Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Set-Cookie
Server
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
P3P
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
Access-Control-Allow-Origin
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Request-Id
X-Varnish
Referrer-Policy
X-Adblock-Key
X-Check
X-Generator
X-Language
X-Template
X-Type
X-Cache-Group
X-Pass-Why
X-Buckets
WPE-Backend
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Download-Options
Alt-Svc
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Host-Header
X-Cache-Hits
X-Ac
X-Hacker
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-AspNetMvc-Version
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-ShardId
X-Sorting-Hat-PodId-Cached
X-Via
X-Runtime
X-Served-By
X-Powered-By-Plesk
P3p
X-Contextid
X-PC-Hit
X-PC-Key
X-UA-Device
X-Amz-Cf-Id
X-PC-AppVer
X-ServedBy
X-PC-Date
X-PC-Host
MS-Author-Via
Content-Location
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-Timer
X-IPLB-Instance
X-Rid
X-Seen-By
X-Wix-Request-Id
Status
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Ua-Compatible
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Tumblr-Pixel-1
CF-Cache-Status
Cartoon
X-Tumblr-Pixel-2
X-Iinfo
Access-Control-Allow-Credentials
X-Backend
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
Content-Encoding
Powered-By
X-CST
X-Endurance-Cache-Level
X-Host
X-Cache-Enabled
X-Mod-Pagespeed
X-Cache-Hit
X-FRAME-OPTIONS
X-Port
X-CDN
X-Tumblr-Pixel-3
X-NewRelic-App-Data
X-Newrelic-App-Data
X-Logged-In
X-Server-Powered-By
Keep-Alive
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-DIS-Request-ID
X-Server
X-Robots-Tag
X-Accel-Version
X-Proxy-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Turbo-Charged-By
X-Page-Speed
X-GitHub-Request-Id
X-Content-Powered-By
X-LiteSpeed-Cache
X-Content-Digest
Content-Security-Policy-Report-Only
X-Request-ID
X-Rack-Cache
X-Tumblr-Pixel-4
X-FW-Hash
X-FW-Server
X-AH-Environment
Request-Context
X-FW-Serve
X-FW-Type
X-FW-Static
X-Pad
X-Varnish-Cache
Edge-Control
X-Hits
X-Trace
X-Webcom-Cache-Status
Access-Control-Expose-Headers
X-XRDS-Location
SPRequestGuid
X-BC-Stapler
X-SharePointHealthScore
X-Request-Country
Edge-Cache-Tag
X-MS-InvokeApp
X-HS-Cache-Config
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-Node
Cf-Railgun
WP-Super-Cache
X-CF-Powered-By
X-HS-Combine-CSS
X-Amz-Id-2
X-Amz-Request-Id
Charset
X-Died
Timing-Allow-Origin
X-SERVER
X-Content-Security-Policy
X-Webserver
X-FullPageCaching
X-Fastly-Request-ID
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
X-Cache-Lookup
X-PhApp
Access-Control-Max-Age
X-Cnection
Request-Id
X-Backend-Server
SPIisLatency
SPRequestDuration
X-Edge-Cache
X-Edge-Cache-Key
CONTENT-SECURITY-POLICY
X-Servedby
MicrosoftOfficeWebServer
X-CDN-Pop
X-CDN-Pop-IP
EagleId
Rating
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Tumblr-Pixel-5
Composed-By
