origin
X-Xrds-Location
Frame-Options
X-Request-Guid
X-Revision
X-Trace-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cdn
X-Amz-Meta-S3cmd-Attrs
Healthy
X-Envoy-Decorator-Operation
TCN
X-Magnolia-Registration
X-RateLimit-Remaining
X-Origin-Cache
X-Device-Type
X-Contextid
X-Vcl-Version
X-Source
X-CSRF-Token
X-Aspnetmvc-Version
X-Rid
X-Webkit-CSP
X-WP-CF-Super-Cache-Active
X-Cache-Age
Server-Name
X-Px
X-Backend-Name
X-Mobile
DC
X-Proxy
X-Language
X-App-Environment
X-Varnish-Grace
X-Buckets
X-RemovedCookies
X-Tumblr-User
X-Seen-By
X-ProcessESI
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-RM-Cache-TTL
X-Tumblr-Pixel
X-Framework
X-Rule
X-Environment-Context
X-Status
X-Debug-Info
X-Akamai-Edgescape
X-L-Path
X-Mg-Request-UUID
X-Storage
Access-Control-Request-Headers
X-Adobe-Loc
X-Region
X-Proxy-Cache-Info
X-UUID
X-Cacheable-TTL
X-Content-Powered-By
X-HTML-Minification-Powered-By
X-NYM-Debug-Backend
X-Node-Name
X-ServerID
X-G
X-Instance
X-Adobe-Content
X-Debug-IsPreview
X-Debug-IsConnected
SD-X-WS
Cross-Origin-Window-Policy
NGB
Ms-Operation-Id
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
GEO-INFO
X-Datadog-Sampled
MS-CV
X-FW-Version
X-Tec-Api-Version
X-RTag
X-Is-Bot
X-Tec-Api-Origin
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-FW-Hash
X-FW-Server
X-Rendered-As
X-FW-Serve
X-Tec-Api-Root
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-ECache
Paypal-Debug-Id
X-EdgeConnect-Cache-Status
X-User-Agent
X-Cache-Time
Upgrade-Insecure-Requests
Countrycode
Webserver
X-B3-Traceid
Trailer
Charset
Front
Protected
X-Fastly-Request-Id
X-Whom
X-WebKit-CSP-Report-Only
OT-Force-Account-Verify
X-Edge-Location
X-Lambda-Id
X-VC
Refresh
X-N
Section-Io-Id
X-VHOST
X-IPS-LoggedIn
X-HS-Prerendered
X-Cache-Status-Check
X-Akamai-Request-ID2
X-AB
Country
Priority
X-TT-LOGID
X-Time
X-Reqid
X-Amzn-Remapped-Content-Length
Backend
Alternate-Protocol
X-B3-SpanId
Xet-Cookie
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Hl-Ver
X-WP-CF-Super-Cache-Cookies-Bypass
Liferay-Portal
X-Server-W
X-CLOUD-TRACE-CONTEXT
X-Original-Request-Id
X-Response-Served-From
Accept-Language
X-Via-JSL
Onion-Location
X-Mode
SRV
X-Frame-Option
X-Origin-Date
X-UPSTREAM-Address
X-Web-Node
X-Real-IP
X-VC-Cache
X-Tumblr-Pixel-2
X-Skip-Cache
X-JoinUs
X-Wix-Request-Id
X-Fetched-On
Meta-Geo
X-Cache-Host
Environment
X-FB-TRIP-ID
X-Tb
From-Origin
ServerID
Cross-Origin-Embedder-Policy-Report-Only
Fastcgi-Useragent
VIX-Pulpo-Upstream-Status
X-Rn-Rsrv
Filters
X-Scope-Id
X-Rewrite-Enabled
X-Auth-Group-Type
X-Accel-Version
X-SaId
VIX-Pulpo-Node
