Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
X-AspNet-Version
P3P
X-Pingback
Age
Content-Language
X-UA-Compatible
Via
Access-Control-Allow-Origin
Expect-CT
Upgrade
X-Adblock-Key
X-Varnish
P3p
X-Cacheable
Content-Security-Policy
X-Template
X-Check
X-Language
X-Generator
X-Buckets
X-Drupal-Cache
X-Request-Id
X-AspNetMvc-Version
X-Type
X-Cache-Group
X-Pass-Why
X-Hacker
X-Ac
X-Powered-By-Plesk
X-Cache-Hits
Alt-Svc
Content-Location
X-Permitted-Cross-Domain-Policies
X-Runtime
X-FRAME-OPTIONS
X-Download-Options
X-Xss-Protection
Host-Header
MS-Author-Via
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId
X-Dc
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-IPLB-Instance
X-Powered-CMS
Cartoon
X-UA-Device
X-Served-By
Status
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Via
X-Amz-Cf-Id
X-Iinfo
X-Cache-Status
X-Backend
X-ServedBy
X-Timer
X-Contextid
CF-Cache-Status
X-PC-Key
X-PC-Hit
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-DIS-Request-ID
Powered-By
X-Mod-Pagespeed
X-Request-ID
X-CST
X-PC-Host
X-PC-Date
X-PC-AppVer
Content-Encoding
X-Logged-In
Keep-Alive
X-Rid
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Host
X-CDN
X-Cache-Hit
X-Tumblr-Pixel-1
X-Port
Referrer-Policy
X-Server
X-Tumblr-Pixel-2
X-Server-Powered-By
X-Robots-Tag
X-Cache-Enabled
X-Wix-Server-Artifact-Id
X-Nginx-Cache-Status
X-Endurance-Cache-Level
X-Accel-Version
X-Seen-By
X-Wix-Request-Id
X-Wix-Renderer-Server
X-Page-Speed
WP-Super-Cache
X-Turbo-Charged-By
X-Pad
X-Wix-PunisherID
X-Drupal-Dynamic-Cache
X-Content-Powered-By
WPE-Backend
X-Tumblr-Pixel-3
X-Forwarded-For
Content-Security-Policy-Report-Only
X-Content-Digest
X-Forwarded-Proto
X-Varnish-Cache
X-Rack-Cache
X-AH-Environment
X-Proxy-Cache
Surrogate-Key-Raw
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
SPRequestGuid
X-SharePointHealthScore
X-GitHub-Request-Id
MicrosoftSharePointTeamServices
X-MS-InvokeApp
X-Request-Country
X-Cnection
X-Original-Date
X-LiteSpeed-Cache
X-XRDS-Location
Edge-Control
X-Cache-Lookup
Timing-Allow-Origin
X-FullPageCaching
Cf-Railgun
X-Safe-Firewall
X-Amz-Request-Id
X-Amz-Id-2
MicrosoftOfficeWebServer
X-Died
Request-Id
Charset
X-Webserver
X-FW-Hash
X-FW-Static
X-FW-Type
X-FW-Serve
X-PhApp
X-SERVER
X-Content-Security-Policy
Edge-Cache-Tag
X-Node
SPIisLatency
X-INKT-SITE
X-INKT-URI
SPRequestDuration
X-HS-Cache-Config
X-HS-Content-Id
X-Hits
Composed-By
X-Tumblr-Pixel-4
Access-Control-Max-Age
Liferay-Portal
Fastly-Debug-Digest
X-CF-Powered-By
Grace
Served-By
X-Swift-CacheTime
X-Swift-SaveTime
X-Firenze-Processing-Times
Content-MD5
X-Newrelic-App-Data
EagleId
X-Spip-Cache
X-Hyper-Cache
X-BC-Stapler
Access-Control-Expose-Headers