X-SS-Location
X-SS-Conf
Ali-Swift-Global-Savetime
X-Safe-Firewall
X-Tumblr-Content-Rating
X-Server-Name
X-Device
X-NF-Request-ID
X-DDC-Arch-Trace
Liferay-Portal
Served-By
X-Dw-Request-Base-Id
X-Do-Not-Hack
X-HeyJason
Permitted-Cross-Domain-Policies
X-Spip-Cache
X-VCache
X-Cloud-Trace-Context
X-Hyper-Cache
X-Microcache
Front-End-Https
P-LB
P-WS
X-LiteSpeed-Cache-Control
X-RateLimit-Limit
X-RateLimit-Remaining
Surrogate-Control
X-Middleton-Display
Display
X-Sol
X-TNCMS
X-Loop
X-Original-Date
Response
X-Middleton-Response
X-Cluster-Node
X-Acc-Exp
X-RateLimit-Reset
X-Jimdo-Instance
X-Jimdo-Wid
X-OneAgent-JS-Injection
X-Clacks-Overhead
X-FB-Debug
X-DNS-Prefetch-Control
X-Firenze-Processing-Times
Content-Style-Type
X-Kinsta-Cache
X-Vtex-Processado-Em
Content-Script-Type
Public-Key-Pins
X-Debug-Info
X-Wix-Punisher
X-StackifyID
X-Shopid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Featureset
X-Sorting-Hat-Podid
X-Tumblr-Pixel-6
X-Sorting-Hat-Shopid-Cached
X-Shardid
X-Sorting-Hat-Podid-Cached
X-Amz-Version-Id
X-Age
X-Magento-Tags
X-HOST
Refresh
X-User-Agent
X-LW-Cache
X-Goog-Hash
X-DynaTrace-JS-Agent
X-XN-XNHTML
X-XN-Trace-Token
Fpc-Cache-Id
X-Ruxit-JS-Agent
X-Zen-Fury
Xkey
X-Cache-Config
X-Url
X-Cached
X-Px
Feature-Policy
X-N-OperationId
PageSpeed
Wpe-Backend
X-Hostname
Retry-After
X-WebKit-CSP
X-Upstream
X-Version
X-Handled-By
X-Frame-Option
X-Topify-Platform
X-Generated-By
X-Goog-Generation
X-Edge-Location
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-FORWARDED-FOR
Rt-Fastcgi-Cache
Allow
X-Source
Fastcgi-Cache
Access-Control-Request-Method
X-MiniProfiler-Ids
X-Loopia-Node
X-Whom
X-B-Cache
X-Request-Time
X-ET-API-VERSION
X-ET-API-ROOT
X-ET-API-ORIGIN
Powered
X-EdgeConnect-Origin-MEX-Latency
X-SRCache-Fetch-Status
X-Cached-By
X-SRCache-Store-Status
ServedBy
TCN
X-Platform-Cluster
X-Platform-Processor
X-URLSCHEME
X-Platform-Router
X-RESOURCE
X-EdgeConnect-MidMile-RTT
X-Guploader-Uploadid
Product
X-Engine
X-CMS-Version
X-Content-Options
X-ARC
X-Outils-CS
Last-Published
Fhost
X-Application-Context
X-Fastcgi-Cache
X-Vtex-Processed-At
No
X-VTEX-Janus-Router-Backend-App
X-Vtex-Remote-Cache
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Cache-Status-Janus-ApiCache
X-CacheServer
X-AspNetWebPages-Version
X-Magento-Cache-Debug
X-F-Cache
X-Accel-Expires
X-Tec-Api-Origin
Pagespeed
X-Tec-Api-Root
X-Tec-Api-Version
X-Developer
X-Varnish-Count
Cache-Provider
X-Varnish-Host
Warning
X-DynaTrace
X-Varnish-HitMiss
Public-Key-Pins-Report-Only
X-Signature
X-Varnish-Cache-Hits
X-Returned-From
X-Original-Request
X-Passed-To-DLL
X-Passed-To
X-Returned-From-DLL
X-Location-Id
X-Shop-Id
X-Defender
X-Actual-URL
X-UD-Method
X-Ezoic-Cdn
X-S
Generator
X-LBLID
X-Platform-Server
X-From
X-Response-Time
X-Microcachable
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Cache-Key
X-Varnish-Beresp-Grace
Cache-Key
X-ApacheServer
Imagetoolbar
X-PERF