X-R9-Blue-Green-Version
X-SayCDN-TTL
X-Restarts
X-Varnish-Age
X-Request-URI
X-Say-TTL
X-Redis-Cache
X-Say-Cacheable
X-IPLB-Instance
Webcakes-App-Version
Webcakes-App-Name
Expiry
Webcakes-Region
Atl-Traceid
X-BYPASS-REASON
Uber-Trace-Id
TWC-Privacy
TWC-Device-Class
Property-Id
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Cache-Action
X-Cache-Expired-At
X-Origin-Hint
X-Logging-Id
X-ProxyCache-Key
X-ProxyCache-Status
X-Webstats-RespID
X-IPLB-Request-ID
X-Hosted-By
X-Connection-Hash
X-Cluster-Node
X-Director
X-Format
X-Generated-By
X-Varnish-Cache-Hits
TWC-Connection-Speed
X-Nginx-Cache
X-DataDome
Web-Mar-Node
Mn-Server-Ip
X-Tncms
X-Varnish-Beresp-Grace
Apigw-Requestid
X-Soup
X-PHP-Host
X-Cms-Context
X-Handled-By
X-Forwarded-Host
X-Httpd
X-Labrador-Cache-Channel
X-Adobe-Source
X-Loop
X-Vcache
X-Served-From
X-Proxy-Build
DB-Nickname
X-Timing-Wait
Selected-Fe
X-S
X-Origin
X-Proxied
Url
X-Extlb
X-Routing-Service
X-Cloudmap
X-Zipkin-Id
X-Servername
ServedBy
X-Origin-CC
X-Detected-As
X-Cluster
X-Origin-TTL
Referer-Policy
LB
X-LSADC-Cache
Xserver
N-Cache
X-Lagoon
X-Rocket-Nginx-Serving-Static
X-TraceId
X-XRDS-Location
X-Hit
CF-IPCountry
Cross-Origin-Embedder-Policy
X-Webkit-Csp
X-FTR-Request-ID
X-DynaTrace
X-Xfnlog-Site
X-Ms-Version
X-SRV
X-Ms-Request-Id
X-XRDS-LOCATION
X-Tumblr-Pixel-3
X-NWS-UUID-VERIFY
X-UA
X-RID
X-Upstream-Ht
X-Upstream-Ct
X-Cache-Debug
X-Azure-Ref-OriginShield
Source
X-VCT
WPO-Cache-Status
X-RCS-CacheZone
X-Proxy-Cache-Status
WPO-Cache-Message
Surrogated-Key
X-RateLimit-Remaining-Second
CDN-RequestId
X-Worker
X-RateLimit-Limit-Second
X-Tcp-Rtt
X-Geo-Region
X-Is-Tablet
X-Browser-Name
X-Is-Supported-Browser
X-Is-Mobile
X-Is-Desktop
X-Urbn-Context-Path
X-No-Session
X-Urbn-Site-Id
X-F-Cache
X-Signature
X-B-Cache
Locale
X-Sucuri-Cache
Node
X-Generation-Time
X-Cdn-Origin
X-App-Version
X-RateLimit-Limit
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-NODE
X-Sucuri-ID
X-Alternate-Cache-Key
X-ShopId
X-Storefront-Renderer-Rendered
X-Tx-Id
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Cdn-Forward
X-Locale
X-MP-GENERATED-AT
Cross-Origin-Opener-Policy-Report-Only
Ohc-File-Size
X-Cache-Rule
X-Cache-Operation
X-Site-Version
X-BCube-Filmed-By
X-ElasticPress-Query
X-GeoCode
X-Bc-Bl
X-Backend-Instance
Azure-SlotName
X-Aed
Azure-Version
BehaviorPad-Version
X-Cache-NE
X-Gdpr
Candidate-Md5Url
Fastly-Backend-Name
Expect-Staple
X-Service
X-Bug-Bounty
X-A-Dgt
Fastly-GeoIP-CountryCode
X-A-Wwc
X-Cache-Info
X-GeoIP
X-GeoCountry
X-GeoIP-City
X-We-Are-Hiring
X-Vtex-Remote-Cache
Azure-SiteName
Azure-RegionName
