Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
X-Cache
P3P
X-AspNet-Version
Strict-Transport-Security
CF-RAY
X-Pingback
Age
Content-Language
Via
X-UA-Compatible
Access-Control-Allow-Origin
X-Adblock-Key
X-Xss-Protection
X-Varnish
Upgrade
X-Cacheable
X-Check
X-Template
X-Language
X-Generator
Content-Security-Policy
X-Buckets
X-Drupal-Cache
P3p
X-Request-Id
X-AspNetMvc-Version
X-Type
X-Cache-Group
X-Pass-Why
X-Hacker
X-Ac
X-Powered-By-Plesk
Content-Location
X-Cache-Hits
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Download-Options
MS-Author-Via
Host-Header
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-ShardId
X-Sorting-Hat-Section
X-Dc
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-IPLB-Instance
Cartoon
Alt-Svc
X-Powered-CMS
Status
X-UA-Device
X-Served-By
Access-Control-Allow-Credentials
WPE-Backend
Access-Control-Allow-Headers
X-Via
Access-Control-Allow-Methods
X-Amz-Cf-Id
X-Iinfo
X-Request-ID
X-Backend
X-ServedBy
X-Cache-Status
X-Contextid
X-Timer
X-PC-Hit
X-PC-Key
X-Ua-Compatible
Powered-By
X-TEC-API-VERSION
X-PC-AppVer
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-PC-Date
X-PC-Host
X-Mod-Pagespeed
X-Logged-In
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
CF-Cache-Status
X-DIS-Request-ID
Keep-Alive
X-CDN
X-Tumblr-Pixel-1
X-Cache-Hit
X-Port
X-Server
X-Host
Content-Encoding
X-Tumblr-Pixel-2
X-Robots-Tag
X-Server-Powered-By
WP-Super-Cache
X-Rid
X-CST
X-Cache-Enabled
X-Pad
Referrer-Policy
X-Nginx-Cache-Status
X-Seen-By
X-Wix-Renderer-Server
X-Wix-Request-Id
Fastly-Debug-Digest
X-Accel-Version
X-Turbo-Charged-By
X-Page-Speed
X-Endurance-Cache-Level
X-Tumblr-Pixel-3
X-Content-Powered-By
X-Wix-PunisherID
X-Rack-Cache
X-Content-Digest
X-Drupal-Dynamic-Cache
X-Forwarded-For
X-Varnish-Cache
X-AH-Environment
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Surrogate-Key-Raw
SPRequestGuid
Content-Security-Policy-Report-Only
X-SharePointHealthScore
X-Proxy-Cache
X-Forwarded-Proto
MicrosoftSharePointTeamServices
X-Request-Country
X-Cnection
X-MS-InvokeApp
X-GitHub-Request-Id
X-XRDS-Location
X-Cache-Lookup
X-Original-Date
X-Safe-Firewall
X-Died
X-LiteSpeed-Cache
Cf-Railgun
Timing-Allow-Origin
MicrosoftOfficeWebServer
X-FullPageCaching
Edge-Control
X-Amz-Request-Id
X-Amz-Id-2
Request-Id
X-Node
X-Tumblr-Pixel-4
Charset
X-Webserver
X-FW-Hash
SPIisLatency
SPRequestDuration
X-FW-Type
X-FW-Static
X-FW-Serve
Composed-By
X-PhApp
X-CF-Powered-By
X-INKT-SITE
X-INKT-URI
X-Content-Security-Policy
X-Hits
Rating
Content-MD5
Access-Control-Max-Age
X-Swift-SaveTime
X-Swift-CacheTime
X-Hyper-Cache
Served-By
EagleId
X-Firenze-Processing-Times
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