Request-Context
X-CDN-Pop-IP
X-CDN-Pop
Rating
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Server-Name
X-WPE-Loopback-Upstream-Addr
X-Device
X-Backend-Server
X-Fastly-Request-ID
X-PHP-Backend
X-Dw-Request-Base-Id
X-Microcache
X-Tumblr-Content-Rating
X-VCache
X-RateLimit-Remaining
Refresh
X-RateLimit-Limit
X-ServerName
Content-Style-Type
X-RateLimit-Reset
X-FB-Debug
Content-Script-Type
X-Jimdo-Instance
X-Jimdo-Wid
X-User-Agent
X-Clacks-Overhead
X-TNCMS
Real-Hostname
X-Loop
X-Cloud-Trace-Context
Public-Key-Pins
X-Cache-Config
Front-End-Https
X-XN-Trace-Token
X-XN-XNHTML
Surrogate-Control
X-Acc-Exp
X-DDC-Arch-Trace
X-Hostname
X-Age
Xkey
Fpc-Cache-Id
X-Tumblr-Pixel-5
X-N-OperationId
X-Generated-By
PageSpeed
X-Cached
X-Px
X-DNS-Prefetch-Control
X-Middleton-Display
X-Sol
X-Middleton-Response
Display
Response
X-SS-Location
X-SS-Conf
X-LiteSpeed-Cache-Control
X-WebKit-CSP
X-StackifyID
X-MiniProfiler-Ids
X-Topify-Platform
X-Cached-By
X-Request-Time
X-CMS-Version
X-Zen-Fury
Surrogate-Key
X-Url
X-Content-Options
X-Outils-CS
TCN
X-DynaTrace-JS-Agent
X-URL
X-Whom
X-ApacheServer
X-PERF
Rt-Fastcgi-Cache
X-Microcachable
X-Handled-By
X-DynaTrace
X-Amz-Version-Id
X-Pantheon-Site
X-Pantheon-Phpreq
X-Pantheon-Environment
Access-Control-Request-Method
X-Kinsta-Cache
X-FORWARDED-FOR
Product
Edge-Control-Message
Imagetoolbar
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-AspNetWebPages-Version
Host
X-Umbraco-Version
Alternate-Protocol
ServedBy
X-Varnish-TTL
X-Magento-Tags
X-Trace
X-OneAgent-JS-Injection
X-HS-Combine-CSS
X-Tumblr-Pixel-6
P-LB
X-Engine
DynaTrace
P-WS
X-LBLID
Fhost
X-HOST
X-Varnish-Cache-Hits
Powered
X-Cache-Rule
X-Correlation-Id
X-Ruxit-JS-Agent
X-NWS-LOG-UUID
X-CacheServer
Generator
X-Actual-URL
X-RESOURCE
X-B-Cache
X-Goog-Hash
X-Track
X-From
WZWS-RAY
X-Location-Id
X-Micro-Cache
X-Returned-From-DLL
X-Powered-By-360WZB
X-Returned-From
X-Passed-To
X-Passed-To-DLL
X-Original-Request
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Edge-Location
X-Varnish-Beresp-Grace
X-Hosted-By
X-Recruiting
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Fastcgi-Cache
X-Stale
X-Returned-From-BeforeDispatch
X-URLSCHEME
X-Vtex-Processado-Em
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-Powered-By-VTEX-Janus-ApiCache
No
X-VTEX-Cache-Status-Janus-ApiCache
Arr-Disable-Session-Affinity
X-Instart-Request-ID
Fastcgi-Cache
X-Developer
Public-Key-Pins-Report-Only
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Varnish-Host
X-Powered-By-VTEX-Janus-Edge
X-Cache-Age
X-Msg-2-Log
Origin
X-Application-Context
X-I-Sp
X-Accel-Expires
X-BS
X-Source
Dmn
X-Shop-Id
X-Cache-TTL
X-Defender
X-App-Hosting
X-Matrix-Server