X-App-Name
X-Ec-Fail
A
X-Ec-GeoHdr
X-Epic-Correlation-Id
Content-Secure-Policy
X-Debug-Cache-Fetch
X-DPWN-IS-SECURE
X-Developer
X-Amz-Storage-Class
X-DefElseHash
X-Debug-Cache-Store
Cluster
X-AK-Request-ID
Gannett-Cam-Experience-Id
Cdncip
X-FC-Vary-Parameters
X-Conf
DCR-Processing-Time-Ms
Azure-InstanceId
Cdnsip
X-D
X-Aicache-OS
XkeyRZ
Xc-Version
DCR-Decision-By
X-Proxied-Request
X-DefHash
X-A-Dam
X-Rojux
X-TIM-N
X-Vmg-Version
X-Nyt-Route
X-Thinkindot-L3
Odigeo-Trace-Id
Ngx.Var.Host
X-Request-Time
MD5-Digest
Mail-Subject
X-Mvc-Supplant-Cachable
Meta-Geo-Continent
X-Mvc-Supplant-OutputCached
X-PAYTM-SRV-ID
Origin-Agent-Cluster
X-Shield-Cache-Expires
X-Origin-Response-Time
TDXMobile
X-NGINX-Cache
X-Scheme
Sslversion
AMP-Access-Control-Allow-Source-Origin
Thinkindot-CacheControl
X-Path
X-Org
X-Origin-Expires
X-Origin-Time
Thinkindot-CacheControl-Type
X-ScT
X-Varnish-CookieHashed-On
X-Proxy-CacheRZ
Rendered-Blocks
X-Mly-Id
X-A
X-Ig-Push-State
Redirect-Candidate
Host-ID
X-Ig-Origin-Region
X-Vdms-Version
X-Jobs
X-Internal-TTL
X-Loc
X-Proto
X-Varnish-CookieINHashed-On
Producers
X-A-Dcw
X-A-Ccd
Lang
We-Hiring
X-Varnish-Remaining-TTL
X-Platform-Server
X-Varnish-Beresp-Ttl
X-Optimistic-Header
Mime-Version
X-Bl-Debug
Server-Host
RNT-Time
X-BBC-Edge-Cache-Status
RNT-Machine
Req-Svc-Chain
Tube-Return
Web-Mar-Region
X-Access
X-Acquia-Purge-Cdn-Unconfigured
Wxu-Next-Commit
Wxu-Next-Hostname
X-Cache-Aspx
Wxu-Next-Region
X-Accel-Expires-Debug
W
Origin
Tube-Got-Eval
Tube-Get-Contents
X-Auto-Login
Tube-Got-Results
X-Amz-Meta-Cb-Modifiedtime
User-Agent
X-Akamai-Device-Characteristics
X-B3-Trace-ID
X-Fastly-Backend
X-Varnish-Authentication
X-Micro-Cache
X-Location
X-Var-Ttl
X-V-Cache
X-NMSegId
X-UA-Device-Type
X-Varnish-Director
X-VarnishDD-TTL
X-VG-WebCache
X-Via-Fastly
X-Human
X-INCAP-ABP
X-Level-Front-Cache
X-Varnishpool
X-Node-Id
X-Op-Id-All
X-Platform
X-SB
X-Req
X-Policy
X-Powered-By-VTEX-Cache
X-Pool
X-SD-PageType
X-Section
X-SVT-ORM-VERSION
X-Tb-Optimization-Total-Bytes-Saved
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-HS-Content-Campaign-Id
X-Viewer-Country
X-Date
X-Csrf-Jwt
X-Core-Value
X-Depends
X-Dispatcher-Server
X-Edge-Server
X-Ec-Custom-Error
X-Content-Age
X-Contensis-Viewer-Groups
X-Cache-Id
X-Cache-Grace
X-Cached-By
X-CacheTTL
X-Clientip
X-CGP
Yak-Timeinfo
X-Esi-Check
X-Gzip
X-GoCache-CacheStatus
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-HN
X-Hash
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Wikidot-Static-Cache
X-Eu-Site
X-Fmm-Version
X-Gamma-Serve
X-Generated-On
X-Wikidot-Backend
