Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Set-Cookie
Server
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Content-Language
Expect-CT
P3P
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
X-Xss-Protection
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Request-Id
Referrer-Policy
X-Varnish
X-Adblock-Key
X-Check
X-Generator
X-Language
X-Template
X-Type
X-Cache-Group
X-Pass-Why
X-Buckets
WPE-Backend
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Download-Options
Alt-Svc
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Ac
X-Hacker
Host-Header
X-Cache-Hits
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-AspNetMvc-Version
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-ShopId-Cached
P3p
X-Via
X-Runtime
X-Powered-By-Plesk
X-Served-By
X-Contextid
X-PC-Key
X-PC-Hit
X-UA-Device
X-ServedBy
X-PC-AppVer
X-Amz-Cf-Id
X-PC-Date
X-PC-Host
MS-Author-Via
Content-Location
Access-Control-Allow-Headers
X-Powered-CMS
Access-Control-Allow-Methods
X-IPLB-Instance
X-Timer
X-Rid
X-Wix-Request-Id
X-Seen-By
Status
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Ua-Compatible
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Tumblr-Pixel-1
CF-Cache-Status
Cartoon
X-Tumblr-Pixel-2
Access-Control-Allow-Credentials
X-Iinfo
X-Backend
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
X-CST
Powered-By
X-Host
Content-Encoding
X-Endurance-Cache-Level
X-NewRelic-App-Data
X-Mod-Pagespeed
X-Cache-Hit
X-FRAME-OPTIONS
X-Port
X-Cache-Enabled
X-Tumblr-Pixel-3
X-CDN
X-Logged-In
X-Newrelic-App-Data
X-Server-Powered-By
Keep-Alive
X-DIS-Request-ID
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Robots-Tag
X-Server
X-Accel-Version
X-Request-ID
X-Turbo-Charged-By
X-Proxy-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
X-Content-Powered-By
X-LiteSpeed-Cache
X-GitHub-Request-Id
Content-Security-Policy-Report-Only
X-Content-Digest
X-Tumblr-Pixel-4
X-Rack-Cache
X-FW-Hash
X-FW-Server
X-AH-Environment
X-FW-Type
X-FW-Serve
X-FW-Static
X-Pad
Request-Context
X-ASPNET-VERSION
X-Varnish-Cache
Edge-Control
X-Hits
X-Trace
X-Webcom-Cache-Status
X-XRDS-Location
X-Request-Country
SPRequestGuid
X-BC-Stapler
X-SharePointHealthScore
X-Node
X-MS-InvokeApp
Edge-Cache-Tag
Access-Control-Expose-Headers
X-HS-Cache-Config
X-SERVER
WP-Super-Cache
X-HS-Content-Id
MicrosoftSharePointTeamServices
Cf-Railgun
X-HS-Combine-CSS
X-CF-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
Charset
Timing-Allow-Origin
X-Content-Security-Policy
X-FullPageCaching
X-Died
X-Fastly-Request-ID
X-Cache-Lookup
X-PHP-Backend
X-Webserver
X-INKT-SITE
X-INKT-URI
X-Cnection
Request-Id
Access-Control-Max-Age
X-PhApp
X-Backend-Server
SPIisLatency
SPRequestDuration
X-Edge-Cache-Key
X-Edge-Cache
CONTENT-SECURITY-POLICY
Rating
EagleId
Composed-By
MicrosoftOfficeWebServer
X-Swift-CacheTime
X-Swift-SaveTime
X-CDN-Pop
X-Tumblr-Pixel-5
X-CDN-Pop-IP
Grace