X-LB
X-Matrix-Proxy
Akamai-IP
X-Internal-ReqID
X-Rocket-Nginx-Bypass
X-Platform-Router
X-Server-ID
X-Debug-Info
X-Platform-Processor
X-Platform-Cluster
X-NetCat-Version
X-UD-Method
X-Response-Time
X-Cache-Info
X-Cdn
X-Upstream
X-Art-Request-Id
X-Platform
X-Version
X-TransIP-Balancer
Pool
X-VARNISH-Cache
X-Varnish-HitMiss
Content-Hash
Last-Published
X-Varnish-Count
X-LW-Cache
Powered-By-ChinaCache
X-Front
X-Content-Security-Policy-Report-Only
X-Expires-Orig
USPLoggingUUID
X-Gamma-Serve
Version
X-S
X-Device-Type
X-I
X-Daa-Tunnel
X-TransIP-Backend
X-Cache-Operation
IBM-Web2-Location
X-Storage
X-Firenze-Processing-Time
Ohc-File-Size
X-HS-Content-Campaign-Id
X-Page-Cache
Node
X-Signature
X-Varnish-Cacheable
X-Duration
X-Content-Encoded-By
X-UPSTREAM
X-Powered-By-VelaWeb
X-ATG-Version
HTTPS
X-Cache-Debug
Content-Disposition
X-Supported-By
MIME-Version
X-Origin
X-Revision
X-Cache-Tags
X-Director
X-NoCache
X-Hypernode
X-SSL-Cipher
X-Magento-Cache-Debug
X-Server-Upstream
X-Microcache-Status
X-Translation
Srv
X-Cf-Powered-By
X-EdgeConnect-Origin-MEX-Latency
X-SSL-Protocol
X-Cache-Key
X-VTEX-Cache-Status-Janus-Edge
Cache-Key
X-Dispatcher
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-Varnish-Seen-By
X-Platform-Server
X-CJ-Soft
X-TTL
X-Varnish-Age
X-Route-Server
ServerName
X-EdgeConnect-MidMile-RTT
X-PwB-Node
SSPAppContext
X-F-Cache
X-Cache-Control-Orig
X-Client-IP
X-Platform-Cache
X-Vcap-Request-Id
X-Grace
X-Dns-Prefetch-Control
X-SV-Nginx-Duration
X-SV-CreatedAt
X-Abgroup
Pv
X-SV-Edge
X-SV-Pid
X-SV-FromDBCache
X-Dispatch
X-SV-Duration
X-SV-CacheTags
Cache-Provider
Req-Id
PICS-Label
SN
Accept-Encoding
X-SV-Expires
X-SV-Cacheable
Lsrequestid
Allow
X-Cache-Lifetime
X-Lambda-Id
X-Cache-Only-Varnish
X-Flow-Powered
X-Cache-Expires
Fw-Via
X-ARC
FAI-W-FLOW
X-Abuse
X-Akamai-Transformed
IM-Version
Cneonction
Section-Io-Id
X-Akamai-Device-Characteristics
X-GeoIP-Country-Code
X-Loopia-Node
X-Geo-Country
X-LB-Node
X-Debug
X-Country-Code
Proxy-Connection
X-Content-Age
Location
X-Last-Modified
Wsr-Cache
Page-Completion-Status
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-Sucuri-ID
X-ORACLE-DMS-ECID
X-Sapient
X-ServerID
X-Varnish-Backend
X-AOL-HN
X-Cookie-Domain
X-Sucuri-Cache
X-SDS
X-Edge-IP
Accept-Charset
X-Cache-Server
X-FW
X-Cache-Engine
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-IsCacheURL
X-Goog-Stored-Content-Length
X-Worker
Tracecode
X-GUploader-UploadID
X-Proxy
X-PF-Uncompressing
X-Via-JSL
Content-Encoding-Handler
X-SE-Debug
X-Ttl
X-RequestId
X-BackendServer
Edge-Content-Tag
X-Akamai-Device-Model
ServerID
Backend
Author
X-Amz-Meta-S3cmd-Attrs
X-Url-Base
X-Speed-Cache
X-GeoIP-Country-Name