X-Stale
X-Cache-Info
X-Device-Type
X-Returned-From-BeforeDispatch
X-Passed-To-BeforeDispatch
X-Umbraco-Version
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
Host
Alternate-Protocol
X-Micro-Cache
X-HS-Content-Campaign-Id
X-Hosted-By
X-Platform
X-NWS-LOG-UUID
X-Via-JSL
X-Sapient
X-URL
Origin
Version
Content-Hash
X-Cache-Namespace
X-Recruiting
Surrogate-Key
X-Platform-Cache
DynaTrace
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Cache-Rule
X-I-Sp
Arr-Disable-Session-Affinity
Akamai-IP
X-SO
X-BS
X-Lambda-Id
X-Acquia-Application-UUID
X-Cache-Age
X-Track
X-SSLUpstream
X-Translation
X-Powered-By-360WZB
X-Microcache-Status
X-SSLProxy
X-Instart-Request-ID
X-Forwarded-For
X-Akam-SW-Version
Dmn
X-Correlation-Id
X-Svr-Proxy
X-SVR-IIS
X-Dealeron-Original-Url
X-Dealeron-Backend
X-Environment
X-DealerOn
X-Rnd
X-Magento-Cache-Control
X-Powered-By-VTEX-Janus-Edge
MIME-Version
X-Msg-2-Log
RTSS
X-Dns-Prefetch-Control
X-Dispatcher
WZWS-RAY
X-Cache-TTL
SSPAppContext
X-Server-Upstream
X-Supported-By
X-Duration
X-Cache-Tags
S-Cnection
USPLoggingUUID
X-SSL-Cipher
X-SSL-Protocol
X-App-Status
Pool
Content-Disposition
X-Abgroup
X-Powered-By-VelaWeb
X-Director
X-Edge-IP
X-App-Hosting
X-Storage
Wsr-Cache
X-Server-ID
X-NetCat-Version
X-Expires-Orig
X-Page-Cache
X-Hypernode
X-Cache-Control-Orig
Node
X-TransIP-Balancer
X-LB-Node
X-CSRF-Protection
X-Vcap-Request-Id
X-ORACLE-DMS-ECID
X-Revision
Accept-Encoding
X-TransIP-Backend
X-Rocket-Nginx-Bypass
X-Matrix-Server
X-Matrix-Proxy
X-I
X-Debug
X-Front
X-Cache-Debug
Edge-Control-Message
X-Geo-Country
X-ATG-Version
Cache
X-Generated
X-Varnish-Cacheable
X-Now-Id
FAI-W-FLOW
X-Client-IP
X-Correlation-ID
X-Env
X-Cache-Handler
X-Cache-Lifetime
X-Drupal-Cache-Tags
Contao-Page-Layout
X-VARITI-CCR
X-Cache-Server
X-Daa-Tunnel
X-Rocket-Nginx-Serving-Static
X-Art-Request-Id
SiteSpeed
X-ServerName
X-Cache-Operation
X-LB-Server
X-SmugMug-Hiring
X-TTFB-L
X-Acquia-Application-Trace
X-SmugMug-Values
X-TTFB
ServerID
Update-Time
Src-Update
Smug-CDN
X-NoCache
X-SRV
X-Gamma-Serve
X-Last-Modified
X-Hiawatha-Cache
X-Varnish-TTL
Content-Encoding-Handler
X-Url-Base
X-IsCacheURL
X-Server-Id
X-Route-Server
X-Varnish-Age
Req-Id
X-Vhost
X-Cache-Level
Powered-By-ChinaCache
X-Cache-Engine
X-Varnish-Seen-By
X-Dispatch
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-Amz-Meta-S3cmd-Attrs
X-Varnish-RemainingLife
X-Discourse-Route
X-Varnish-ObjectSource
X-Varnish-Url
X-SV-Cacheable
X-SV-FromDBCache
X-SV-Expires
X-Grace
X-SV-Nginx-Duration
X-SV-Pid
SN
X-SV-Edge
X-SV-CacheTags
X-SV-Duration
X-SV-CreatedAt
X-Firenze-Processing-Time
X-Cache-Only-Varnish
X-GeoIP-Country-Code
Backend
Author
X-Pressidium-NinukisWP-Ver
X-Server-Instance
X-CJ-Soft
X-Drupal-Cache-Contexts
X-Unbounce-VisitorID
Section-Io-Id
X-Unbounce-PageId
X-Unbounce-Variant
X-Country-Code
Https
X-Middleware-Start
X-Varnish-IP
Lsrequestid
Cache-Tags
X-TransIP-Reserved