X-SS-Conf
X-SS-Location
X-Server-Name
X-Tumblr-Content-Rating
X-NF-Request-ID
X-Device
X-DDC-Arch-Trace
X-Safe-Firewall
X-Spip-Cache
Served-By
Liferay-Portal
Server-Timing
X-Dw-Request-Base-Id
X-Hyper-Cache
X-VCache
X-Cloud-Trace-Context
Ali-Swift-Global-Savetime
Front-End-Https
X-Do-Not-Hack
X-HeyJason
X-Microcache
Permitted-Cross-Domain-Policies
X-Original-Date
P-LB
P-WS
Surrogate-Control
X-TNCMS
X-Loop
X-LiteSpeed-Cache-Control
X-RateLimit-Remaining
X-RateLimit-Limit
X-Sol
Display
X-Middleton-Display
X-Servedby
X-StackifyID
X-Middleton-Response
Response
X-Acc-Exp
X-OneAgent-JS-Injection
X-Jimdo-Wid
X-Jimdo-Instance
X-RateLimit-Reset
X-Cluster-Node
X-Clacks-Overhead
X-Wix-Punisher
X-FB-Debug
X-Kinsta-Cache
Content-Style-Type
X-Firenze-Processing-Times
Content-Script-Type
X-Vtex-Processado-Em
X-DNS-Prefetch-Control
Public-Key-Pins
X-Debug-Info
X-Tumblr-Pixel-6
X-Shopid
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Featureset
X-Shardid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Sorting-Hat-Podid-Cached
X-Age
X-Amz-Version-Id
X-Goog-Hash
X-HOST
X-XN-XNHTML
X-XN-Trace-Token
Refresh
Fpc-Cache-Id
X-DynaTrace-JS-Agent
X-Cached
X-User-Agent
X-Magento-Tags
X-Ruxit-JS-Agent
X-Zen-Fury
X-Cache-Config
X-N-OperationId
PageSpeed
X-Hostname
X-Px
X-Version
Wpe-Backend
X-WebKit-CSP
X-LW-Cache
Retry-After
X-Url
Feature-Policy
Xkey
X-Generated-By
X-Handled-By
X-Goog-Generation
X-Goog-Storage-Class
X-Frame-Option
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Topify-Platform
X-Edge-Location
X-Upstream
X-MiniProfiler-Ids
Rt-Fastcgi-Cache
X-FORWARDED-FOR
Allow
X-Source
Access-Control-Request-Method
Fastcgi-Cache
TCN
X-Request-Time
X-B-Cache
X-EdgeConnect-Origin-MEX-Latency
X-Loopia-Node
X-Whom
X-CMS-Version
X-ET-API-VERSION
X-ET-API-ROOT
X-ET-API-ORIGIN
X-EdgeConnect-MidMile-RTT
X-URLSCHEME
X-Cached-By
Product
X-Outils-CS
Powered
ServedBy
Last-Published
X-RESOURCE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Content-Options
Warning
X-Platform-Router
X-Guploader-Uploadid
X-Platform-Cluster
X-Platform-Processor
X-AspNetWebPages-Version
X-Fastcgi-Cache
X-Accel-Expires
X-CacheServer
X-Powered-By-VTEX-Janus-ApiCache
No
X-Vtex-Remote-Cache
X-Magento-Cache-Debug
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processed-At
X-VTEX-Janus-Router-Backend-App
X-Tec-Api-Origin
X-Tec-Api-Root
X-Application-Context
X-Location-Id
X-Tec-Api-Version
X-From
Public-Key-Pins-Report-Only
X-Engine
X-Signature
Fhost
X-Varnish-HitMiss
X-Varnish-Count
X-Cache-Key
X-Varnish-Host
X-Umbraco-Version
X-Developer
X-Returned-From
X-Returned-From-DLL
X-Original-Request
X-Passed-To-DLL
X-Passed-To
X-Actual-URL
X-DynaTrace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-NWS-LOG-UUID
X-Varnish-Beresp-Grace
X-Varnish-Cache-Hits
Dmn
X-Stale
X-Microcachable
X-Response-Time
X-Platform-Server
X-Cache-Info
X-F-Cache
X-Ezoic-Cdn
X-URL
