Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Set-Cookie
Server
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
X-AspNet-Version
P3P
X-Pingback
Via
X-UA-Compatible
Upgrade
Access-Control-Allow-Origin
Content-Security-Policy
X-Xss-Protection
X-Cacheable
X-Request-Id
X-Varnish
Referrer-Policy
X-Adblock-Key
X-Check
X-Generator
X-Language
X-Template
X-Buckets
X-Type
X-Cache-Group
X-Pass-Why
WPE-Backend
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Download-Options
Alt-Svc
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Host-Header
X-Ac
X-Hacker
X-Cache-Hits
P3p
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-AspNetMvc-Version
X-ShopId
X-ShardId
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId-Cached
X-Via
X-Runtime
X-Powered-By-Plesk
X-Served-By
X-Contextid
X-PC-Key
X-PC-Hit
X-UA-Device
X-Amz-Cf-Id
X-PC-AppVer
X-ServedBy
X-PC-Date
X-PC-Host
MS-Author-Via
Content-Location
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-Timer
X-IPLB-Instance
Status
X-Rid
X-Wix-Request-Id
X-Seen-By
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Ua-Compatible
X-Tumblr-Pixel-1
CF-Cache-Status
Cartoon
X-Tumblr-Pixel-2
Access-Control-Allow-Credentials
X-Iinfo
X-Backend
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
Content-Encoding
Powered-By
X-CST
X-Host
X-Endurance-Cache-Level
X-Cache-Enabled
X-Mod-Pagespeed
X-Cache-Hit
X-Port
X-FRAME-OPTIONS
X-CDN
X-Tumblr-Pixel-3
X-NewRelic-App-Data
X-Newrelic-App-Data
X-Logged-In
X-Server-Powered-By
Keep-Alive
X-DIS-Request-ID
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server
X-Robots-Tag
X-Accel-Version
X-Proxy-Cache
X-Turbo-Charged-By
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Content-Powered-By
X-GitHub-Request-Id
X-LiteSpeed-Cache
X-Content-Digest
Content-Security-Policy-Report-Only
X-Request-ID
X-Rack-Cache
X-Tumblr-Pixel-4
X-FW-Hash
X-FW-Server
X-AH-Environment
Request-Context
X-Pad
X-FW-Serve
X-FW-Static
X-FW-Type
Edge-Control
X-Varnish-Cache
X-Hits
X-Trace
X-Webcom-Cache-Status
X-XRDS-Location
Access-Control-Expose-Headers
SPRequestGuid
X-SharePointHealthScore
X-Request-Country
X-BC-Stapler
X-Node
X-MS-InvokeApp
Edge-Cache-Tag
X-HS-Cache-Config
MicrosoftSharePointTeamServices
X-HS-Content-Id
WP-Super-Cache
Cf-Railgun
X-SERVER
X-CF-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-HS-Combine-CSS
Timing-Allow-Origin
Charset
X-Died
X-Content-Security-Policy
X-FullPageCaching
X-Webserver
X-Fastly-Request-ID
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
X-Cache-Lookup
X-PhApp
Access-Control-Max-Age
Request-Id
X-Cnection
SPIisLatency
SPRequestDuration
X-Backend-Server
X-Edge-Cache
X-Edge-Cache-Key
MicrosoftOfficeWebServer
EagleId
CONTENT-SECURITY-POLICY
X-Swift-SaveTime
X-Swift-CacheTime
X-Servedby
Rating
X-CDN-Pop
X-CDN-Pop-IP
Composed-By
Grace
X-SS-Conf
X-SS-Location
Ali-Swift-Global-Savetime
X-Tumblr-Pixel-5
X-Device
X-Safe-Firewall