Liferay-Portal
X-Spip-Cache
Access-Control-Expose-Headers
X-SERVER
Grace
X-HS-Cache-Config
X-Tumblr-Content-Rating
Edge-Cache-Tag
X-CDN-Pop
X-CDN-Pop-IP
X-HS-Content-Id
X-Server-Name
X-Device
X-BC-Stapler
X-Backend-Server
X-Newrelic-App-Data
X-Dw-Request-Base-Id
X-Microcache
X-Fastly-Request-ID
Request-Context
X-RateLimit-Remaining
X-RateLimit-Limit
X-VCache
X-RateLimit-Reset
X-ServerName
X-Jimdo-Instance
X-Jimdo-Wid
X-User-Agent
Content-Style-Type
X-FB-Debug
Content-Script-Type
X-Acc-Exp
Public-Key-Pins
X-Clacks-Overhead
Refresh
X-Cloud-Trace-Context
X-Cache-Config
Xkey
Real-Hostname
X-Loop
X-TNCMS
X-DDC-Arch-Trace
X-XN-XNHTML
X-XN-Trace-Token
Front-End-Https
Fpc-Cache-Id
X-Age
X-Generated-By
X-Tumblr-Pixel-5
X-Hostname
X-Microcachable
X-Cached
X-Url
X-DNS-Prefetch-Control
X-N-OperationId
PageSpeed
X-Px
Surrogate-Control
X-LiteSpeed-Cache-Control
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Display
Surrogate-Key
X-Pantheon-Phpreq
X-Pantheon-Environment
X-Pantheon-Site
X-Cached-By
X-MiniProfiler-Ids
X-WebKit-CSP
X-Content-Options
X-CMS-Version
X-Zen-Fury
X-Topify-Platform
X-SS-Conf
X-SS-Location
X-HOST
X-Outils-CS
Rt-Fastcgi-Cache
X-Request-Time
X-OneAgent-JS-Injection
X-StackifyID
X-Umbraco-Version
TCN
X-DynaTrace-JS-Agent
X-Handled-By
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-Whom
X-Amz-Version-Id
X-Ruxit-JS-Agent
X-AspNetWebPages-Version
Edge-Control-Message
Product
X-ApacheServer
X-PERF
X-Varnish-Cache-Hits
X-DynaTrace
X-Tumblr-Pixel-6
Host
Imagetoolbar
Alternate-Protocol
X-Cache-Rule
X-Powered-By-360WZB
WZWS-RAY
X-Magento-Tags
X-Micro-Cache
X-Kinsta-Cache
X-Engine
Powered
X-URL
X-Recruiting
X-Varnish-TTL
Fhost
X-NWS-LOG-UUID
X-VARNISH-Cache
ServedBy
X-Correlation-Id
X-CacheServer
X-Track
X-FORWARDED-FOR
Generator
DynaTrace
P-WS
P-LB
X-Edge-Location
X-Location-Id
X-Instart-Request-ID
X-Hosted-By
No
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processed-At
X-Vtex-Processado-Em
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Remote-Cache
X-B-Cache
X-Powered-By-VTEX-Janus-Edge
X-Upstream
X-RESOURCE
X-LBLID
X-Cache-Age
X-Response-Time
Akamai-IP
X-Goog-Hash
X-BS
X-I-Sp
X-Actual-URL
X-Varnish-Host
Origin
X-Returned-From
X-URLSCHEME
X-From
X-Returned-From-DLL
X-Passed-To
X-Passed-To-DLL
X-Original-Request
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Varnish-Backend
Fastcgi-Cache
X-Developer
X-LB
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Source
X-Returned-From-BeforeDispatch
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Varnish-Beresp-Ttl
X-Application-Context
X-App-Hosting
X-Stale
Pool
X-Defender
X-Shop-Id
X-Msg-2-Log