X-Cache-Bucket
V-Age
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Content-Script-Type
Content-Style-Type
Cache
NGX
Click-Count-Error
NM-Fastcgi-Cache
Cache-Key
L5d-Success-Class
L
DSUID
Apple-News-Services-Handled
Apple-News-Services-Host
Esi-Enabled
Gh-Request-Id
Ha-Gx-Prefs
X-Pad
HA-Ipaddr
Debug
Origin-CC
Origin-EX
Product
Platform
Cdn-Request-Time
Cdn-Host
PFcat
Release
Canary
Cache-Provider
Click-Count-Action-Start
TP-L2-Cache
CDN-EdgeStorageId
X-Cache-FS-Status
CDN-PullZone
CDN-Cache
CDN-CachedAt
X-Bip
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
CDN-RequestCountryCode
Country-Code
X-Content-Length
X-Block-Status
X-Gen-Mode
ServerName
X-Server-IP
X-LiteSpeed-Tag
Ssr
X-Request-Start
X-Newrelic-Synthetics
X-Thanos
X-VG-TLSProxy
Req-ID
Pramga
Sid
X-Varnish-Beresp-Status
X-Request-Host
X-Pubstack
X-Hnp-Log
X-AB-Test
CDCHOST
X-Cache-Hit
X-CUA
X-Men
X-SIPLIST1
X-Cdn-Srv
IsBot
X-Irp-Debug
X-NodeID
User-Cache-Control
Fastly-SSL
Akamai-Mon-Iucid-Del
X-ORCA-Accelerator
Fl-Custom-Application
X-HOST
XM
X-Api-Version
X-CACHE-GROUP
X-LiteSpeed-Cache-Control
X-Varnish-Hits
X-Cs
X-Dc
X-VWS-Id
X-HS-CF-Cache-Status
True-Client-Country-4JS
X-AWS-Id
X-GEO
X-VServer
X-LJ-Flow-ID
X-TA-CDN-Provider
X-LB-NoCache
X-Air-Pt
X-Provided-By
X-HITS
X-Refresh
CloudFront-Viewer-Country
GeoIP-Latitude
C-Via
Sever-Int
Server-Ext
Proxy-Firewall
Server-Hostname
X-Test
X-Servedbyhost
X-RequestId
X-Nananana
X-Geolocation
X-Cache-Date
Fastly-Drupal-HTML
X-S-Cookie
Is-Eu
X-Destination
X-External-Request-Id
X-IsAdmin
X-B3-Parentspanid
X-Via-SSL
Edge-Copy-Time
X-DC
X-Application
X-B-Cookie
Adler-Geo
X-Via-Edge
X-APP
X-Via-CDN
X-Nginx-Cache-Key
X-Via-Poph
X-Via-Popv
X-Dispatcher-Number
X-Via-Popn
X-HA-Backend
X-Tt-Logid
X-B3-Spanid
X-Zone
X-Zen-Fury
Cdn-Requestid
S-Rt
X-Endurance-Cache-Level
X-ZONE
Fastly-Drupal-Html
X-Wa
WZWS-RAY
X-Nc
X-LB-ID
X-User
X-Litespeed-Tag
Cache-Tv-Group
X-DynaTrace-JS-Agent
HostName
X-Geo-Header
X-Webkit-Csp-Report-Only
T-Server
Server-ID
X-Custom-Header
X-Srv
X-CDN-Forward
X-Presslabs-Stats
Cdn
X-Oracle-Dms-Ecid
X-AIR-PT
X-Pass-Why
X-URL
X-COUNTRY
X-ND-Cache
Ohc-Cache-HIT
X-CS
Vc-Max-Age
GeoIp-Country-Code
X-Cache-Server
X-VC-TTL
X-CMSURLCustom
X-HubSpot-Correlation-Id
X-CACHE-AGE
X-Parent-Response-Time
WP-Super-Cache
X-Vgn-Hpd-Reason
X-TH-Server
X-Fpc
SID
X-Moov-T
X-DataCenter
True-Client-IP
X-Moov-Xdn-Caching-Status
Resin-Trace
X-Moov-Xdn-Version
X-NewRelic-App-Data
X-API-Version
Powered-By
Pics-Label
X-Old-Content-Length
Vix-Hermes-Req-Id
X-Varnish-Beresp-TTL
SEZNAM-JOBS-OFFER
Uri
True-Client-Ip