X-Cache-Level
X-Speed-Cache-Key
X-Xrds-Location
X-N
X-BKSrc
X-Browser
X-Nginx-Cache
NnCoection
X-Id
X-Nbs
X-Pressidium-NinukisWP-Ver
X-Config-Blacklist-Version
Server-Info
X-Yadis-Location
X-Varnish-Ttl
If-Modified-Since
HCVer
X-Cache-Type
RTSS
S
HAVer
X-Server-Id
X-Purge-URL
X-Generated
X-Orig-Vary
X-CDN-Cache-Status
Nodo
X-CDN-Node
X-Correlation-ID
X-Magento-Cache-Control
X-SRCache-Key
X-Drupal-Cache-Tags
X-Shield-Request-Id
X-Empowered-By
X-Varnish-Url
X-NB-Cached-Page
X-Cache-CFC
X-ID
X-SO
X-Middleware-Start
Cm-Server
X-Processed-By
X-Yottaa-Metrics
Cache
X-Hiawatha-Cache
X-Time
X-Yottaa-Optimizations
X-Discourse-Route
Nitro-Cache
Content-Transfer-Encoding
X-DealerOn
X-DataDome
Access-Control-Allow-Header
X-Rnd
X-Processing-Time
Frame-Options
Use-Proxy
S-Cnection
Xc-Version
A-Powered-By
X-Powered-By-Server
X-Magnolia-Registration
X-CDN-Forward
AMF-Ver
X-Amz-Storage-Class
Identity
X-Environment
X-Frontend
Magicmarker
X-Cache-PageType
X-Cache-Fix
Retry-After
X-Always-Cache
X-Srv
X-Purge-Host
X-App-Server
X-Vhost
Qs-Cache
X-Real-Server
X-Webkit-CSP
Eomportal-Instance
SVR
Cached
Front
X-Healthy
SRV
X-ORACLE-DMS-RID
X-Cache-Handler
X-Directory-Script
X-VARITI-CCR
X-Mobilized-By
X-Location
X-Hit-Cache
BALANCEDTO
X-AF-Userserver
W
X-Pagename
X-Client-Vid
X-EPiphany-Vid
X-Client-Image-Vid
Disablevcache
Warning
Local-Info
Cache-Tag
X-Route-To
X-Traffic
X-HP-Trace-ID
X-CB-Server
AddOutputFilterByType
NetMindSessionID
X-Varnish-ID
X-HP-Trace-Project
X-Cache-Control
WWW-Authenticate
X-VC-TTL
Cteonnt-Length
SEOMOZ
X-Env
X-Runtime-Memory
MJ12bot
X-WN-ClientGroup
X-ACMCache
X-Varnish-IP
WN
X-LB-Server
HitType
X-Cache-Doesi
X-ClientSide-Caching
X-CDN-COMPRESS
EagleEye-TraceId
X-CDN-RULE
X-Cache-Device-Type
X-Drupal-Cache-Contexts
Keywords
X-Framework
X-JG-Page-Cache
X-FireWall-Port
X-CAPServer
MC
X-SmugMug-Hiring
X-TTFB
X-SmugMug-Values
X-Content-Type-Option
Smug-CDN
X-Remote-Addr
Machine
X-WR-Flags
X-Amz-Meta-Cb-Modifiedtime
X-TTFB-L
CacheControlHeader
X-Dw-Trace-Id
Content_type
X-CF-Passed-Proto
NtCoent-Length
Thanks
X-IIJ-Cache
X-WR-MODIFICATION
X-Varnish-Retries
X-High-Performance
X-Varnish-Server
X-NODE
X-Varnish-Hostname
X-Drectory-Script
X-Varnish-Hits
X-RealServer
X-Webcelerate
X-Adobe-Content
X-Adobe-Loc
X-Debug-Token
X-Ezoic-Cdn
Description
X-Connection-Hash
X-LP
X-Transaction
X-Server-IP
X-Sys-Req-ID
X-NginX-Server
X-Twitter-Response-Tags
Ufe-Result
X-Cache-TTL-Remaining
X-Cache-Dispatchercachecontrol
NODE
X-VC-Enabled
X-Symfony-Cache
Id
X-WP
X-ReqId
X-GeoIP
X-Cache-Dispatcherpragma
Server-Name
X-Page
IISExport
X-Generated-Time
Ctx
X-Cache-Provider
X-ASAP-Cache
X-Clara-ASAP
X-Cache-Source
Web-App-Origin-Name