X-TransIP-Balancer
X-Cache-Info
X-Internal-ReqID
X-S
X-Fastcgi-Cache
X-Platform
X-I
IBM-Web2-Location
Content-Hash
X-Content-Encoded-By
X-Front
X-Matrix-Server
X-Matrix-Proxy
Expect-CT
X-Revision
X-Device-Type
X-Varnish-Cacheable
X-UD-Method
X-TransIP-Backend
X-Origin
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-Varnish-Seen-By
X-Expires-Orig
Powered-By-ChinaCache
X-LB-Node
X-Accel-Expires
X-VTEX-Cache-Status-Janus-Edge
X-Platform-Cluster
X-Daa-Tunnel
X-NetCat-Version
X-TTL
X-Firenze-Processing-Time
X-Powered-By-VelaWeb
X-Platform-Processor
X-Platform-Router
X-Cache-Tags
Version
HTTPS
X-Page-Cache
X-Cache-Operation
X-Signature
X-Route-Server
USPLoggingUUID
X-Server-ID
X-Dispatch
X-Version
X-Rocket-Nginx-Bypass
Cache-Tag
Ohc-File-Size
X-Akamai-Transformed
X-Translation
Last-Published
X-Cache-Debug
X-Microcache-Status
X-NoCache
Node
X-Storage
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Varnish-HitMiss
X-Gamma-Serve
X-Varnish-Count
X-HS-Content-Campaign-Id
X-Dispatcher
X-Cache-Only-Varnish
X-Hypernode
X-Cache-Lifetime
X-EdgeConnect-Origin-MEX-Latency
X-Cache-Control-Orig
X-Server-Upstream
X-Cache-Key
X-CJ-Soft
X-Supported-By
X-Github-Request-Id
Page-Completion-Status
Content-Disposition
Dmn
X-Abuse
SSPAppContext
MIME-Version
Srv
X-SSL-Cipher
X-EdgeConnect-MidMile-RTT
ServerName
X-Varnish-Age
X-Director
PICS-Label
X-Akamai-Device-Characteristics
X-SSL-Protocol
X-PwB-Node
FAI-W-FLOW
X-Last-Modified
X-ARC
X-F-Cache
X-Flow-Powered
X-SE-Debug
X-SDS
X-Magento-Cache-Debug
Lsrequestid
Cache-Key
X-Amz-Meta-S3cmd-Attrs
X-UPSTREAM
X-SV-CacheTags
X-ATG-Version
X-Country-Code
X-SV-Cacheable
X-SV-Duration
X-SV-FromDBCache
X-SV-Nginx-Duration
X-SV-Pid
X-Grace
X-SV-Expires
X-SV-CreatedAt
X-SV-Edge
Content-Encoding-Handler
X-Geo-Country
Cneonction
X-ORACLE-DMS-ECID
X-Cookie-Domain
X-Platform-Server
Accept-Encoding
Proxy-Connection
X-Duration
X-Art-Request-Id
X-Url-Base
IM-Version
If-Modified-Since
X-Content-Age
X-Platform-Cache
X-Cache-Engine
X-Edge-IP
Location
X-GeoIP-Country-Code
ServerID
X-Vcap-Request-Id
X-Internal-UserID
SN
S-Cnection
Req-Id
X-CDN-Cache-Status
X-Proxy
Allow
X-Client-IP
X-CDN-Node
X-Cache-Server
X-Server-Id
X-Orig-Vary
Accept-Charset
Pv
X-GeoIP-Country-Name
X-Processing-Time
X-Shield-Request-Id
X-ServerID
X-Nbs
X-Speed-Cache-Key
X-Speed-Cache
WSR-Cache
X-Debug
X-Middleware-Start
X-NB-Cached-Page
X-Abgroup
X-Sapient
X-Processed-By
X-Sucuri-ID
X-BackendServer
X-Srv
A-Powered-By
X-FW
X-RequestId
X-Akamai-Device-Model
X-N
X-Real-Server
X-PF-Uncompressing
X-AF-Userserver
X-Cache-Expires
X-Frontend
X-Discourse-Route
X-Pressidium-NinukisWP-Ver
Fw-Via
X-Lambda-Id
X-Cache-Level