If-Modified-Since
X-Trace-Id
X-Varnish-Backend
X-Locale
X-SDS
X-N
ServerName
X-Sucuri-ID
X-Litespeed-Cache
X-Flow-Powered
Cneonction
Page-Completion-Status
Location
Strikingly-Cached-Version
X-Amz-Rid
Strikingly-Cache-Region
X-Content-Encoded-By
Strikingly-Cached
X-Forwarded-Proto
X-Cache-Expires
X-Content-Type-Option
X-Cache-Type
Proxy-Connection
X-Twitter-Response-Tags
X-Connection-Hash
X-Time
X-Sucuri-Cache
X-Transaction
X-Service-Id
X-Always-Cache
Content-MD5
MJ12bot
X-SRCache-Key
W
X-TTL
SEOMOZ
X-Esi
Service-Worker-Allowed
X-Config-Blacklist-Version
X-Ttl
AMF-Ver
X-FIRSTBase
X-High-Performance
X-GUploader-UploadID
X-Magnolia-Registration
X-Webkit-CSP
X-Speed-Cache-Key
X-Speed-Cache
Use-Proxy
X-Cache-Control
X-Shard
X-Varnish-Retries
X-CF-Passed-Proto
X-GeoIP-Country-Name
X-WR-MODIFICATION
X-Now-Cache
X-FW
X-LB
Srv
X-FTR-Request-ID
X-ORACLE-DMS-RID
Custom-Header
X-Real-Server
X-Dynamic-Cache
X-Wikidot-Backend
X-Cache-Fix
X-PwB-Node
X-Wikidot-Static-Cache
From-Origin
X-BackendServer
X-Cache-PageType
X-Frontend
Server-Name
X-Akamai-Device-Model
X-Cookie-Domain
X-Storage-Cache-Expires
Pv
X-HW
X-Nginx-Cache
Swift-Performance
X-CDN-Forward
FindLaw
X-Empowered-By
X-Storage-Cache
X-Storage-Cache-Date
Edit
X-Akamai-Device-Characteristics
X-Cache-Device-Type
X-Xrds-Location
MC
X-Nitro-Cache
NetMindSessionID
X-Content-Security-Policy-Report-Only
X-Pool
X-Symfony-Cache
Prama
IBM-Web2-Location
Local-Info
X-NginX-Cache
Xc-Version
X-ServerID
X-Litespeed-Cache-Control
PICS-Label
X-Browser
Fw-Via
Drupal-Pagecache-Memcache
Ohc-File-Size
Content_type
X-ACMCache
X-Varnish-Server
X-Vip
X-Nbs
X-Amz-Meta-Content-Md5
NnCoection
Qs-Cache
X-Key
X-Processing-Time
X-Runtime-Memory
X-Srv
X-PF-Uncompressing
X-Cache-Miss-From
X-Sedo-Request-Id
X-Varnish-Hits
X-FireWall-Port
Nodo
X-Analytics
X-Id
Pics-Label
IM-Version
Hummingbird-Cache
X-Location
Backend-Timing
X-A
Cached
X-Worker
X-Yadis-Location
X-Orig-Vary
X-Disney-Akamai-Rule
Content-Transfer-Encoding
Server-Timing
X-SP-UniqueName
X-RequestId
Tracecode
Noq
X-Content-Age
Ramp
X-SP-Farm
X-LP
Ram
S
X-WR-Flags
X-Purge-Host
X-CacheFROM
X-BKSrc
X-Purge-URL
X-Rq
X-ID
X-Amz-Storage-Class
X-Role
RequestId
X-Distributor
Dtk-Cache-Check-0
X-Varnish-ID
X-Pantheon-Site
X-Pantheon-Phpreq
X-Varnish-Ttl
X-Pantheon-Environment
Surrogate-Key-Raw
CacheControlHeader
X-Cache-2
Access-Control-Allow-Method
X-SERVER-NAME
X-Varnish-Hostname
X-Sys-Req-ID
X-Cache-CFC
X-Hit-Cache
Adm-Server
X-Proxy
X-AEM
X-Shield-Request-Id
X-Pagename
X-Drectory-Script
X-Unique-ID
X-JSESSIONID
X-NginX-Server
X-4ormat-Cacheable
X-CB-Server
X-LW-Web-Server
X-Adobe-Loc
X-Hstore
X-E
Proxy-Agent
X-TB-M
AsisCache
X-VC-Enabled
X-Hrouter
X-Origin
X-Adobe-Content
Cm-Server
X-HydroSheep
Cteonnt-Length
X-Yottaa-Metrics
X-ClientSide-Caching
Dynatrace
X-Span
X-Dynatrace
Accept-Charset
X-App-Runtime
Accept-Language
Request-EU
Frame-Options
X-GoCache-CacheStatus