X-LBLID
Cache-Provider
Pagespeed
Generator
X-Returned-From-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
Cache-Key
X-Defender
X-Shop-Id
X-Platform
Host
X-Device-Type
X-UD-Method
X-ApacheServer
Imagetoolbar
X-Gateway-Cache-Status
X-HS-Content-Campaign-Id
X-PERF
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-S
Origin
X-Sapient
X-Micro-Cache
X-ARC
Surrogate-Key
Alternate-Protocol
X-Hosted-By
Version
X-I-Sp
Arr-Disable-Session-Affinity
X-Recruiting
X-SO
X-Cache-Rule
X-BS
Content-Hash
Akamai-IP
X-SSLUpstream
X-Lambda-Id
X-Dns-Prefetch-Control
X-SSLProxy
DynaTrace
X-Msg-2-Log
X-Cache-Namespace
X-Translation
X-Microcache-Status
X-Forwarded-For
X-Powered-By-360WZB
X-Platform-Cache
X-App-Status
X-Via-JSL
MIME-Version
X-Track
X-Akam-SW-Version
X-Cache-Age
X-Supported-By
X-SVR-IIS
X-Magento-Cache-Control
X-Svr-Proxy
X-Rnd
WZWS-RAY
X-DealerOn
X-Dealeron-Backend
X-Instart-Request-ID
X-Dealeron-Original-Url
SSPAppContext
X-Powered-By-VelaWeb
X-Correlation-Id
USPLoggingUUID
X-Powered-By-VTEX-Janus-Edge
X-Environment
X-Duration
X-Server-Upstream
X-NetCat-Version
X-Cache-TTL
X-SSL-Cipher
X-Director
S-Cnection
Node
X-Page-Cache
X-Hypernode
X-SSL-Protocol
Content-Disposition
X-Art-Request-Id
X-Acquia-Application-UUID
X-Cache-Tags
Edge-Control-Message
Pool
RTSS
X-Expires-Orig
X-Dispatcher
X-Abgroup
X-App-Hosting
X-CSRF-Protection
X-Matrix-Server
Accept-Encoding
X-Rocket-Nginx-Bypass
X-Storage
X-Matrix-Proxy
X-LB-Node
X-Edge-IP
X-Server-ID
X-ServerName
X-Cache-Control-Orig
X-TransIP-Balancer
SN
X-Correlation-ID
X-Last-Modified
X-TransIP-Backend
X-Server-Id
X-Cache-Debug
X-Generated
X-Varnish-Cacheable
X-Debug
X-Cache-Lifetime
X-Cache-Handler
X-ORACLE-DMS-ECID
X-Drupal-Cache-Tags
X-Daa-Tunnel
X-Hiawatha-Cache
X-Revision
X-SV-FromDBCache
X-SV-Nginx-Duration
X-NoCache
X-SV-Edge
X-Vcap-Request-Id
Wsr-Cache
X-SV-CreatedAt
X-SV-Duration
X-SV-Cacheable
X-SV-Expires
X-SV-CacheTags
X-SV-Pid
X-Cache-Server
FAI-W-FLOW
Update-Time
SiteSpeed
X-Grace
Src-Update
X-Front
X-VARITI-CCR
X-Dispatch
X-Gamma-Serve
Req-Id
X-Rocket-Nginx-Serving-Static
Powered-By-ChinaCache
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-Client-IP
X-Now-Id
X-LB-Server
Content-Encoding-Handler
X-Geo-Country
X-Varnish-RemainingTTL
X-Varnish-RemainingLife
X-Varnish-Seen-By
X-CJ-Soft
Contao-Page-Layout
X-Sucuri-ID
X-Ttl
X-I
X-SRV
Https
X-ATG-Version
X-Vhost
X-Amz-Meta-S3cmd-Attrs
X-Cache-Only-Varnish
ServerID
X-GUploader-UploadID
X-SDS
X-Cache-Level
X-Discourse-Route
X-Litespeed-Cache-Control
X-Flow-Powered
X-Drupal-Cache-Contexts
X-Env
X-Cache-Operation
Cache
X-Route-Server
X-Sucuri-Cache
Lsrequestid
X-Varnish-TTL
X-Content-Type-Option
X-Firenze-Processing-Time
Cneonction
X-Pressidium-NinukisWP-Ver
X-Locale
X-Varnish-IP
X-Esi
X-GeoIP-Country-Code
X-TransIP-Reserved
X-Cache-Engine
X-TTFB
X-SmugMug-Values
X-Varnish-Backend
X-SmugMug-Hiring
X-Content-Encoded-By