Served-By
X-Server-Name
X-Tumblr-Content-Rating
Liferay-Portal
X-DDC-Arch-Trace
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Spip-Cache
X-HeyJason
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-VCache
X-Cloud-Trace-Context
X-Hyper-Cache
Front-End-Https
X-Microcache
P-LB
P-WS
X-LiteSpeed-Cache-Control
X-RateLimit-Remaining
X-RateLimit-Limit
X-Original-Date
Surrogate-Control
X-Loop
X-TNCMS
Display
X-Middleton-Display
X-Sol
X-RateLimit-Reset
X-Jimdo-Wid
X-Jimdo-Instance
X-Acc-Exp
X-Cluster-Node
X-Middleton-Response
Response
X-OneAgent-JS-Injection
X-Clacks-Overhead
X-FB-Debug
Refresh
X-Vtex-Processado-Em
X-Kinsta-Cache
Content-Style-Type
X-DNS-Prefetch-Control
X-Firenze-Processing-Times
X-Debug-Info
Public-Key-Pins
Content-Script-Type
X-StackifyID
X-Wix-Punisher
X-Shopid
X-Sorting-Hat-Featureset
X-Magento-Tags
X-Sorting-Hat-Podid
X-Shardid
X-Tumblr-Pixel-6
X-Sorting-Hat-Shopid
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Podid-Cached
X-XN-XNHTML
X-XN-Trace-Token
X-Sorting-Hat-Privacylevel
X-Amz-Version-Id
X-Age
X-LW-Cache
X-Goog-Hash
X-HOST
Fpc-Cache-Id
X-User-Agent
X-DynaTrace-JS-Agent
X-Cached
X-Ruxit-JS-Agent
X-Zen-Fury
X-Px
X-Cache-Config
Feature-Policy
X-N-OperationId
X-Url
Xkey
PageSpeed
Wpe-Backend
X-Hostname
Retry-After
X-Upstream
X-WebKit-CSP
X-Version
X-Handled-By
X-Generated-By
X-Frame-Option
X-Topify-Platform
X-FORWARDED-FOR
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Edge-Location
Allow
Access-Control-Request-Method
Rt-Fastcgi-Cache
X-Source
X-B-Cache
Fastcgi-Cache
X-Loopia-Node
X-MiniProfiler-Ids
X-EdgeConnect-Origin-MEX-Latency
X-Whom
X-Cached-By
X-ET-API-ROOT
X-ET-API-ORIGIN
X-ET-API-VERSION
X-EdgeConnect-MidMile-RTT
X-RESOURCE
X-Outils-CS
Powered
X-CMS-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-URLSCHEME
ServedBy
TCN
X-Content-Options
X-Request-Time
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-AspNetWebPages-Version
Product
X-DynaTrace
Last-Published
No
X-Magento-Cache-Debug
X-Powered-By-VTEX-Janus-ApiCache
X-Vtex-Processed-At
X-VTEX-Janus-Router-Backend-App
X-Vtex-Remote-Cache
X-Guploader-Uploadid
X-VTEX-Cache-Status-Janus-ApiCache
X-CacheServer
Fhost
Pagespeed
Warning
X-ARC
X-Accel-Expires
X-Engine
X-Fastcgi-Cache
X-Varnish-Host
X-Passed-To
X-Returned-From
X-Tec-Api-Root
X-Original-Request
X-Passed-To-DLL
X-Tec-Api-Origin
X-Tec-Api-Version
X-Returned-From-DLL
X-Developer
X-Application-Context
X-Actual-URL
Generator
X-LBLID
Public-Key-Pins-Report-Only
X-Varnish-Cache-Hits
X-From
Cache-Provider
X-Signature
X-UD-Method
X-Varnish-HitMiss
X-Response-Time
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Varnish-Count
X-Ezoic-Cdn
X-Cache-Info
Cache-Key
X-Returned-From-BeforeDispatch
X-Stale
X-Returned-From-PostProcessResponse
X-Platform-Server
X-Passed-To-BeforeDispatch
X-Cache-Key
X-Passed-To-PostProcessResponse
X-Shop-Id
X-F-Cache
X-ApacheServer
X-Location-Id