Web-App-Origin-Name
X-Proxy-Backend
Request-Country
X-Yottaa-Optimizations
Lookup-Cache-Hit
X-Runtime-Affili
X-Backend-Status
X-CAPServer
CF-Worker-Script
X-Culture
SVR
Server-Info
X-Appmachine-Environment
X-JG-Page-Cache
X-Stage
Nginx-Cache
A-Powered-By
X-Dw-Trace-Id
Lb
X-Balanceador
Server-ID
X-V
WWW-Authenticate
X-PRAM
X-Atraveo-Varnish-Server-Id
X-ARRServer
X-Atraveo-TTL
X-Atraveo-Set-Cookie
Front
X-Path-Route
X-Force
X-Real-IP
X-Forwarded-Host
X-Vcache
X-Atraveo-Zone
X-Atraveo-Param-Rm
X-Request-Uri
X-Atraveo-ETag
X-App
SHInfo
X-ServerIndex
X-Generated-Timestamp
Upgrade-Insecure-Requests
X-Atraveo-Cache-Control
X-Atraveo-Expires
X-Atraveo-From-Varnish-Cache
X-CLOUD-TRACE-CONTEXT
X-Jphone-Copyright
X-Ratelimit-Limit
X-Varnish-Debug-TTL
X-Pantheon-Az
Beyond-Iis
X-Varnish-Debug-Age
HCVer
X-CacheDebug
HAVer
X-WPL-DATA
X-GeoIP
X-CACHE-TTL
SRV
X-Webstats-RespID
X-Distil-CS
X-Agent
X-Ratelimit-Reset
X-Proxy-Skip
XDomainRequestAllowed
X-Runtime-Rack
Access-Control-Request-Headers
X-Ratelimit-Remaining
X-Session-ID
X-Hosting-Env
X-SDE-Name
X-Akamai-Transformed
X-ESI
Accept-CH
X-Rule
X-Debug-Token
X-RealServer
X-VC-TTL
CS-SERVER
WP-FROM-CACHE
X-Frames-Options
X-Plat
Firespring-Website-Id
Load-Balancer
IES-Server
X-SE-Debug
Yoncu-Errno
X-Framework
X-RiS-UFDI
X-Processed-By
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
X-Batcache
X-Domain-Checked
X-Cms-Mode
X-Dev
X-Dynatrace-Js-Agent
Worker
X-Provisioner-Version
X-Helper-Autoassign-All
X-Fedora-School-Id
X-Server-IP
X-Remote-Addr
CLMOB
Referer
X-Map-Context
X-Varnish-Grace
Copyright
X-Req-Head-Response
ServerTokens
ServerSignature
X-AOL-HN
Web
X-Avg-Cookie-Expires
X-Upgrade-Enabled
X-Resource
X-UPSTREAM
Pf.Web.Request.Id
X-Akamai-Edgescape
X-NWS-UUID-VERIFY
X-Detected-Device
Eomportal-Instance
X-Source-ID
X-Redman-Backend
ScoreTracker
X-Redman-Final-Url
X-AVG-Country-Code
X-IIJ-Cache
X-HTML-Minification-Powered-By
X-TKP-SRV-ID
X-Oferteo-Domain
X-HashTwo
X-Soro
X-Proxy-Cache-Control
X-Header
X-Session-Reinit
X-Refresh
X-Cocoon-Version
AETN-Continent-Code
Dispatcher
*
AETN-Country-Code
AETN-Country-Name
AETN-EU
AETN-DEVICE
AETN-City
AETN-Area-Code
X-Autoru-Host
X-Amz-Id-1
X-Amcomm-Site
X-Info
X-Nginx-Host
X-App-Server
X-Confluence-Request-Time
Max-Age
X-Via-S
Play-Detected-UserAgent
Proxy-Cache
X-VCS-Ttl
Play-Detected-Device
Traffic-Origin
X-Application
Il-Cl
Thanks
X-VCS-Cacheable
X-Domino-CacheValidationWithETagResult
X-DSMX-Render-MS
X-DSMX-Rewrite-MS
X-Domino-CacheValidationWithETagReason
X-B2f-Not-Route
X-Varnish-Cache-Local
X-Aramark-SID
Home
X-ETag
X-Streams-Distribution
Arrnode
BALANCEDTO
Access-Control
X-WebNode
X-Data-Request
AETN-Latitude
Cleartype
Num
AR-ATIME
X-HA-Frontend
X-HA-Backend
AR-CACHE
AR-PoweredBy
X-SAPP
AR-SID
X-UA-Bot
X-Ghost-Cache-Status
X-Highwire-RequestId
X-CRA-DC
X-Cache-Varnish
X-Bip
X-Highwire-SessionId
X-PHP-Response-Code
X-SmartBan-URL
X-SmartBan-Host