X-TTFB-L
X-Country-Code
X-Cache-Type
Smug-CDN
X-Forwarded-Proto
X-Twitter-Response-Tags
X-Transaction
X-Connection-Hash
X-Cache-Expires
X-Trace-Id
X-Webkit-CSP
W
X-Server-Instance
Strikingly-Cache-Region
X-Unbounce-PageId
Cache-Tags
Backend
Strikingly-Cached-Version
X-Litespeed-Cache
X-Varnish-Age
X-Magnolia-Registration
X-Amz-Rid
X-Unbounce-VisitorID
X-Unbounce-Variant
Strikingly-Cached
X-IsCacheURL
X-Speed-Cache-Key
X-Cache-Control
X-Time
X-FIRSTBase
Service-Worker-Allowed
Author
X-Speed-Cache
X-Varnish-Url
X-Service-Id
MC
X-SRCache-Key
X-N
Pv
X-Always-Cache
If-Modified-Since
X-GeoIP-Country-Name
X-Acquia-Application-Trace
Server-Name
Section-Io-Id
X-ID
AMF-Ver
SEOMOZ
X-Cache-Device-Type
MJ12bot
ServerName
X-Akamai-Device-Characteristics
X-BackendServer
X-Akamai-Device-Model
S
X-Url-Base
Content-MD5
X-Cookie-Domain
Location
Custom-Header
X-TTL
From-Origin
X-LB
X-ORACLE-DMS-RID
X-Origin
X-Middleware-Start
X-Dynamic-Cache
Page-Completion-Status
X-PwB-Node
Fw-Via
X-Storage-Cache-Expires
X-Config-Blacklist-Version
X-Varnish-Server
X-Storage-Cache-Date
Use-Proxy
X-Symfony-Cache
X-Storage-Cache
X-Yadis-Location
PICS-Label
X-CF-Passed-Proto
X-UPSTREAM
X-High-Performance
X-Varnish-Retries
X-Amz-Meta-Content-Md5
X-Content-Age
NnCoection
X-Xrds-Location
NetMindSessionID
X-Real-Server
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-ServerID
X-Pantheon-Environment
X-Pool
X-CDN-Forward
Ohc-File-Size
X-CacheFROM
X-Pantheon-Phpreq
X-Browser
X-Pantheon-Site
X-FTR-Request-ID
X-Key
Surrogate-Key-Raw
Proxy-Connection
X-Now-Cache
Xc-Version
Tracecode
X-Nitro-Cache
Srv
Qs-Cache
X-HW
X-Srv
X-Cache-PageType
X-Amz-Storage-Class
X-NginX-Cache
FindLaw
Drupal-Pagecache-Memcache
Nodo
X-Content-Security-Policy-Report-Only
X-Cache-Fix
X-BKSrc
X-Empowered-By
X-Nbs
X-Processing-Time
X-Vip
X-VC-Enabled
Prama
X-Varnish-Hits
X-Worker
X-Cache-Miss-From
X-Sedo-Request-Id
X-FW
Access-Control-Allow-Method
IM-Version
X-Varnish-Ttl
Hummingbird-Cache
X-Shard
X-Frontend
Pics-Label
X-Id
X-Drectory-Script
Cached
X-SP-UniqueName
X-RequestId
Dtk-Cache-Check-0
X-Proxy
X-RealServer
X-SP-Farm
X-Runtime-Memory
X-Nginx-Cache
Content-Transfer-Encoding
Ramp
X-Runtime-Rack
X-Ratelimit-Remaining
X-Ratelimit-Limit
X-Cache-CFC
X-Disney-Akamai-Rule
X-Orig-Vary
X-Pagename
HAVer
Noq
Content_type
Ram
X-Location
HCVer
X-Hit-Cache
IBM-Web2-Location
Swift-Performance
X-TB-M
X-Shield-Request-Id
X-WPL-DATA
X-Distributor
RequestId
CacheControlHeader
X-Varnish-ID
X-Stage
Front
X-JSESSIONID
Cm-Server
X-NginX-Server
Local-Info
X-Real-IP
X-Unique-ID
X-Avg-Cookie-Expires
X-Akamai-Edgescape
X-AVG-Country-Code
X-Redman-Final-Url
A-Powered-By
X-Redman-Backend
X-App
SRV
X-Rq
X-CB-Server
Edit
X-A
X-4ormat-Cacheable
X-Analytics
X-Resource
X-Cache-2
Access-Control-Request-Headers
Accept-Charset
X-Yottaa-Metrics
X-App-Runtime
Backend-Timing
Web-App-Origin-Name
X-Yottaa-Optimizations