X-Defender
X-PERF
X-S
Origin
Alternate-Protocol
X-Micro-Cache
X-Hosted-By
DynaTrace
Imagetoolbar
X-HS-Content-Campaign-Id
X-URL
X-Microcachable
X-Via-JSL
Arr-Disable-Session-Affinity
X-Umbraco-Version
X-Device-Type
X-Platform
Host
X-NWS-LOG-UUID
X-Sapient
X-Dns-Prefetch-Control
Content-Hash
Version
Surrogate-Key
X-Recruiting
X-Track
X-Gateway-Cache-Key
X-Powered-By-360WZB
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Magento-Cache-Control
X-Environment
X-Cache-Age
X-Cache-Namespace
Akamai-IP
X-Instart-Request-ID
X-Platform-Cache
X-Correlation-Id
X-Lambda-Id
X-Acquia-Application-UUID
X-BS
X-Rnd
X-I-Sp
X-SO
X-Cache-Rule
X-App-Status
X-SSLProxy
X-Microcache-Status
X-Translation
X-SSLUpstream
X-Msg-2-Log
X-Powered-By-VTEX-Janus-Edge
X-Akam-SW-Version
X-Cache-TTL
X-Forwarded-For
Dmn
X-Duration
X-SVR-IIS
X-Svr-Proxy
WZWS-RAY
RTSS
SSPAppContext
MIME-Version
X-CSRF-Protection
X-DealerOn
X-Dispatcher
X-Dealeron-Original-Url
X-Supported-By
X-Dealeron-Backend
X-Cache-Tags
Pool
X-Director
S-Cnection
X-Server-Upstream
X-Powered-By-VelaWeb
USPLoggingUUID
X-SSL-Protocol
X-ORACLE-DMS-ECID
X-Last-Modified
Content-Disposition
X-SSL-Cipher
X-Hypernode
X-App-Hosting
X-Abgroup
X-Expires-Orig
FAI-W-FLOW
X-TransIP-Balancer
X-Cache-Control-Orig
Wsr-Cache
X-NetCat-Version
Edge-Control-Message
X-Page-Cache
Update-Time
Src-Update
Node
X-LB-Node
X-Edge-IP
X-Front
X-TransIP-Backend
X-Vcap-Request-Id
X-Rocket-Nginx-Bypass
X-Geo-Country
X-Storage
X-Revision
X-Now-Id
X-Matrix-Server
Req-Id
X-SDS
X-Matrix-Proxy
X-Generated
X-Debug
X-I
Accept-Encoding
X-Client-IP
X-Drupal-Cache-Tags
X-ServerName
X-Server-ID
X-Gamma-Serve
X-ATG-Version
Contao-Page-Layout
Cache
X-Cache-Server
X-Route-Server
X-Varnish-Cacheable
X-Varnish-TTL
X-Rocket-Nginx-Serving-Static
X-Correlation-ID
X-NoCache
X-Daa-Tunnel
X-VARITI-CCR
X-Cache-Handler
X-Cache-Lifetime
X-Cache-Debug
X-Env
X-SV-Edge
X-SV-Pid
X-SV-CacheTags
X-SRV
X-SV-CreatedAt
SiteSpeed
X-SV-Expires
X-SV-Cacheable
X-SV-Nginx-Duration
X-Art-Request-Id
X-SV-FromDBCache
X-SV-Duration
ServerID
X-SmugMug-Hiring
X-TTFB
X-N
SN
X-Acquia-Application-Trace
X-SmugMug-Values
X-TTFB-L
Smug-CDN
X-LB-Server
Content-Encoding-Handler
X-Varnish-Age
X-Cache-Engine
X-Hiawatha-Cache
X-Server-Id
X-Amz-Meta-S3cmd-Attrs
X-Url-Base
X-Cache-Level
Powered-By-ChinaCache
X-Vhost
Lsrequestid
X-Content-Type-Option
X-Cache-Operation
X-IsCacheURL
X-Varnish-GracePeriod
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Dispatch
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Discourse-Route
Section-Io-Id
ServerName
X-Drupal-Cache-Contexts
X-Cache-Expires
X-Grace
X-GUploader-UploadID
X-Middleware-Start
X-Varnish-Url
X-Firenze-Processing-Time
X-Sucuri-ID
X-Content-Encoded-By
X-Cache-Only-Varnish
Author
X-Locale
Backend
X-TransIP-Reserved
X-Trace-Id
X-Pressidium-NinukisWP-Ver
X-Forwarded-Proto
X-GeoIP-Country-Code
X-Sucuri-Cache
W
X-ORACLE-DMS-RID