X-NewRelic-App-Data
Section-Io-Id
X-AOL-HN
X-Varnish-Url
X-Time
X-VC-Enabled
X-IsCacheURL
X-Sucuri-Cache
X-VC-TTL
X-BKSrc
X-Goog-Storage-Class
Qs-Cache
Cached
Use-Proxy
X-Config-Blacklist-Version
X-DealerOn
X-Browser
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-SRCache-Key
Magicmarker
X-Always-Cache
S
X-Goog-Stored-Content-Length
Cm-Server
X-GUploader-UploadID
X-Loopia-Node
AMF-Ver
X-Goog-Generation
Identity
Author
EagleEye-TraceId
X-Worker
Server-Info
CacheControlHeader
X-TB-M
SRV
Tracecode
X-Magnolia-Registration
NnCoection
X-Nginx-Cache
X-Directory-Script
X-Cache-Type
X-Id
MC
X-Dns-Prefetch-Control
X-Empowered-By
Retry-After
SVR
Buuteeq-Source
X-Purge-URL
Backend
X-Varnish-Hits
X-Ttl
Nodo
MJ12bot
NetMindSessionID
X-Varnish-Hostname
Cache
X-Correlation-ID
X-Varnish-Ttl
HCVer
X-Framework
SEOMOZ
HAVer
X-Varnish-IP
X-Litespeed-Cache
X-WR-MODIFICATION
X-Cache-Fix
X-Cache-PageType
X-SmugMug-Values
X-TTFB
Smug-CDN
X-TTFB-L
X-Session-ID
X-Connection-Hash
X-Cache-Control
Nitro-Cache
X-Hit-Cache
X-Pagename
Cteonnt-Length
Content-Transfer-Encoding
X-Vhost
X-Twitter-Response-Tags
X-SmugMug-Hiring
X-Drectory-Script
X-Route-To
X-Traffic
X-Transaction
X-Adobe-Content
X-Adobe-Loc
X-Powered-By-Server
Server-Name
X-JG-Page-Cache
RTSS
X-OpenCart-Lightning
X-ACMCache
Keywords
X-Site-Name
X-Yadis-Location
X-Healthy
Local-Info
X-Environment
X-Resolver-IP
BALANCEDTO
X-Env
X-Magento-Cache-Control
X-LB-Server
Ufe-Result
X-Amz-Storage-Class
X-Served-Server
X-Unique-ID
Frame-Options
X-Purge-Host
Cache-Provider
X-FireWall-Port
X-Trace
X-Garden-Version
X-Sys-Req-ID
X-Fastly-Request-Id
X-WR-Flags
Thanks
X-Cache-Handler
X-ID
NODE
X-Content-Security-Policy-Report-Only
X-Runtime-Memory
X-Highwire-SessionId
X-SmartBan-Host
X-Highwire-RequestId
Description
SS
X-SmartBan-URL
HitType
X-Mobilized-By
X-LP
X-Generated
Xc-Version
X-Cocoon-Version
X-Cache-Dispatchercachecontrol
X-Cache-Dispatcherpragma
X-LW-Web-Server
X-CB-Server
X-VARITI-CCR
X-Author
X-Cache-TTL-Remaining
X-Cache-Device-Type
X-Cache-Node
X-ClientSide-Caching
X-Unbounce-Variant
X-Unbounce-PageId
X-Hiawatha-Cache
X-Server-Instance
X-Unbounce-VisitorID
X-Debug-Token
X-ORACLE-DMS-RID
X-CF-Passed-Proto
X-Balanceador
WWW-Authenticate
X-Cache-Doesi
X-Location
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Client-Image-Vid
X-Generated-Time
X-Client-Vid
X-EPiphany-Vid
Disablevcache
X-WN-ClientGroup
X-High-Performance
X-Varnish-Retries
WN
X-Webcelerate
X-DEBUG
X-HydroSheep
X-ARRServer
X-HP-Trace-ID
Front
X-Session-Reinit
Max-Age
X-EC-Security-Audit
X-OPNET-Transaction-Trace
X-Drupal-Cache-Tags
Dispatcher
Content_type
X-NginX-Cache
X-CAPServer
ServerSignature