X-ClientSide-Caching
X-LP
Accept-Language
X-GoCache-CacheStatus
X-Proxy-Backend
X-Span
X-Runtime-Affili
X-Hstore
X-PRAM
X-Force
X-Generated-Timestamp
X-Request-Uri
X-Hrouter
X-FireWall-Port
X-VC-TTL
X-Domain-Checked
X-Path-Route
X-ServerIndex
X-Fedora-School-Id
X-Remote-Addr
Identity
X-CAPServer
X-Varnish-Hostname
X-Backend-Status
X-Atraveo-Zone
X-Culture
Frame-Options
X-Rule
X-Vcache
X-CLOUD-TRACE-CONTEXT
WWW-Authenticate
X-ARRServer
SVR
X-PF-Uncompressing
X-App-Server
X-E
X-Provisioner-Version
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
X-Atraveo-Varnish-Server-Id
X-Atraveo-TTL
X-Atraveo-ETag
X-Atraveo-Cache-Control
X-AF-Userserver
X-Source-ID
Server-Info
X-Dw-Trace-Id
Nginx-Cache
X-Appmachine-Environment
Cmsid
Cmstype
X-Role
X-Purge-URL
XDomainRequestAllowed
X-Purge-Host
Lookup-Cache-Hit
Proxy-Agent
X-Agent
X-Distil-CS
X-IIJ-Cache
X-Jphone-Copyright
Cteonnt-Length
X-Debug-Token
X-CacheDebug
Beyond-Iis
X-Sys-Req-ID
X-Ratelimit-Reset
Environment
X-Varnish-Debug-TTL
X-Pantheon-Az
X-NWS-UUID-VERIFY
X-Varnish-Debug-Age
X-Session-ID
Request-EU
Request-Country
X-Dev
X-Processed-By
AsisCache
Lb
X-Cacheable-TTL
X-ESI
X-Cms-Mode
X-RiS-UFDI
X-SE-Debug
SHInfo
Url
X-Forwarded-Host
Worker
X-VCS-Ttl
X-WR-MODIFICATION
X-Cache-Ttl
X-CACHE-TTL
X-Frames-Options
X-VCS-Cacheable
Firespring-Website-Id
X-Server-IP
WP-FROM-CACHE
X-Nginx-Host
Upgrade-Insecure-Requests
CS-SERVER
X-Detected-Device
X-JG-Page-Cache
X-AEM
X-Client-Image-Vid
X-EPiphany-Vid
X-V
X-GeoIP
X-Map-Context
ServerTokens
ServerSignature
X-Req-Head-Response
X-Webstats-RespID
X-Consent-Required
X-Ms-Request-Id
CLMOB
Referer
X-Client-Vid
X-DataDome
Accept-CH
X-Balanceador
X-HeBS-Cache-Status
Eomportal-Instance
AR-CACHE
AR-PoweredBy
Arrnode
AR-SID
AR-ATIME
BALANCEDTO
X-HA-Frontend
X-CacheLoc
Disablevcache
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
X-Block-RuleID
Num
X-Block-Rule
X-ACMCache
X-Actindo-Thread-Id
X-TKP-SRV-ID
X-Oferteo-Domain
X-SERVER-NAME
X-Adnet
Dispatcher
X-Amcomm-Site
Cleartype
X-Actindo-Rs
VANITY-HOST
X-Via-S
X-Soro
X-Data-Request
X-Actindo-Request-Id
X-HashTwo
Myheader
IISExport
X-Cache-Doesi
X-B2f-Not-Route
X-Plat
X-Info
X-AOL-HN
X-Aramark-SID
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
Resin-Trace
X-Domino-CacheValidationWithETagReason
Machine
X-Batcache
X-Resolver-IP
X-Domino-CacheValidationWithETagResult
X-Varnish-Cache-Local
X-SAPP
Traffic-Origin
Home
EagleEye-TraceId
Access-Control
X-Proxy-Cache-Control
X-WebNode
Ufe-Result
Il-Cl
Proxy-Cache
Thanks
Play-Detected-UserAgent
Play-Detected-Device
X-Ghost-Cache-Status
X-HA-Backend
X-Header
AETN-Country-Code
AETN-Continent-Code
AETN-Country-Name
AETN-DEVICE
AETN-EU
AETN-City
IES-Server
X-PBY
X-Clara-ASAP
AETN-Area-Code
Load-Balancer
X-Cocoon-Version
X-Resty-Request-Id
X-Framework
AKA-DEVICE
X-Upstream-Backend
X-Upstream-Status
*
X-GSL-Server
AETN-State-Code
Edgecast