Proxy-Agent
X-Domain-Checked
X-Provisioner-Version
X-HTML-Minification-Powered-By
X-Balanceador
X-Distil-CS
X-Rq
X-App-Status
MW-Webserver
X-ServerIndex
X-ARRServer
X-Oracle-DMS-ECID
X-Mobile-URL
CLMOB
X-Session-ID
SBGI-5
X-Cache-Node
X-HW
X-Resolver-IP
X-TB-M
X-A
ServerSignature
X-Source-ID
X-UA
ServerTokens
SBGI-9
X-Backend-Status
SBGI-7
SBGI-10
X-Redman-Final-Url
RN-Server
X-Redman-Backend
X-AVG-Country-Code
X-Session-Reinit
X-HP-Redirect
X-NginX-Cache
X-Disney-Akamai-Rule
Max-Age
X-Smartcache-Timeout
SBGI-1
X-Avg-Cookie-Expires
X-Culture
X-DTC
X-Smartcache-Keys
X-Rack-Cors
SBGI-RealPath
SBGI-RenderTime
X-Origin-Server
X-Key
Dispatcher
X-Info
X-Atraveo-Set-Cookie
X-Rocket-Nginx-Serving-Static
X-Force
X-SmartBan-URL
X-PRAM
X-SmartBan-Host
X-Atraveo-Zone
X-Atraveo-TTL
X-Atraveo-Varnish-Server-Id
DNNOutputCache
X-Highwire-SessionId
SBGI-Device
TC-Cache-IC
TC-Cache-U
X-Highwire-RequestId
TC-Cache
X-Atraveo-Cache-Control
Yoncu-Errno
X-RiS-UFDI
X-Akamai-Edgescape
X-Atraveo-ETag
TC-S-Cache
TC-S-Cache-M
X-Atraveo-Param-Rm
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
X-Runtime-Rack
Fastly-Backend-Name
SHInfo
From
X-Nginx-Host
X-Cocoon-Version
Cmstype
Cmsid
X-OPNET-Transaction-Trace
X-Goog-Meta-Replace
X-Goog-Meta-Policy
Nginx-Cache
X-Artvisual-Server
X-Esi
X-Litespeed-Cache-Control
Bios
X-Cluster-Node
X-Proto
X-HydroSheep
X-Upstream-Status
X-Upstream-Backend
X-Avvio-Cms-Cacheload
Access-Control-Request-Headers
X-E
X-Ghost-Cache-Status
X-Machine
X-Analytics
X-MSEdge-Ref
X-Cache-Via
X-Wikidot-Backend
Backend-Timing
X-ProcessESI
OriginServer
Home
X-RemovedCookies
X-SERVER-NAME
X-Wikidot-Static-Cache
X-Proxy-Cache-Key
NLCacheNote
X-Hosting-Env
X-OpenCart-Lightning
X-SDE-Name
X-Cache-Keep
Dis-Env
Og
XDomainRequestAllowed
X-Middleton-PageSpeed
X-Jphone-Copyright
X-Frame-Option
ScoreTracker
X-Unbounce-Variant
X-Unbounce-VisitorID
X-Garden-Version
X-Unbounce-PageId
X-Server-Instance
X-Render-Time
From-Origin
X-Resty-Request-Id
X-WHOIS-Cached
Web
X-Fedora-School-Id
X-KoobooCMS-Version
X-Ser
X-LW-Web-Server
X-Hrouter
X-Hstore
AsisCache
X-Req-Head-Response
Strikingly-Cached-Version
MS-CV
Strikingly-Cached
Strikingly-Cache-Region
X-HITS
Buuteeq-Source
X-4ormat-Cacheable
X-AEM
X-NewRelic-App-Data
COMMERCE-SERVER-SOFTWARE
X-Unique-Id
X-Map-Context
Provider
WP-AdvCache-MemCached
X-This-Proto
X-Nginx-Request-Processing-Time
X-Trace-Id
Swift-Performance
Beyond-Iis
X-ACCELERATE
X-Batcache-Reason
X-EC2-Instance-Id
X-Batcache
X-Stage
X-Unique-ID
Access-Control-Allow-Method
X-Machine-Name
X-SCM-Server-Number
X-Actindo-Thread-Id
X-RDP
X-PBY
X-MAT-GEO
NZSpeedy
ServerIP
Server-ID
X-Depends
Serverid
X-Adnet
X-Zendesk-User-Id