X-Rebelmouse-Cache-Control
X-Garden-Version
X-AF-Userserver
AMP-Redirect-To
X-Desc
VServer
X-FORWARDED-PROTO
X-MAT-GEO
Identity
Access-Control-Allow-Header
Disablevcache
X-7d-Trace-Id
X-7d-Instance-Id
Paypal-Debug-Id
X-Cache-On
Filters
AKA-DEVICE
AETN-State-Code
AETN-Postal-Code
AETN-Longitude
X-GSL-Server
WP-AdvCache-MemCached
Pramga
X-EPiphany-Vid
X-Now-Trace
X-Client-Vid
X-Cacheable-TTL
Cmsid
X-Client-Image-Vid
Now
Cmstype
X-OpenCart-Lightning
NtCoent-Length
X-Smartcache-Keys
X-Cache-Ttl
X-SV
X-WP
X-Smartcache-Timeout
X-Rack-Cors
RN-Server
X-Via-NSCOPI
X-DataDome
X-SERVER-ID
X-Ms-Request-Id
X-Envoy-Upstream-Service-Time
Url
X-Compress-Hint
X-Cache-Me-Harder
X-HostName
X-CACHE-KEY
COMMERCE-SERVER-SOFTWARE
X-Varnish-URL
IISExport
X-Geo-IP
X-CacheLoc
X-Beget-Proxy
Ibf5scheme
N365rili
X-Clara-ASAP
Prot
DNNOutputCache
X-Lb
Aurora-Node
TC-Cache-IC
Description
X-SilverStripe-Cache
X-Block-RuleID
TC-Cache-U
X-Middleton-PageSpeed
TC-Cache
XX
Nitro-Cache
X-DevSrv-CMS
X-Test
X-Served-Server
X-Route
X-Skip-Cache
X-Goog-Meta-Replace
X-ASAP-Cache
Keywords
X-Policy
X-Upstream-Status
X-Block-Rule
X-WEBMGR-CACHE
X-Cache-Detail
X-Amzn-Trace-Id
Og
X-Gyrobase-Publication
X-Amzn-RequestId
X-Amz-Apigw-Id
CDN-Cache
Dis-Env
CDN-Uid
CDN-RequestId
X-Resty-Request-Id
X-CacheID
X-SH-Cache-Status
X-Response
Environment
CDN-CachedAt
CDN-PullZone
FRONT-END-SECUREBROWSER
X-Upstream-Backend
X-Goog-Meta-Policy
TC-S-Cache
MageStack-Loadbalancer
X-Flex-Tag
X-Flex-Tags
MageStack-Debug
X-Flex-Lastmod
X-Flex-Evend
X-Flex-Evstart
X-Flex-Lang
X-HeBS-Cache-Status
MageStack-Magento-Version
MageStack-Web-Node
Viewport
AMP-Access-Control-Allow-Source-Origin
X-Nx-All
X-PBY
MageStack-PageSpeed
MageStack-Tag
X-Requestid
X-Flex-Community
X-Consent-Required
Fastly-Backend-Name
Myheader
MageStack-Cache-Status
Edgecast
MageStack-Cache-Lifetime
MageStack-Cache
MageStack-Area
MageStack-Cache-Hits
MageStack-Cacheable
PServer
X-Actindo-Thread-Id
X-Adnet
X-AutoRu-App-Id
X-Actindo-Rs
X-Actindo-Request-Id
MageStack-Config
VANITY-HOST
X-LBPoolMember
X-Nx
X-Scheme
Ttl
VAR-Cache
X-Server-Addr
X-Varnish-Id
X-Timestamp
X-RiS-PX
X-Hit
ServerNode
X-Mobilized-By
X-Cache-Doesi
X-DN-Cache-Control
X-EC2-Instance-Id
TC-S-Cache-M
X-Beatles
X-Geo
Server-Ip
X-Qnm-Cache
X-Fastly-Request-Id
X-M-Log
X-M-Reqid
X-Tag-Playlist
X-Sid
X-Access-Control-Allow-Origin
BackendServer
X-Served
Device
X-Appid
X-Deity
Serverid
X-Vary-Options
X-Varnish-Debug-Hits
X-FastCGI-Cache-Status
X-Varnish-Action
X-Reflector-Cache
X-Reflector
CommunityServer
X-Pj-Cache-Status
Xc
VSID
X-Proto
ViewMode
X-Appversion
X-RAMCache
X-Cdn-Forward
X-ORIKEY
X-APIVERSION
X-APIAUTH-VAL
X-Gateway-Rate-Limit-Delayed
X-TLS-Version
X-Highwire-Sitecode
NODE
X-ENDPOINT
X-DB-Content-Length
X-Highwire-Smart-Code
X-Varnish-Ip
X-ROUTING
Ohc-Response-Time
CF-Cache-Key
X-We-Are-Hiring
X-Proxy-Id
X-Phpwcms-Page-Processed-In
X-Page
X-Phpwcms-Release