X-Session-Reinit
AETN-Latitude
AETN-Longitude
AETN-Postal-Code
X-WR-Flags
X-CacheID
X-Confluence-Request-Time
Server-ID
X-Amz-Id-1
X-LW-Web-Server
X-HTML-Minification-Powered-By
X-ASAP-Cache
NtCoent-Length
X-Smartcache-Keys
Copyright
COMMERCE-SERVER-SOFTWARE
X-Proxy-Skip
Dynatrace
X-Smartcache-Timeout
X-OpenCart-Lightning
X-WP
X-Dynatrace
Adm-Server
X-Varnish-URL
Bios
X-Adobe-Loc
X-HydroSheep
X-Reflector
X-Reflector-Cache
X-HostName
Now
X-Highwire-Smart-Code
X-Adobe-Content
X-Upgrade-Enabled
X-Highwire-Sitecode
X-Now-Trace
X-Flex-Tag
X-MainProfileURL
X-Beatles
X-WebKit-CSP-Report-Only
Ttl
Fastly-Backend-Name
X-Generated-Time
X-Cache-Time
X-Flex-Lastmod
X-Depends
X-Blog
X-Custom-Name
VAR-Cache
MageStack-Cache-Hits
Fastly-Debug-Digest
X-UA-Bot
X-MCB-Server
X-Flex-Evstart
X-Protected-By
From
X-Flex-Evend
X-Flex-Community
Magicmarker
HitType
X-Flex-Tags
AC-ELC
X-Timestamp
X-Autoru-Host
X-DN-Cache-Control
X-AutoRu-App-Id
X-UnsetCookies
MageStack-Cache
X-Status
X-MainProfileName
X-Flex-Lang
MageStack-Area
X-Secret
X-Refresh
X-Amzn-Trace-Id
X-Amzn-RequestId
X-Middleton-PageSpeed
X-MainProfileCategory
Pf.Web.Request.Id
X-Say-TTL
X-Say-Cacheable
X-Nx-All
X-Amz-Apigw-Id
X-MainProfileID
MageStack-Tag
MageStack-PageSpeed
Max-Age
MageStack-Web-Node
Viewport
X-WEBMGR-CACHE
X-LBPoolMember
X-SayCDN-TTL
X-Nx
CDN-RequestId
X-Directory-Script
Paypal-Debug-Id
CDN-PullZone
CDN-CachedAt
WP-AdvCache-MemCached
CDN-Cache
Dis-Env
X-Server-Addr
CDN-Uid
X-Garden-Version
X-SH-Cache-Status
Prot
X-DynamicCache
DNNOutputCache
X-Beget-Proxy
Aurora-Node
MageStack-Magento-Version
MageStack-Loadbalancer
X-Goog-Meta-Policy
X-Goog-Meta-Replace
X-RiS-PX
X-Goog-Meta-Goog-Reserved-File-Mtime
MageStack-Cache-Status
TC-Cache-U
TC-S-Cache
TC-S-Cache-M
Id
Pragrma
X-Gyrobase-Publication
MageStack-Cache-Lifetime
X-Fastly-Request-Id
X-Varnish-Id
X-Served-Server
X-Cf-Powered-By
X-Test
TC-Cache-IC
TC-Cache
MageStack-Cacheable
Filters
ServerNode
MageStack-Config
PServer
MageStack-Debug
X-Cache-Detail
X-Envoy-Upstream-Service-Time
X-ETag
X-SmartBan-URL
X-Requestid
X-Application
X-SmartBan-Host
X-Origin-Date
X-Highwire-RequestId
X-Highwire-SessionId
Provider
X-APIVERSION
Serverid
ViewMode
VSID
X-Appid
X-Varnish-Ip
X-Serv
X-SV
Server-Ip
X-FORWARDED-PROTO
X-Gateway-Rate-Limit-Delayed
X-DB-Content-Length
X-FastCGI-Cache-Status
CommunityServer
Pramga
X-Via-NSCOPI
X-Cache-Me-Harder
X-Access-Control-Allow-Origin
X-Deity
X-Served
X-Tag-Playlist
X-SDE-Name
X-Rack-Cors
X-ENDPOINT
X-ORIKEY
X-ROUTING
X-Varnish-Debug-Hits
X-APIAUTH-VAL
X-IP
NODE
NLCacheNote
Report-To
X-TLS-Version
X-Appversion
VServer
X-Akamai-Transformed
X-Hosting-Env
Web
X-RAMCache
X-Pj-Cache-Status
Device
BackendServer
CF-Worker-Script
X-Vary-Options
X-MyName
Ssl-Proxy-Server
X-NewsFlow-Sitename
X-PBS-Appsvrip
X-PBS-Appsvrname
X-SCM-Server-Number
X-Rewritten-By
X-NodeID
SINA-TS
X-Cache-FS-Status
X-Powered-By-ADS