X-Zendesk-Origin-Server
X-Response
X-Ezpublish-Nodeid
X-Ezpublish-Installationid
X-Cache-On
X-SilverStripe-Cache
X-Secret
X-Airee-Node
Content-Server
Sophnep-Edge-FX
DrivedBy
Session-From
X-MidCOM-Meta-Cache
X-CRA-DC
X-Rebelmouse-Cache-Control
X-AMAZEEIO
Myheader
Edgecast
X-Rebelmouse-Surrogate-Control
X-Autoru-Host
X-Plat
SB-Site-IE-VERSION
SB-Site-Device
X-GSL-Server
X-HA-Frontend
Paypal-Debug-Id
X-Sc-Cache
X-Rewrite
SB-Cache-Remaining
Set-Cookie2
X-Amz-Id-1
X-App
X-WPL-DATA
X-Cache-Detail
SB-Cache-Life
ViewMode
X-Data-Request
X-HashTwo
X-Blog
X-Aramark-SID
X-EMAC-Request-ID
X-Actindo-Request-Id
X-Actindo-Error-1
X-B2f-Not-Route
X-Actindo-Rs
X-AutoRu-App-Id
AccessControlAllowOrigin
X-Autoru-LB
SG
X-Origin-404Back
Accept-Language
Cluster-ID
X-Apm-Telemetry-Syncmark
Hname
X-Varnish-Cache-Local
X-Origin-404URL
X-Replay-Request-ID
Xc
X-HA-Backend
X-VarnState-NoCache
ClientIP
X-CACHE-TTL
X-CacheResult
X-WA-Info
X-Old-Content-Length
X-VarnMisc-UrlChanged
X-VarnMisc-Url
Response-Time
F5-IpCliente
Gzip
X-Pagely-Cache
X-ETag
X-Server-Addr
X-Serv
X-Dev
Worker
X-Distributor
WSR-Cache
SBMCLOUD
X-Goog-Meta-Goog-Reserved-File-Mtime
X-HostName
X-Header
X-CSRF-Token
X-Detected-Device
X-Bcwwwid
X-Cache-Warmer
Server-Ip
VServer
Ttl
X-SV
X-Cms-Mode
X-DB-Content-Length
Pics-Label
X-ACLR-Version
X-We-Are-Hiring
X-Nginx
N365rili
Ibf5scheme
AMP-Access-Control-Allow-Source-Origin
X-DSMX-Render-MS
X-DSMX-Rewrite-MS
X-DN-Cache-Control
X-LBPoolMember
X-HAProxy
X-Amz-Meta-Content-Md5
Ews
StatusCode
X-FRUIT
PagesDisplayed
X-Viator-Tapersistentcookie
X-AG-MIPS
X-Obj.Ttl
X-L-Path
VANITY-HOST
Cache-Status
AC-ELC
X-Node-ID
X-Grid-Server
MwpReleaseVersion
X-Cached-Status
X-CacheID
X-Router
X-Frames-Options
X-Desc
X-M
Hamster
Traffic-Origin
Tempo
Ram
Noq
NS-VaryByCustom-Key
X-Cache-Time
X-Webstats-RespID
Debug-Status
X-Webkit-CSP-Report-Only
X-PM-ID
X-XHR-Current-Location
Hosted-By
Il-Cl
Actual-Object-TTL
X-Forwarded-Host
Proxy-Cache
AGI-Request-ID
X-Gyrobase-Publication
X-Served-Server
X-Layout
X-Hosting
X-PROCESSED-BY
X-Cache-TTL-Current
DB-Nickname
X-Environment-Context
X-Title
X-Built-With
X-NodeID
X-Highwire-Smart-Code
X-Highwire-Sitecode
X-Dynamic-Cache
X-Session-Id
X-DS1D
X-Author
X-Captured
X-Theme
X-RequesterIP
X-Who
X-ZSITES-DNS
Url
X-Fstrz
X-Forwarded-By
CommunityServer
FastCGI-Cache-Status
X-Cache-TTL-Age
X-Gannett-Site-Version
X-Container
Device
TP-Cache
X-Ss-Conf
BackendServer
TP-L2-Cache
X-ChromeLogger-Data
SERVER-ID
X-REDIRECTSERVER
X-Varnish-Action
X-CACHE-KEY
X-SH-Cache-Status
X-Ss-Location
X-Reflector-Cache
X-Cdn-Forward
X-Reflector
RSB-LINK
RATING
PServer
SiteSpeed
X-Cache-HT
X-Site
X-Resource
X-Optimization
X-App-Runtime