Content-MD5
X-CJ-Soft
X-Server-Instance
X-Unbounce-VisitorID
Service-Worker-Allowed
X-Unbounce-Variant
X-Unbounce-PageId
X-LB
X-Varnish-IP
Proxy-Connection
Use-Proxy
If-Modified-Since
X-Varnish-Backend
X-Flow-Powered
Strikingly-Cached-Version
Location
Strikingly-Cached
Strikingly-Cache-Region
Cneonction
Page-Completion-Status
X-Country-Code
X-Shard
X-Litespeed-Cache
X-Amz-Rid
X-Time
X-Transaction
X-Connection-Hash
X-Twitter-Response-Tags
X-Service-Id
X-Cache-Type
Cache-Tags
Pv
X-NginX-Cache
X-Akamai-Device-Model
X-Always-Cache
X-Akamai-Device-Characteristics
X-SRCache-Key
MJ12bot
SEOMOZ
X-Ttl
X-GeoIP-Country-Name
X-Cache-Control
X-CF-Passed-Proto
X-Webkit-CSP
Https
X-High-Performance
X-Speed-Cache-Key
AMF-Ver
X-Speed-Cache
X-Magnolia-Registration
X-Varnish-Retries
X-FIRSTBase
X-HW
X-FTR-Request-ID
X-Empowered-By
X-Now-Cache
X-WR-MODIFICATION
Srv
Custom-Header
X-TTL
X-Esi
X-Cache-Fix
X-Frontend
X-BackendServer
From-Origin
X-PwB-Node
Server-Name
X-Cache-PageType
X-Wikidot-Static-Cache
X-Dynamic-Cache
X-Wikidot-Backend
IM-Version
X-Storage-Cache-Expires
X-Storage-Cache-Date
X-Config-Blacklist-Version
X-Nginx-Cache
Edit
X-Storage-Cache
X-CDN-Forward
Server-Timing
X-Browser
FindLaw
X-Cookie-Domain
X-Real-Server
X-Content-Security-Policy-Report-Only
X-FW
X-Cache-Device-Type
MC
X-Nitro-Cache
X-Analytics
Dtk-Cache-Check-0
NetMindSessionID
X-Rq
X-Xrds-Location
X-ID
X-Content-Age
X-CacheFROM
Swift-Performance
Backend-Timing
Local-Info
X-Helper-Autoassign-All
IBM-Web2-Location
X-Pool
X-Symfony-Cache
X-ServerID
S
Xc-Version
X-Stage
Drupal-Pagecache-Memcache
Fw-Via
X-Litespeed-Cache-Control
PICS-Label
Content_type
Prama
Qs-Cache
X-Srv
X-Vip
X-Varnish-Server
X-4ormat-Cacheable
X-Key
X-ACMCache
NnCoection
Ohc-File-Size
X-Nbs
X-Processing-Time
X-VC-Enabled
X-Id
X-Cache-Miss-From
Hummingbird-Cache
X-PF-Uncompressing
X-Varnish-Hits
Pics-Label
Nodo
X-Sedo-Request-Id
X-FireWall-Port
Cached
X-RealServer
Noq
X-SP-Farm
X-Backend-Status
X-SP-UniqueName
X-Location
X-RequestId
Frame-Options
X-Amz-Meta-Content-Md5
X-Orig-Vary
Content-Transfer-Encoding
X-Yadis-Location
Tracecode
Ramp
X-LP
Cm-Server
X-WR-Flags
X-Worker
X-Runtime-Memory
X-Disney-Akamai-Rule
X-A
Ram
X-NginX-Server
X-Varnish-Ttl
X-Amz-Storage-Class
X-Proxy
X-Role
X-BKSrc
X-Pantheon-Phpreq
RequestId
X-Varnish-ID
Request-EU
X-Pantheon-Site
X-Pantheon-Environment
Surrogate-Key-Raw
X-Cache-2
Request-Country
Access-Control-Allow-Method
CacheControlHeader
X-HydroSheep
X-Distributor
X-Shield-Request-Id
X-Pagename
X-Hit-Cache
X-Drectory-Script
X-SERVER-NAME
AsisCache
X-JSESSIONID
X-E
X-JG-Page-Cache
X-Origin
X-Varnish-Hostname
X-Unique-ID
X-Sys-Req-ID
X-LW-Web-Server
X-TB-M
CF-Worker-Script
X-Adobe-Content
X-AEM
X-Hrouter
X-Hstore
Adm-Server
X-Cache-CFC
X-Adobe-Loc
Web-App-Origin-Name
X-Purge-Host
Accept-Language
X-Purge-URL
X-Yottaa-Optimizations
X-ClientSide-Caching
X-Span
Lookup-Cache-Hit
X-GoCache-CacheStatus