X-Datadome
X-Fastly-Cache
X-Ckpd-Fst-Backend
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Srv
On-Server
X-APP-VERSION
X-SERVER-NAME
GeoIP-Country-Code
X-FPC
X-TX-ID
X-Thinkindot-L1
X-Cache-VC
Thinkindot-Control
Serverhost
X-Vercel-Id
X-Action
ServerHost
Location
X-Vercel-Cache
X-Client-Ip
X-Stale
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Backend-Server
X-PHP-Backend
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-Cache-TTL-Remaining
AKAMAI
X-Amz-Meta-Opti
X-Air-Source
X-Dynatrace-Js-Agent
X-Air-Trace-Id
X-Air-Hostname
X-Oracle-Dms-Rid
Server-Id
N1-Cache
Magicmarker
Hostname
X-Debug-Service
X-Datacenter
Cl-Cache
X-Cdn-Cache-Status
X-Info
Av-Poweredby
X-Resp-Is-Stale
Xkey-La3
X-Proxy-Cache-La3
X-Fastly-Backend-Reqs
X-NC
Xkeylog
X-Fastly-Cache-Status
X-PERF
X-WA
X-ApacheServer
X-Litespeed-Cache-Control
X-V
Tcn
X-VCL-Version
X-Ssense-Gql
Sm-Log-Id
X-Ssense-Shipping-Surcharge-Enabled
X-Vc
X-Service-Response-Time
X-Ee-Request-Date
X-Ee-Generated-By
X-Cms-Device
X-Ee-Origin
X-Lb-Id
X-CDN-Cache-Status
X-Save-Cache
X-Nitro-Cache
X-Ee-Request-Id
X-IAuth-Set-Uid
X-VTEX-Cache-Backend-Header-Time
X-Vary-Devices
X-VTEX-Cache-Backend-Connect-Time
X-WA-Info
X-Udemy-Cache-App-Namespace
Store-Cloud-Cache
X-Geo
X-Render-Time
Time-Cloud-Cache
CDN
X-Cache-Ttl
X-New
TWC-GeoIP-DMA
TWC-GeoIP-City
Cache-Hits
X-App
X-Ha-Backend
X-Via-PopH
TWC-GeoIP-Region
X-Uri
X-Rollout
X-Via-PopV
X-Via-PopN
X-Github-Request-Id
X-Eligible
X-Oracle-DMS-ECID
X-Esi
Machine
Cloudfront-Viewer-Country
X-ServedByHost
RewriteTestHook
X-Ion-Hop
X-Ion-Healthy
Log-Origin
X-Jungle-Id
X-Forwarded-Site
X-Limited
X-Region-Sid
Cache-Contol
Geoip-Latitude
X-Akamai-Pragma-Client-IP
RewriteTeamHook
WWW-Authenticate
Cneonction
X-Lb-Nocache
X-Ua
My-App
X-Traceid
WebServer
Server-Info
Cmstype
Cmsid
X-Correlation-ID
CountryCode
X-Git-Commit
X-From
Edge-Cache
Pragrma
X-Container-Uri
Cf-Ipcountry
X-MSEdge-Flight
X-MSEdge-Features
X-EC-Lua
X-Requestid
X-Ftr-Request-Id
X-Dw-Trace-Id
X-Up
X-LAGOON
Reporter
CacheControlHeader
X-HS-Status
X-Check-Cacheable
X-Acquia-Purge-Tags
X-Acquia-Site
Lb
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Varnish-Hostname
X-SRCache-Key
X-Cdn-Request-ID
X-Akamai-Transformed
X-Serial
FSS-Cache
X-Pod
Permission-Policy
X-Sucuri-Id
X-Akamai-ERPolicy
Warning
CF-Cached-On
X-BBC-Origin-Response-Status
X-Akamai-ERRuleID
X-Elasticpress-Query
X-Fastly-Cache-Hits
X-Tncms-Bot-Tier
X-Ramcache
X-Ms-Blob-Type
X-Ms-Lease-Status
PICS-Label
X-Platform-Router
X-Orig-Cache-Control
X-Platform-Cluster
X-Platform-Processor
Timeexpire