X-Trace-Id
X-HP-Trace-Project
Web-App-Origin-Name
X-Disney-Akamai-Rule
ServerTokens
X-HTML-Minification-Powered-By
X-RiS-UFDI
Strikingly-Cached-Version
X-Distributor
X-App
X-Optimization
X-HITS
X-Rack-Cors
X-App-Status
Eomportal-Instance
Strikingly-Cached
From-Origin
X-WebKit-CSP-Report-Only
X-Domain-Checked
X-Nginx-Host
X-Provisioner-Version
Dis-Env
X-Site
X-Machine
X-AEM
X-Cf-Powered-By
Machine
OriginServer
SiteSpeed
Set-Cookie2
X-App-Server
Ohc-Upstream-Trace
Public-Key-Pins-Report-Only
X-Cache-Provider
X-CDN-Forward
X-Server-IP
X-HW
X-Varnish-ID
X-Config-By
X-Hosting-Env
X-Varnish-Server
X-SDE-Name
X-Jphone-Copyright
X-C2M-Server
X-C2M-Runtime
Access-Control-Allow-Method
IISExport
X-Varnish-Debug-TTL
X-Varnish-Debug-Age
X-Runtime-Rack
X-Cache-Keep
X-Culture
X-Cache-Source
X-Node-Name
X-WP
X-Smartcache-Timeout
X-Smartcache-Keys
X-Cache-CFC
Id
XDomainRequestAllowed
AsisCache
X-Esi
X-RealServer
X-We-Are-Hiring
X-Amz-Meta-Cb-Modifiedtime
X-Wikidot-Backend
X-CacheResult
X-GeoIP
X-Mobile-URL
X-Litespeed-Cache-Control
ScoreTracker
Og
X-Nginx
X-NginX-Server
X-Ser
WP-AdvCache-MemCached
X-A
X-Wikidot-Static-Cache
X-Server-Generated
X-GSL-Server
Nginx-Cache
X-Amcomm-Site
X-Dw-Trace-Id
X-Cache-Via
X-HashTwo
X-HA-Backend
X-HA-Frontend
CLMOB
X-Magento-Action
ViewMode
X-Rewrite
X-Page
X-Powered-By-Home.Pl
Expect-Ct
X-Pageid
X-Fpc
X-E
X-Bcwwwid
X-Avvio-Cms-Cacheload
CP
X-Desc
X-MAT-GEO
X-Detected-Device
Ttl
SG
Paypal-Debug-Id
Cluster-ID
X-Data-Request
Traffic-Origin
X-Blog
NLCacheNote
Hname
X-DataDome
X-Machine-Name
X-Cache-Detail
X-Viator-Tapersistentcookie
X-Remote-Addr
RN-Server
X-Lb
X-SV
X-Response
From
X-RDP
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-PageType
X-Grid-Server
TC-Cache-IC
X-Time-Microsecs
TC-Cache
Content-Server
X-Key
X-Refresh
TC-Cache-U
TC-S-Cache-M
X-Proto
Ctx
TC-S-Cache
Yoncu-Errno
Xc
X-App-Runtime
Sophnep-Edge-FX
X-SO
X-Clara-ASAP
X-IIJ-Cache
X-Runtime-Affili
X-DTC
X-Symfony-Cache
Ibf5scheme
N365rili
X-Hstore
X-ASAP-Cache
W
X-EC-Lua
X-Cdn-Forward
X-CRA-DC
X-Cache-On
X-MidCOM-Meta-Cache
MW-Webserver
X-ServerIndex
X-Fedora-School-Id
X-SERVER-NAME
Resin-Trace
X-CACHE-KEY
X-Resty-Request-Id
X-WA-Info
NS-VaryByCustom-Key
X-Atg-Version
X-Dynatrace-Js-Agent
X-UA
Cmstype
X-Beresp-Ttl
X-ReqId
X-Info
X-Render-Time
Cmsid
X-Batcache
MS-CV
Provider
Debug-Status
X-Frame-Option
X-Pagely-Cache
X-Forwarded-By
X-Header
X-7d-Instance-Id
X-7d-Trace-Id
X-Cache-Time
Warning
X-CDN-COMPRESS
X-Server-Instance-Name
X-Amz-Id-1
Mime-Version
SINA-LB
X-Nginx-Request-Processing-Time
X-Analytics
X-Distil-CS
X-CDN-RULE
X-Sc-Cache
X-AG-MIPS
X-Cacheable-TTL
SINA-TS
X-Depends
X-Rq
X-Application
X-Backend-Status