X-Nginx
CF-Worker-Version
X-WebKit-CSP-Report-Only
Content
X-Svr
SBSS
X-ENV
DB-Nickname
Webserver
Content-Sn
From
ModuleCacheType
Backend-Powered-By
X-Unique-Id
X-Beluga-Status
X-Node-App
X-Protected-By
X-Meta-MSThemeCompatible
CommercePlatform-Version
X-Meta-MSSmartTagsPreventParsing
EagleEye-TraceId
Debug-Status
Id
X-Client-Id
X-Obvious-Info
X-ACCELERATE
Tk
Provider
Resin-Trace
X-Meta-Imagetoolbar
X-Instance-Name
OracleCommerceCloud-Version
X-Cache-TTL-Age
ServerIP
Session-From
StatusCode
Ufe-Result
OracleCommerceCloud-Sandiego
MSThemeCompatible
Httpd-Identifier
X-Goog-Meta-Goog-Reserved-File-Mtime
MSSmartTagsPreventParsing
X-Firewall
X-Cache-TTL-Current
X-Varnish-Cached-TTL
X-Obvious-Tid
X-Beluga-Record
X-Beluga-Node
X-Beluga-Response-Time
X-Static
X-Beluga-Response-Time-X
X-Secret
X-Beluga-Cache-Status
X-B3-Sampled
X-Aramark-CSID
X-Reqid
YF-ID
TYPO3-Sitename
X-Title
X-ZSITES-DNS
X-Beluga-Trace
X-Layout
X-Sn-Servicetimems
Machine
X-Resolver-IP
X-UPServer
X-Varnish-Cached
X-Origin-Date
X-FPC
X-Proxy-Cache-Key
X-Cdn-Origin
X-Captured
X-Depends
X-Fpc
X-MCF-ID
TYPO3-Pid
X-HA
X-Shopware-Cache-Id
X-Blog
X-Shopware-Allow-Nocache
X-Origin-Cache
X-NoIndex
X-Cache-Time
X-Rack-CORS
Provided-Host
GranicusServer
X-Varnish-Backend-Beresp-Backend
Session-Id
X-Instance
X-Custom-Header
X-MrHost
Bios
X-Webcelerate
X-Wodby-Node
X-Generated-Time
Fastly-Debug-Digest
X-Batcache-Reason
Server-Id
NGX
Hosted-By
HTTPS
MS-CV
WN
X-Build-Id
X-MCB-Server
X-Cname-TryFiles
MageStack-Last-Modified
MageStack-Cache-Warning
X-Processed
X-This-Proto
X-M
MageStack-Cache-Lifetime-Sent
X-MID-Host
X-ProBase-Server
X-Cache-LB
Tempo
X-Cache-Node
X-CH-Device
Amfplus-Ver
X-WN-ClientGroup
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-V-Cache
X-Powered-By-Home.Pl
X-Vol-Mrp
X-PM-ID
X-Status
HitType
HSTS
X-Pass-Through
X-PBS-Fwsrvname
X-PBS-Appsvrname
Response-Time
X-NewsFlow-Sitename
X-Search-Id
X-PBS-Appsvrip
X-Mighty-Proxy
TP-Cache
X-Compressed-By
X-FastCGI-Cache
X-Custom-Name
X-Max-Age
X-Cluster
X-Cache-Extended
Ssl-Proxy-Server
TP-L2-Cache
X-Box
X-Cache-Action
Magicmarker
X-Src-Webcache
X-Global-Transaction-ID
X-Now-Instance
X-FromPodPressCache
X-Firefox-Spdy
X-DynamicCache
X-Cache-FS-Status
SINA-TS
SINA-LB
X-Vol-Correlation
Cf-Ipcountry
Hit-Count
X-MyName
X-Backside-Transport
X-MainProfileName
X-MainProfileURL
X-UnsetCookies
Purge-Cache-Tags
REFRESH
PBS
X-HS-Status
X-MainProfileID
X-Instance-Id
X-MainProfileCategory
X-RENDER-TIME
X-COUNTRY-CODE
X-Xml-Http-Blocked
X-PROCESSED-BY
X-Serv
X-DEBUG
X-Actual-Url
X-Directory-Script
X-Oracle-Dms-Ecid
X-From-Cache
X-Cache-HT
X-Amz-Meta-S3b-Last-Modified
X-GZip
X-Optimization
X-Appmachine-Name
X-Appmachine-Duration
UrlWatchModule-Time
Fastly-Restarts
X-BPool-Back
X-Appmachine-CreatedOn
X-Varnish-Age-Debug
X-Varnish-TTL-Debug
X-InDy-Query
X-InDy-Memory
X-InDy-Time
X-Mobile-Rewrite
X-Origin-Upstream-Status
X-Grid-Server