X-Runtime-Affili
Accept-Charset
Eomportal-Instance
Cteonnt-Length
X-Yottaa-Metrics
X-App-Runtime
X-CB-Server
X-Proxy-Backend
X-Generated-Timestamp
X-App-Server
WWW-Authenticate
Nginx-Cache
X-Real-IP
X-App
X-Debug-Token
X-CAPServer
Front
X-Culture
X-CLOUD-TRACE-CONTEXT
X-Balanceador
X-Forwarded-Host
X-ARRServer
SHInfo
Server-Info
X-V
X-Dw-Trace-Id
Lb
A-Powered-By
SVR
X-Vcache
X-ServerIndex
X-Atraveo-Varnish-Server-Id
X-Atraveo-Set-Cookie
X-Atraveo-Param-Rm
X-Atraveo-From-Varnish-Cache
X-Atraveo-Zone
X-Force
X-AF-Userserver
X-Path-Route
X-Request-Uri
X-PRAM
Server-ID
X-Atraveo-TTL
X-Atraveo-Expires
X-Appmachine-Environment
X-Atraveo-Cache-Control
X-Atraveo-ETag
X-Ratelimit-Limit
X-Ratelimit-Remaining
X-Ratelimit-Reset
X-Varnish-Debug-Age
X-Varnish-Debug-TTL
Beyond-Iis
Web
X-Jphone-Copyright
X-Webstats-RespID
X-Distil-CS
HAVer
HCVer
X-Pantheon-Az
X-CacheDebug
Proxy-Agent
X-Agent
X-GeoIP
XDomainRequestAllowed
Access-Control-Request-Headers
X-Session-ID
X-WPL-DATA
X-Runtime-Rack
X-AOL-HN
X-Dev
X-Processed-By
X-ESI
X-SDE-Name
X-Framework
X-Frames-Options
X-Akamai-Transformed
Load-Balancer
X-Hosting-Env
Worker
CS-SERVER
X-Batcache
WP-FROM-CACHE
X-Cms-Mode
Accept-CH
X-VC-TTL
X-Fedora-School-Id
X-Domain-Checked
X-Server-IP
X-Info
X-Cache-Dispatchercachecontrol
Environment
X-Plat
X-Rule
X-HTML-Minification-Powered-By
X-Provisioner-Version
Firespring-Website-Id
IES-Server
X-RiS-UFDI
X-SE-Debug
Upgrade-Insecure-Requests
X-Cache-Dispatcherpragma
X-Client-Vid
SRV
X-Client-Image-Vid
X-EPiphany-Vid
X-Remote-Addr
Pf.Web.Request.Id
X-UPSTREAM
X-Avg-Cookie-Expires
X-AVG-Country-Code
X-Redman-Backend
ScoreTracker
X-Redman-Final-Url
X-Akamai-Edgescape
X-Server-Addr
ServerSignature
Referer
ServerTokens
X-Map-Context
X-Req-Head-Response
CLMOB
Copyright
X-IIJ-Cache
X-Source-ID
X-Proxy-Skip
X-Resource
X-Detected-Device
X-NWS-UUID-VERIFY
X-Upgrade-Enabled
X-Application
X-HA-Backend
X-Cocoon-Version
Traffic-Origin
X-HA-Frontend
WP-AdvCache-MemCached
X-Session-Reinit
X-Nginx-Host
X-Proxy-Cache-Control
AKA-DEVICE
X-Varnish-Cache-Local
X-Autoru-Host
X-VCS-Cacheable
X-VCS-Ttl
X-GSL-Server
Cleartype
*
X-Proto
Session-From
NZSpeedy
X-Cache-Warmer
Dispatcher
AR-SID
AETN-State-Code
X-Amz-Id-1
X-Bip
AR-CACHE
AR-PoweredBy
AR-ATIME
X-UA-Bot
Play-Detected-Device
Play-Detected-UserAgent
Proxy-Cache
X-Confluence-Request-Time
Il-Cl
Home
X-Oferteo-Domain
Thanks
X-DSMX-Rewrite-MS
X-Domino-CacheValidationWithETagReason
Debug-Status
X-Domino-CacheValidationWithETagResult
X-B2f-Not-Route
X-DSMX-Render-MS
X-Aramark-SID
X-Desc
AETN-Area-Code
Access-Control
AETN-Longitude
AETN-Latitude
X-WebNode
X-Via-S
AETN-Postal-Code
Num
AETN-EU
AETN-DEVICE
X-Route
AETN-City
AETN-Continent-Code
AETN-Country-Code
X-Resolver-IP
AETN-Country-Name
X-Soro
X-Amcomm-Site
Filters
X-Cache-On
AMP-Redirect-To
BALANCEDTO
X-Header
X-MAT-GEO
Max-Age
Disablevcache
Access-Control-Allow-Header