X-Instance-Id
X-PBS-Fwsrvname
AMP-Redirect-To
X-Svr
X-Skip-Cache
Yoncu-Errno
Access-Control-Allow-Header
Ibf5scheme
X-SilverStripe-Cache
X-Reqid
X-Desc
X-W3TC-Minify
X-Geo-IP
X-MAT-GEO
SINA-LB
Nitro-Cache
X-WN-ClientGroup
X-V-Cache
Amfplus-Ver
X-Cache-Node
X-CH-Device
X-BPool-Back
X-Search-Id
X-Build-Id
X-MID-Host
X-Airee-Node
X-ProBase-Server
X-PM-ID
X-Pass-Through
X-ManagedFusion-Rewriter-Version
Session-Id
X-Node-Id
X-MrHost
X-Webcelerate
Provided-Host
X-Gannett-Site-Version
X-Mighty-Proxy
X-Max-Age
X-BServer
X-Captured
N365rili
X-7d-Instance-Id
X-Obvious-Tid
X-Obvious-Info
X-Varnish-Grace
X-FPC
X-Lb
X-Client-Id
X-ACCELERATE
ServerIP
X-Webkit-Csp
Session-From
Debug-Status
Tk
ScoreTracker
X-Lw-Cache
X-Page
X-Nginx
X-We-Are-Hiring
X-XHTML-Minification-Powered-By
X-Avvio-Cms-Cacheload
X-Aramark-CSID
YF-ID
X-Layout
X-Static
X-Title
X-ZSITES-DNS
X-Varnish-Cache-Ttl
Cf-Ipcountry
X-PHP-Response-Code
X-CRA-DC
X-Policy
X-Rebelmouse-Cache-Control
Description
X-Cache-Varnish
X-Cache-On
X-7d-Trace-Id
Purge-Cache-Tags
Hit-Count
X-Bip
Keywords
Og
X-Beluga-Trace
X-Beluga-Status
X-Test-Debug
X-DevSrv-CMS
X-Streams-Distribution
X-Beluga-Response-Time-X
X-Beluga-Response-Time
Ohc-Response-Time
X-Beluga-Cache-Status
X-Beluga-Node
X-Beluga-Record
X-Src-Webcache
Response-Time
X-Who
X-M-Log
X-Cache-TTL-Current
X-Shopware-Allow-Nocache
X-Global-Transaction-ID
X-Route
X-Proto
NZSpeedy
Page-Template
X-Instance
X-NoIndex
X-Origin-Cache
X-Cache-TTL-Age
DrivedBy
X-B3-Sampled
X-Varnish-Backend-Beresp-Backend
RN-Server
X-Backside-Transport
GranicusServer
X-Rack-CORS
X-Firefox-Spdy
EN-User
StatusCode
X-Node-App
X-Built-With
X-FromPodPressCache
X-EC2-Instance-Id
X-Cache-Warmer
Hosted-By
X-RemovedCookies
X-Ms-Version
X-ReqId
X-AMAZEEIO
NGX
X-Nginx-Request-Processing-Time
X-ProcessESI
X-Proxy-Cache-Key
Server-Id
X-Proxy-Server
X-Origin-Server
SB-Site-IE-VERSION
SB-Site-Device
X-Qnm-Cache
X-Server-Generated
X-Enhanced-By
X-Now-Instance
X-M-Reqid
SB-Cache-Life
X-Vol-Correlation
X-Custom-Header
SB-Cache-Remaining
X-Wodby-Node
X-Vol-Mrp
HTTPS
X-Shopware-Cache-Id
X-Processed
REFRESH
X-This-Proto
Tempo
X-Cache-LB
X-Cname-TryFiles
X-M
AMP-Access-Control-Allow-Source-Origin
PBS
X-HA
MageStack-Cache-Lifetime-Sent
X-Powered-By-Home.Pl
MS-CV
MageStack-Last-Modified
CDCHOST
MageStack-Cache-Warning
WN
X-PROCESSED-BY
X-CACHE-KEY
X-RENDER-TIME
X-Oracle-Dms-Ecid
X-Cdn-Forward
X-Geo
X-Sid
X-Mobilized-By
X-Scheme
X-Actual-Url
X-Xml-Http-Blocked
X-DEBUG
X-COUNTRY-CODE
SERVER-ID
X-Compress-Hint
Language
OracleCommerceCloud-Version
X-Nginx-Page-Cache
ProxiaInstanceId
X-Ssl-Cipher
X-CorrelationId
VC-NoCache
X-Pagely-Cache
X-NMT-Proxy
X-Meta-MSThemeCompatible
X-Appmachine-Duration
Gzip
X-Appmachine-Name
X-Cache-HT
X-Appmachine-CreatedOn
Fastly-Restarts
X-Ruxit-Js-Agent
X-Serverid
X-WA-Info
OracleCommerceCloud-Sandiego
X-CloudBurst-Cache
X-KoobooCMS-Version
X-JoinUs