X-Lb
X-Cache-BE
X-RAMCache
X-Src-Webcache
X-Pj-Cache-Status
X-Varnish-URL
X-Runtime-Affili
X-CH-Device
X-Pageid
X-MainProfileName
X-DevSrv-CMS
X-HP-CAM-COLOR
X-Fastly-Backend-Reqs
X-LOCATION
X-MainProfileCategory
X-FreeTag-Count
X-Search-Id
X-Server-Generated
X-MainProfileID
X-IP-Address
X-Magento-Action
X-Router-Backend
X-Backend-Host
X-Obvious-Info
Referer
X-UseReverse-Proxy
X-Webapp
User-Agent
XDisk
RequestId
X-Obvious-Tid
Provided-Host
X-Cacheable-TTL
Tk
X-MainProfileURL
X-Time-Microsecs
X-Serendipity-InterfaceLang
Note
X-Serendipity-InterfaceLangSource
Session-Id
Fw-Cache-Status
Cache-Tags
X-ELB
X-CPU-Time
X-MCF-ID
X-Script
X-ServerAddr
X-Server-FQDN
X-Country
X-Cache-Varnish
X-OCTOPOD
X-Meta-MSThemeCompatible
X-Proxy-Id
X-Uncacheable
D
X-Streams-Distribution
X-Time-Zone
MSThemeCompatible
MSSmartTagsPreventParsing
X-Rack-CORS
X-GoCache-CacheStatus
X-Meta-Imagetoolbar
X-Instance-Name
Httpd-Identifier
Hostname
X-Varnish-Cached
X-UPServer
X-Varnish-Cached-TTL
X-Varnish-Instance
X-VLoc
X-Bip
X-AppServer-Cache-Rule
X-Brought-To-You-By
X-Box
X-Cache-Extended
X-Cluster
X-Test
X-DeliveryServer
X-Application
X-Agent
X-VC-Debug
X-Not-Cacheable
X-WebNode
X-Route
Resin-Trace
X-Dynamic
X-ENV
DbServerName
X-ASAP-Age
FindLaw
Rewriter
Webserver
UrlWatchModule-Time
Content-Cache
X-Upgrade-Enabled
X-Status
X-Meta-MSSmartTagsPreventParsing
X-Restarts
X-Sid
X-HS-Status
X-Nginx-Request-Time
MageStack-PageSpeed
X-AppVersion
X-Config-By
X-APP
Uuri
Service-Worker-Allowed
Quri
X-Srcache-Fetch-Status
AR-SID
GranicusServer
X-Rewritten-By
X-ManagedFusion-Rewriter-Version
Server-Tuning
Aurora-Node
X-Deity
X-Debug-Message
X-HA
X-9XB-Server
Arrnode
X-FPC
X-Cname-TryFiles
X-Pass-Through
X-Beatles
X-Cache-LB
X-IP
AR-PoweredBy
X-Sites
INFO
X-Svr
X-Flex-Lang
X-Flex-Evstart
X-Flex-Evend
X-Flex-Lastmod
X-Cache-Id
X-Turpentine-Esi
WebServer
Apple-Itunes-App
X-Flex-Tag
X-Beatles-Hits
X-Cache-Set
X-Your-GrandPa-Would-Wait
X-ImpID
AR-ATIME
AR-CACHE
X-Would-Your-GrandPa-Wait
X-TTL-Age
X-CCM
X-Does-He-Have-Time
X-Header-Treatment
X-Flex-Community
X-Flex-Tags
X-AISO-Cache
MageStack-Tag
MageStack-Magento-Version
MageStack-Web-Node
Str-Bsite
Str-Ip
Page-Template
MageStack-Loadbalancer
X-Nginx-Page-Cache
MageStack-Config
MageStack-Debug
X-Node-Name
X-Accel-Cache-Control
X-Amcomm-Site
X-Varnish-Debug-TTL
X-MCB-Server
X-V
X-Varnish-Debug-Age
Y-Trace
X-JSESSIONID
X-Compressed-By
X-App-Version
Expiries
X-Wm-VIP
X-Wm-1
MageStack-Cacheable
MageStack-Cache-Status
X-Tag-Playlist
WSCLoggingUUID
NCache
X-Catalyst
X-Served
X-AISO-Server
X-ESI
X-AISO-Cacheable
X-Processed
X-SCProxy
X-VNode
X-Srcache-Store-Status
X-Enhanced-By
MageStack-Area
MageStack-Cache