X-Rebelmouse-Cache-Control
Arrnode
X-SmartBan-Host
X-7d-Trace-Id
X-SAPP
X-SmartBan-URL
Yoncu-Errno
X-Data-Request
X-Refresh
CommercePlatform-Version
X-Cache-Varnish
X-Garden-Version
X-HashTwo
X-TKP-SRV-ID
X-Highwire-SessionId
OracleCommerceCloud-Sandiego
X-CRA-DC
X-Varnish-Ip
X-7d-Instance-Id
Paypal-Debug-Id
X-Highwire-RequestId
X-PHP-Response-Code
ServerIP
Identity
OracleCommerceCloud-Version
VServer
X-Dynatrace
X-SERVER-ID
X-Envoy-Upstream-Service-Time
X-Mobilized-By
COMMERCE-SERVER-SOFTWARE
X-Smartcache-Keys
X-SV
X-WP
X-Cacheable-TTL
X-Smartcache-Timeout
Dynatrace
Server-Ip
Cmstype
Cmsid
Url
X-Varnish-URL
X-HostName
X-DataDome
X-Goog-Meta-Replace
X-CACHE-TTL
X-Cache-Ttl
X-Compress-Hint
X-Scheme
Now
X-Goog-Meta-Policy
Pramga
X-Ms-Request-Id
X-Now-Trace
RN-Server
X-Rack-Cors
X-Via-NSCOPI
NtCoent-Length
X-OpenCart-Lightning
X-CacheLoc
Ibf5scheme
MSThemeCompatible
X-Gyrobase-Publication
X-DN-Cache-Control
X-Meta-MSThemeCompatible
ServerNode
IISExport
X-EC2-Instance-Id
CDN-Cache
CDN-RequestId
StatusCode
TC-Cache
X-Streams-Distribution
X-Cache-TTL-Current
X-Upstream-Backend
X-Cache-TTL-Age
X-Test
X-Instance-Name
X-Clara-ASAP
X-Firewall
CDN-CachedAt
X-Resty-Request-Id
X-DevSrv-CMS
CDN-Uid
X-Upstream-Status
Httpd-Identifier
X-Meta-MSSmartTagsPreventParsing
TC-S-Cache-M
TC-S-Cache
MSSmartTagsPreventParsing
TC-Cache-U
X-Cache-Detail
X-Served-Server
X-Meta-Imagetoolbar
X-ETag
X-Lb
CDN-PullZone
TC-Cache-IC
Edgecast
X-Middleton-PageSpeed
CF-Worker-Version
X-Policy
X-Response
FRONT-END-SECUREBROWSER
X-Skip-Cache
PServer
X-Geo
X-WEBMGR-CACHE
X-SilverStripe-Cache
Prot
XX
X-CacheID
X-Beget-Proxy
Aurora-Node
N365rili
DNNOutputCache
Og
Description
X-Unique-Id
Keywords
X-Varnish-Id
X-Fastly-Request-Id
MageStack-Config
MageStack-Debug
MageStack-Loadbalancer
MageStack-Magento-Version
MageStack-Cacheable
MageStack-Cache-Status
MageStack-Cache
MageStack-Cache-Hits
MageStack-Cache-Lifetime
MageStack-PageSpeed
MageStack-Tag
X-Dynatrace-Js-Agent
X-FastCGI-Cache
X-Amz-Apigw-Id
X-Amzn-Trace-Id
X-Amzn-RequestId
X-Geo-IP
MageStack-Web-Node
Viewport
X-LBPoolMember
X-Fstrz
X-RiS-PX
X-Old-Content-Length
X-M-Log
X-M-Reqid
X-Qnm-Cache
X-Varnish-Grace
X-Nx
X-PBY
X-Requestid
X-Nx-All
X-Timestamp
X-ACCELERATE
Ttl
VAR-Cache
DrivedBy
X-Beatles
Id
Hosted-By
X-SH-Cache-Status
X-Ghost-Cache-Status
Pragrma
Dis-Env
X-Block-RuleID
X-Actindo-Request-Id
X-Actindo-Rs
X-Actindo-Thread-Id
X-Adnet
VANITY-HOST
X-ASAP-Cache
MageStack-Area
Fastly-Backend-Name
Myheader
X-AutoRu-App-Id
X-Consent-Required
X-Flex-Tag
X-Flex-Tags
X-HeBS-Cache-Status
X-Block-Rule
X-Flex-Lastmod
X-Flex-Lang
X-Flex-Community
X-Flex-Evend
X-Flex-Evstart
X-Cache-Doesi
Xc
VSID
X-Appid
X-Gateway-Rate-Limit-Delayed
ViewMode
Serverid
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-DB-Content-Length
X-Deity
X-FastCGI-Cache-Status
CommunityServer
X-Reflector-Cache
X-Cache-Me-Harder
X-Access-Control-Allow-Origin