X-Autoru-LB
X-Autoru-Host
X-Cache-Warmer
X-Agent
X-Actindo-RS
X-OCTOPOD
Actual-Object-TTL
X-Airee-Node
X-Ezoic-Cdn
Response-Time
X-Zendesk-User-Id
X-AutoRu-App-Id
AGI-Request-ID
Access-Control-Request-Headers
X-Phpwcms-Page-Processed-In
NtCoent-Length
SHInfo
X-Webapp
X-Phpwcms-Release
DNNOutputCache
X-Zendesk-Origin-Server
X-Webstats-RespID
X-Ghost-Cache-Status
X-4ormat-Cacheable
X-Test
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
X-Atraveo-ETag
X-M
X-Atraveo-Param-Rm
X-HP-Redirect
X-UnsetCookies
Server-Ip
SBMCLOUD
X-Atraveo-Cache-Control
X-PRAM
X-Cache-Action
X-ProcessESI
Beyond-Iis
Webluker-Edge
X-RemovedCookies
X-Source-ID
X-Force
X-Atraveo-Set-Cookie
X-Dev
F5-IpCliente
Backend-Timing
X-Cms-Mode
Worker
Gzip
X-Hrouter
X-CACHE-TTL
ClientIP
X-Hosting
X-Atraveo-TTL
VServer
X-MCB-Server
Strikingly-Cache-Region
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
X-Compressed-By
PagesDisplayed
X-Nginx-Request-Time
X-Cache-Extended
X-KoobooCMS-Version
X-Varnish-Action
X-Cache-Varnish
X-Captured
SERVER-ID
X-RAMCache
X-Req-Head-Response
X-Map-Context
X-Middleton-PageSpeed
X-Drupal-Cache-Contexts
X-Webkit-Csp
Ibm-Web2-Location
X-HostName
Web
X-Client-Ip
X-Sid
X-Reflector-Cache
X-Reflector
X-Tag-Playlist
Device
X-ChromeLogger-Data
X-DB
X-DSS
X-Artvisual-Server
DrivedBy
X-This-Proto
Url
X-RSL
X-DW
X-RPM
X-RPS
Ews
X-Varnish-URL
X-Built-With
X-EC2-Instance-Id
X-MSEdge-Ref
X-Node-ID
X-WHOIS-Cached
MageStack-PageSpeed
Myheader
X-Varnish-VCL
X-VLoc
X-SCM-Server-Number
X-XHR-Current-Location
Brightspot-Id
Lb
X-Backend-TTL
X-Cms-Server
X-Nocache
Cleartype
X-FreeTag-Count
Httpd-Identifier
MSSmartTagsPreventParsing
MSThemeCompatible
StatusCode
Pics-Label
X-Varnish-Instance
X-HAProxy
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-Layout
X-PG
X-Router
X-FastCGI-Cache
X-Forwarded-Host
X-Router-Backend
X-Country
X-ELB
X-LBPoolMember
X-RiS-PX
X-Turpentine-Esi
MageStack-Magento-Version
X-Adnet
VANITY-HOST
X-Provided-By
X-Time-Zone
X-Server-FQDN
X-ServiceProvider
X-Streams-Distribution
MageStack-Loadbalancer
X-Cache-TTL-Age
X-Cache-TTL-Current
X-Generated-Date
Server-Hostname
X-Restarts
X-Serv
X-B2f-Not-Route
X-Enhanced-By
X-ASAP-Age
FastCGI-Cache-Status
Note
X-DS1D
X-Sites
X-Src-Webcache
Provided-Host
X-Ezpublish-Installationid
X-Ezpublish-Nodeid
X-RequesterIP
RequestId
X-Origin-Server
Bios
X-Proxy-Cache-Key
X-AMAZEEIO
DB-Nickname
AMFplus-Ver
X-VID
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
X-Server-Addr
X-Unique-Id
X-Meta-Imagetoolbar
X-Instance-Name
MageStack-Tag
MageStack-Web-Node
X-Fstrz
X-DI
X-Wm-1
X-Wm-VIP
MwpReleaseVersion
NZSpeedy
Server-ID
X-V
X-ACLR-Version
Container
X-WPL-DATA