X-From-Cache
X-Machine
WebServer
X-Hit
X-Middleton-Pagespeed
X-ASAP-Age
X-Container
X-FG-RequestId
X-Instance-Name
X-Healthy
X-Catalyst
X-RequesterIP
MwpReleaseVersion
X-Server-Ip
X-Meta-Imagetoolbar
Returned-Status
X-Meta-MSSmartTagsPreventParsing
X-Firewall
X-Bitrix-Composite
X-Old-Content-Length
MachineName
PROGMA
X-Pageid
X-CSRF-Token
X-Expires
X-Magento-Route
X-SG-Server
X-No-Session
X-CAMPUSSUITE-TENANT
X-CAMPUSSUITE-ENVIRONMENT
X-CloudBurst-Frontend
EQ-Cache
PagesDisplayed
V-Cache-Ttl
X-CAMPUSSUITE-DEBUGGING
X-CloudBurst-WordPress
Generate-Time
X-Fastly-Backend-Reqs
X-UT-Cache
Fastly-Drupal-Html
Origin-Vm
RSL-Trace-ID
X-Country
X-Time-Spent
X-Front-Cache
X-Accel-Cache-Control
Prototype-RootPath
X-Itkg-Cache-Tags
X-SSLTerm-Server
X-TEST
X-ENV
X-Tradeindia-Request-GUID
X-Grid-Server
X-Beresp-Ttl
X-InDy-Memory
X-InDy-Query
X-Mobile-Rewrite
X-InDy-Time
PB-RID
PB-PID
X-Varnish-Age-Debug
X-Optimization
X-Varnish-TTL-Debug
Amp-Access-Control-Allow-Source-Origin
LB
F5-IpCliente
X-Origin-Upstream-Status
X-Cache-Id
Servername
X-Enabled1
MSThemeCompatible
X-Enabled3
X-Enabled2
Ews
X-Tradeindia-SMgmt
X-Router
X-ORIGN-SERVER
X-Telligent-Evolution
ClientIP
X-Vid
X-GZip
X-Bcwwwid
X-Compressed-By
X-Cluster
X-FastCGI-Cache
X-Cache-ID
X-Boot
X-Log
X-Cache-Extended
X-Cache-Action
HitInfo
FRONT-END-SECUREBROWSER
HSTS
TP-Cache
X-Box
TP-L2-Cache
X-Oracle-Dms-Rid
X-Qiniu-Zone
Webserver
Web-Server
X-CloudBurst-Backend
X-Served-From
X-DDM-SERVER
X-Clx-Request
Unique-Request-Id
SBSS
X-VHosting-Cache
ID
X-Varnish-Cache-Control
Content
Requested-Host
X-OPNET-Transaction-Trace
SS
X-Mobile-Device-Type
X-Zendesk-Origin-Server
X-Mobile-Device
X-Built-By
X-Debug-Message
X-Dck
X-Transaction-Name
X-SEA-Instance-Name
X-PressLabs-Stats
FastCGI-Cache
X-SCProxy
X-Cachable
X-Zendesk-User-Id
X-BeResp-Ttl
X-Content-Type
X-Render-Time
X-HS-Status
Cache-Status
X-Navigation-Version
X-SSL
X-Olaf
X-HP-CAM-COLOR
X-D2id
X-Az
X-UPSTREAM-Address
X-Amz-Meta-Version-Id
X-Activity-Id
Sl-Pgid
X-DDM-SERVER-UPDATED
X-MSU-SOURCE
X-CGP
X-Cdn-Origin
X-Cache-Via
X-Fpc
X-Homeaway-Requestmarker
X-HAProxy
X-Batcache-Reason
X-BIT-Node
Request-Time
Progma
TYPO3-Pid
TYPO3-Sitename
X-Abuse
X-Ser
X-Jcms-Ajax-Id
X-MCF-ID
Xc
X-XHR-Current-Location
Arrow-RequestId
CmsfirstPublishTimestamp
Httpd-Identifier
CommercePlatform-Version
X-Varnish-Cached-TTL
X-Varnish-Cached
X-Ruby-Cluster-ID
X-NginX-Upstream
X-ServiceProvider
X-Sn-Servicetimems
X-UPServer
NKBVHEADER
ModuleCacheType
X-SuperCache
X-Rocket-Nginx-Reason
X-UType
X-Varnish-Action
XX
X-VG-WebCache
X-Rocket-Nginx-File
X-Response
X-Phpwcms-Release
X-Phpwcms-Page-Processed-In
X-PoweredBy
X-Proxy-Id
X-Requested-With
Backend-Powered-By
BlockPHPCallEnd
HA-Host
HA-Georegion
HA-Ipaddr
HA-Servedtime
L5d-Success-Class
HA-Urlpath
HA-Geolon
HA-Geolat
DB-Nickname
Content-Sn
HA-Cloudapp
HA-Geocity
HA-Geocountry
MSSmartTagsPreventParsing