X-Served
X-Tag-Playlist
X-FORWARDED-PROTO
X-Sid
X-ORIKEY
X-ROUTING
X-Varnish-Debug-Hits
X-ENDPOINT
X-APIVERSION
NODE
X-APIAUTH-VAL
X-Vary-Options
X-TLS-Version
X-RAMCache
X-Cdn-Forward
BackendServer
Device
X-Appversion
X-Pj-Cache-Status
X-Varnish-Action
X-Reflector
Tk
X-DODN-Region
X-DODN-Id
Resin-Trace
Provider
Page-Template
X-LB-Backend
X-Client-Id
X-Enhanced-By
X-FG-RequestId
X-Obvious-Info
X-Proxy-Id
Expiries
Locale
X-Phpwcms-Page-Processed-In
X-Phpwcms-Release
X-LB-Frontend
X-SSL-Host
X-Varnish-Cached-TTL
X-MCF-ID
X-Fpc
X-Varnish-Cached
Webserver
X-UPServer
SBSS
EagleEye-TraceId
Ufe-Result
X-Node-App
X-Protected-By
X-Captured
X-Cdn-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hit
X-Obvious-Tid
X-Origin-Date
X-We-Are-Hiring
X-Page
X-B3-Sampled
YF-ID
X-ZSITES-DNS
X-Sn-Servicetimems
TYPO3-Sitename
X-Beluga-Cache-Status
X-Beluga-Node
X-Aramark-CSID
X-Beluga-Response-Time-X
X-Beluga-Status
X-Beluga-Response-Time
X-ENV
X-Nginx
X-Beluga-Record
CF-Cache-Key
TYPO3-Pid
Backend-Powered-By
Content-Sn
DB-Nickname
X-FPC
X-WebKit-CSP-Report-Only
X-Server-Generated
Machine
X-Proxy-Cache-Key
X-Depends
Ohc-Response-Time
X-Title
X-Static
X-Secret
X-Layout
ModuleCacheType
X-Beluga-Trace
X-Cache-LB
X-This-Proto
X-Processed
X-Powered-By-Home.Pl
MageStack-Cache-Lifetime-Sent
MageStack-Cache-Warning
WN
MageStack-Last-Modified
X-M
X-HA
GranicusServer
X-Varnish-Backend-Beresp-Backend
X-Rack-CORS
HTTPS
MS-CV
X-Cname-TryFiles
Tempo
X-Build-Id
X-MCB-Server
Provided-Host
X-CH-Device
X-Cache-Node
Session-Id
X-Blog
X-MrHost
X-Generated-Time
Amfplus-Ver
X-WN-ClientGroup
X-ProBase-Server
X-MID-Host
X-Say-Cacheable
X-Say-TTL
X-V-Cache
X-SayCDN-TTL
X-Cache-Time
X-Shopware-Cache-Id
X-Src-Webcache
X-Search-Id
X-PM-ID
X-UnsetCookies
AMP-Access-Control-Allow-Source-Origin
REFRESH
PBS
X-Pass-Through
X-Mighty-Proxy
Purge-Cache-Tags
Hit-Count
Cf-Ipcountry
Response-Time
Ssl-Proxy-Server
X-Max-Age
X-Custom-Name
X-Backside-Transport
X-Firefox-Spdy
X-Custom-Header
X-Batcache-Reason
Server-Id
X-Instance
X-NoIndex
X-Shopware-Allow-Nocache
X-Origin-Cache
NGX
Fastly-Debug-Digest
X-Global-Transaction-ID
X-FromPodPressCache
X-Now-Instance
X-Vol-Mrp
Bios
X-Wodby-Node
X-Webcelerate
X-Vol-Correlation
HSTS
X-Cache-Action
X-Svr
X-NewsFlow-Sitename
X-PBS-Appsvrip
X-HS-Status
X-PBS-Fwsrvname
X-Cache-Extended
Content
X-Box
TP-Cache
From
X-MainProfileName
X-MainProfileURL
X-MyName
X-MainProfileID
X-Reqid
TP-L2-Cache
X-Instance-Id
X-MainProfileCategory
X-Cluster
X-PBS-Appsvrname
X-Cache-FS-Status
Nitro-Cache
SINA-TS
SINA-LB
HitType
Magicmarker
X-DynamicCache
X-Status
X-Compressed-By
X-PROCESSED-BY
X-Directory-Script
X-Oracle-Dms-Ecid
X-Xml-Http-Blocked
X-Serv
X-RENDER-TIME
X-Actual-Url
X-CACHE-KEY
X-DEBUG
X-COUNTRY-CODE
X-Qiniu-Zone
X-ORIGN-SERVER
V-Cache-Ttl
X-Router
X-Telligent-Evolution
Servername
X-Enabled3
X-Origin-Upstream-Status
SS
X-Enabled2
X-Enabled1
EQ-Cache
X-Cache-Id