MageStack-Cache-Hits
MageStack-Cache-Lifetime
Lb
X-FG-RequestId
X-Site-Name
X-Lima-Id
Brightspot-Id
CD4
X-Varnish-Ip
X-Beresp-Ttl
X-DEBUG
X-Origin-Cache
ProxiaInstanceId
X-COUNTRY-CODE
X-W3TC-Minify
EREV-Ver
AliCDN-Forbidden-Reason
X-Cache-ID
X-Archive-Orig-Content-Length
X-7d-Instance-Id
X-Archive-Guessed-Charset
HostName
X-Archive-Orig-Connection
X-Server-Instance-Name
X-UPSTREAM-Address
X-Cache-Date
Progma
PB-PID
X-Cjtype
No-Cache
Vserver
X-Archive-Orig-Server
EQ-Cache
Generate-Time
X-HEAD
X-Via-NSCOPI
X-Client-Ip
V-Age
X-Backend-Name
X-Checkout
Ozcache
X-Varnish-Cache-Ttl
X-Phpwcms-Page-Processed-In
X-Static
X-Phpwcms-Release
X-ClusterID
X-NID
Be
VC-NoCache
X-Archive-Orig-Date
X-Archive-Orig-Etag
X-Tt-Dbg
X-Pixelsilk-Server
X-Pixelsilk-Version
X-Real-IP
X-7d-Trace-Id
X-ServiceProvider
Content-Generator
X-Hit
Memento-Datetime
X-DynamicCache
X-Transaction-Name
X-Amz-Meta-Version-Id
Kp-EeAlive
Yola-ID
Tesla.Performance
X-Mobile-Rewrite
X-UT-Cache
X-Czt
X-Config-Version
X-IsCached
X-LB-Backend
Copyright
X-Memcached
X-Server-Ident
X-WebKit-CSP-Report-Only
MachineName
CacheControlMode
LB
Cookie
X-Cache-Action
X-BeResp-Ttl
Tst
PB-RID
X-FIRSTBase
X-Farm-Server
X-LB-Frontend
Ez
Phoenix-A
X-WHO
Phoenix-Mark
Phoenix-Proxy-Cache
Proxy1
Phoenix-Cache-V
Phoenix-Cache
Section-Io-Cache
TTL
Powered-By-VeryCDN
VAR-Cache
X-Test-Debug
RSL-Trace-ID
AMFplus-Ver
WFE
X-Front-Cache
X-Instart-Cache-Id
X-Vary-Options
X-NewCloud-V-Cache
Cleartype
IsMobile
X-Backend-TTL
X-Cache-Me-Harder
X-Obj-Ttl
X-RiS-PX
X-Instance-Id
X-Faeria
X-NewsFlow-Sitename
X-PBS-Appsvrip
X-PBS-Appsvrname
X-Cache-FS-Status
ReqUrl
X-Tradeindia-Request-GUID
X-Tradeindia-SMgmt
X-Vid
FrontEnd
X-Varnish-Mode
X-Varnish-Auto-Cache-Miss
X-EBAY-C-REQUEST-ID
RlogId
X-Generated-Date
CDCHOST
Fastly-Restarts
M
X-Refresh
Countrycode
Head
X-Cache-Bypass
X-CO-Host
X-Pubstack
X-XHTML-Minification-Powered-By
X-Csrf-Token
X-Imforza-Hosted
X-Made-On
X-Powered-By-Home.Pl
Upgrade-Insecure-Requests
Microcache
SS
X-Max-Age
X-Serverid
!~Request-OOB-Work
X-PBS-Fwsrvname
X-POPSUGAR-Server-Name
CDN-Cache-Hit
CDN-Cache
CDN-Node
DeleGate-Ver
Https
X-Mobile-Device-Type
X-Mobile-Device
X-Cache-V
X-Dynatrace
X-Dynatrace-Js-Agent
Container
X-ACache
X-BIT-Node
X-BPool
X-BPool-Back
X-BPool-Bx-Cache
X-BPool-Fx-Cache
TheAnswer
Language
X-Built-By
X-Ssl-Cipher
X-UUID
Accept-CH
Type
ResourceTag
SINA-TS
SINA-LB
X-Clx-Request
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-Skip-Cache
X-Geo-IP
X-SRV
X-Wily-Info
X-Wily-Servlet
Server-Id
X-MSU-SOURCE
X-Service-Id
X-Fpc
X-Sn-Servicetimems
Dynatrace
Public-Extension
X-B3-Traceid
X-B3-Spanid
X-SuperCache
IES-Server
Kanooh-Host
Load-Balancer
X-BServer