PROGMA
Amp-Access-Control-Allow-Source-Origin
LB
PB-PID
PB-RID
X-XHTML-Minification-Powered-By
X-W3TC-Minify
X-NMT-Proxy
X-Cache-Bypass
Prototype-RootPath
X-Node-Id
X-Server-Hostname
Hostname
X-ManagedFusion-Rewriter-Version
X-BServer
X-SSL-Host
X-Gannett-Site-Version
X-Fstrz
X-Powered-By-ADS
X-Rewritten-By
X-AppServer-Cache-Rule
X-AppServer-Cache-Exception
X-Amzn-Remapped-Date
X-Varnish-Cache-Ttl
X-Test-Debug
X-AppServer-Status
X-Ruxit-Js-Agent
SS
X-Serverid
X-Autoru-App-Id
X-ORIGN-SERVER
X-Router
X-Country
EQ-Cache
PagesDisplayed
V-Cache-Ttl
X-Beresp-Ttl
X-Fastly-Backend-Reqs
X-Front-Cache
X-Cache-Id
X-Enabled1
X-Enabled2
X-Enabled3
RSL-Trace-ID
Origin-Vm
X-TEST
X-Time-Spent
X-Expires
X-SSLTerm-Server
X-Magento-Route
X-CSRF-Token
X-CAMPUSSUITE-TENANT
Fastly-Drupal-Html
X-UT-Cache
X-CAMPUSSUITE-DEBUGGING
X-CAMPUSSUITE-ENVIRONMENT
X-No-Session
X-Pageid
Ews
X-Healthy
X-Catalyst
X-Bitrix-Composite
X-Avvio-Cms-Cacheload
X-Middleton-Pagespeed
Actual-Object-TTL
D
X-Telligent-Evolution
Generate-Time
SERVER-NAME
VC-NoCache
ProxiaInstanceId
X-Tradeindia-SMgmt
X-Tradeindia-Request-GUID
X-Accel-Cache-Control
Arrow-RequestId
X-Vid
Servername
Gzip
F5-IpCliente
ClientIP
X-SG-Server
X-Itkg-Cache-Tags
X-CloudBurst-Frontend
X-BeResp-Ttl
NKBVHEADER
Progma
Request-Time
X-SEA-Instance-Name
X-Transaction-Name
L5d-Success-Class
X-Content-Type
HA-Host
HA-Georegion
HA-Ipaddr
HA-Servedtime
HA-Urlpath
X-Bcwwwid
X-Cachable
X-Mobile-Device
X-Mobile-Device-Type
X-Ruby-Cluster-ID
X-ServiceProvider
X-Az
X-Debug-Message
X-NginX-Upstream
X-Jcms-Ajax-Id
X-CGP
X-Built-With
X-SCProxy
X-HAProxy
X-Homeaway-Requestmarker
HA-Geolon
HA-Geolat
X-Clx-Request
X-Navigation-Version
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-PoweredBy
X-MSU-SOURCE
X-Olaf
HitInfo
X-Log
X-Oracle-Dms-Rid
Requested-Host
Unique-Request-Id
Web-Server
X-HP-CAM-COLOR
X-Requested-With
X-UPSTREAM-Address
BlockPHPCallEnd
HA-Cloudapp
HA-Geocity
HA-Geocountry
AC-ELC
X-VG-WebCache
X-Rocket-Nginx-File
X-D2id
X-Rocket-Nginx-Reason
X-SuperCache
X-UType
X-Amz-Meta-Version-Id
X-XHR-Current-Location
X-Old-Content-Length
Sl-Pgid
X-ProcessESI
X-RemovedCookies
X-Server-Generated
X-ReqId
X-Machine
X-JoinUs
X-ASAP-Age
X-CloudBurst-Backend
X-Cache-Warmer
X-Enhanced-By
X-FG-RequestId
NLCacheNote
X-AMAZEEIO
X-Ssl-Cipher
X-SCM-Server-Number
X-Who
CDCHOST
Report-To
Language
X-Proxy-Server
X-Origin-Server
X-Ms-Version
X-IP
X-Nginx-Request-Processing-Time
X-NodeID
X-PressLabs-Stats
WebServer
X-CloudBurst-Cache
X-Varnish-Cache-Control
X-VHosting-Cache
X-Served-From
X-BIT-Node
X-Nginx-Page-Cache
X-Server-Ip
ID
X-Boot
X-SSL
X-Activity-Id
CmsfirstPublishTimestamp
X-OPNET-Transaction-Trace
X-Cache-ID
X-Pagely-Cache
DrivedBy
SB-Cache-Life
Returned-Status
SB-Cache-Remaining
SB-Site-Device
SB-Site-IE-VERSION
X-Qiniu-Zone
X-CloudBurst-WordPress
MwpReleaseVersion
MachineName
NZSpeedy
Page-Template
Pragrma
X-Airee-Node