PagesDisplayed
Ews
LB
X-Appmachine-CreatedOn
Fastly-Restarts
X-Appmachine-Duration
X-Appmachine-Name
X-Cache-HT
X-XHTML-Minification-Powered-By
X-W3TC-Minify
X-Log
X-Serverid
X-Test-Debug
X-Oracle-Dms-Rid
X-Varnish-Cache-Ttl
X-From-Cache
X-GZip
X-Grid-Server
PROGMA
X-InDy-Memory
X-InDy-Query
X-InDy-Time
PB-RID
PB-PID
X-Varnish-Age-Debug
X-Optimization
X-Varnish-TTL-Debug
Amp-Access-Control-Allow-Source-Origin
X-CAMPUSSUITE-DEBUGGING
X-Mobile-Rewrite
X-Accel-Cache-Control
X-Catalyst
X-Bitrix-Composite
X-Healthy
X-Middleton-Pagespeed
Actual-Object-TTL
X-Avvio-Cms-Cacheload
VC-NoCache
ClientIP
Arrow-RequestId
F5-IpCliente
Gzip
ProxiaInstanceId
SERVER-NAME
D
X-Server-Hostname
X-Autoru-App-Id
X-Cache-Bypass
X-UA
Hostname
X-AppServer-Status
X-AppServer-Cache-Rule
X-Amz-Meta-S3b-Last-Modified
UrlWatchModule-Time
X-Amzn-Remapped-Date
X-AppServer-Cache-Exception
X-Vid
X-Tradeindia-SMgmt
Prototype-RootPath
Generate-Time
X-Ruxit-Js-Agent
X-Itkg-Cache-Tags
X-SSLTerm-Server
Unique-Request-Id
X-SG-Server
X-CSRF-Token
X-CAMPUSSUITE-TENANT
X-Expires
X-Magento-Route
Web-Server
X-TEST
X-Time-Spent
X-Front-Cache
X-Fastly-Backend-Reqs
X-No-Session
X-Pageid
X-Tradeindia-Request-GUID
X-Country
X-Beresp-Ttl
X-UT-Cache
Fastly-Drupal-Html
Origin-Vm
RSL-Trace-ID
X-CAMPUSSUITE-ENVIRONMENT
Language
X-Debug-Message
X-Mobile-Device
X-Az
X-Amz-Meta-Version-Id
X-Activity-Id
CmsfirstPublishTimestamp
X-Mobile-Device-Type
HA-Geocountry
HA-Geolat
X-SCProxy
HA-Geocity
HA-Cloudapp
BlockPHPCallEnd
X-Navigation-Version
X-Varnish-Cache-Control
X-VHosting-Cache
X-SuperCache
X-Served-From
X-Olaf
ID
X-Boot
X-VG-WebCache
X-SSL
X-OPNET-Transaction-Trace
X-UType
X-Cache-ID
HA-Geolon
X-XHR-Current-Location
X-Cachable
Request-Time
Progma
X-CGP
X-D2id
X-SEA-Instance-Name
X-Transaction-Name
AC-ELC
X-UPSTREAM-Address
X-Content-Type
X-BeResp-Ttl
X-Built-With
NKBVHEADER
X-HAProxy
HA-Servedtime
HA-Urlpath
HA-Ipaddr
HA-Host
HA-Georegion
X-ServiceProvider
X-Ruby-Cluster-ID
X-Jcms-Ajax-Id
X-Homeaway-Requestmarker
X-HP-CAM-COLOR
X-NginX-Upstream
L5d-Success-Class
X-Nginx-Page-Cache
X-Rocket-Nginx-Reason
X-Origin-Server
X-DDM-SERVER
X-Clx-Request
X-Proxy-Server
X-SCM-Server-Number
X-NodeID
X-Nginx-Request-Processing-Time
X-AMAZEEIO
NLCacheNote
Sl-Pgid
X-IP
X-Ms-Version
X-Ssl-Cipher
X-Who
X-PressLabs-Stats
X-ManagedFusion-Rewriter-Version
X-NMT-Proxy
X-Node-Id
X-Powered-By-ADS
X-Gannett-Site-Version
X-BServer
X-Bcwwwid
CDCHOST
Report-To
X-Airee-Node
X-BPool-Back
X-DDM-SERVER-UPDATED
X-CloudBurst-Backend
SB-Cache-Life
Returned-Status
SB-Cache-Remaining
SB-Site-Device
SB-Site-IE-VERSION
HitInfo
X-PoweredBy
X-BIT-Node
X-Rocket-Nginx-File
X-Requested-With
MachineName
MwpReleaseVersion
WebServer
Requested-Host
X-RemovedCookies
X-ProcessESI
X-ReqId
X-CloudBurst-Frontend
X-CloudBurst-Cache
X-CloudBurst-WordPress
X-MSU-SOURCE
X-Server-Ip
X-ASAP-Age
X-Pagely-Cache
X-JoinUs
X-Machine
X-Rewritten-By