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NewCloud-V-Cache
X-Secret
X-AppServer-Cache-Rule
AR-PoweredBy
AR-CACHE
X-Cluster
X-Container
X-Box
AR-SID
ENV
Drupal-Pagecache-Memcache
Content-Legth
Accept-Language
AR-ATIME
X-W3TC-Minify
X-Plat
X-SH-Cache-Status
X-Title
X-Upgrade-Enabled
X-Catalyst
X-Vary-Options
X-Frames-Options
X-REDIRECTSERVER
MageStack-Cache-Hits
X-Varnish-Cache-Local
Vserver
VAR-Cache
X-PBS-Appsvrname
X-PBS-Fwsrvname
X-PHP-Response-Code
MageStack-Area
X-PBS-Appsvrip
X-Domino-CacheValidationWithETagReason
Proxy-Cache
X-NewsFlow-Sitename
X-Obj-Ttl
X-Apm-Telemetry-Syncmark
X-WebNode
Fastly-Backend-Name
Home
X-Domino-CacheValidationWithETagResult
TP-Cache
TP-L2-Cache
COMMERCE-SERVER-SOFTWARE
Il-Cl
X-Deity
X-Cname-TryFiles
X-Len
RSB-LINK
X-CacheID
X-Cached-Status
X-PoweredBy
MageStack-Config
X-Varnish-Mode
MageStack-Debug
X-UseReverse-Proxy
X-Varnish-Auto-Cache-Miss
X-Svr
X-Served
X-UPSTREAM-Address
X-MSU-SOURCE
X-JSESSIONID
X-SuperCache
X-Serendipity-InterfaceLang
Kanooh-Host
Progma
UrlWatchModule-Time
Content-Cache
X-Serendipity-InterfaceLangSource
Hostname
X-Uncacheable
X-Obj.Ttl
X-VG-WebCache
X-DDM-SERVER-UPDATED
X-DDM-SERVER
Requested-Host
Server-Id
SB-Site-Device
X-Amz-Meta-Content-Md5
Session-Id
X-AWS
Cache-Ctrol
X-Cache-FS-Status
X-Rocket-Nginx-Serving-Static
Hamster
SB-Cache-Remaining
X-Search-Id
GP-Remote-Addr
BackendServer
X-Clx-Request
GP-Version
MageStack-Cacheable
MageStack-Cache-Status
SB-Cache-Life
MageStack-Cache-Lifetime
X-Made-On
MageStack-Cache
X-FF
X-CSRF-Token
X-Stage
X-ACCELERATE
X-Cluster-Node
X-ENV
X-DB-Content-Length
X-Lima-Id
PServer
X-Srcache-Fetch-Status
X-Oracle-DMS-ECID
X-Resource
X-Srcache-Store-Status
X-APP
X-PBY
X-SRV
X-VC-Debug
X-MainProfileURL
X-MainProfileName
X-MainProfileID
FindLaw
X-Not-Cacheable
X-Obvious-Info
X-Obvious-Tid
X-DEBUG-TTL
X-Grow-Guest
X-HASH
X-SilverStripe-Cache
X-Grow-Cache
X-Dynamic
X-Brought-To-You-By
X-MainProfileCategory
X-DeliveryServer
X-Bip
VC-NoCache
CommunityServer
X-FRUIT
Fw-Cache-Status
RSL-Trace-ID
WFE
SB-Site-IE-VERSION
X-Cache-Me-Harder
X-App-Version
Application
X-SCProxy
IsMobile
Prototype-RootPath
X-Accel-Cache-Control
X-FIRSTBase
X-Front-Cache
Lookup-Cache-Hit
Ez
Tk
X-Tt-Dbg
X-Dynamic-Cache
XDisk
X-W-Cache-Hits
X-No-Session
X-IP-Address
X-Tradeindia-Request-GUID
X-Tradeindia-SMgmt
X-W-Cache
X-Faeria
BlockPHPCallEnd
X-AISO-Server
X-AISO-Cacheable
X-Cache-V
X-ETag
X-PvInfo
X-Nginx-Page-Cache
X-AISO-Cache
WebServer
Origin-Content-Encoding
Cache-Tags
Proxy-Agent
Session-From
Type
CD4
Debug-Cache-Control
WSCLoggingUUID
Arrow-RequestId
X-ESI
X-SATserver
X-Theme
X-Vol-Mrp
X-Vol-Correlation
LCache
Debug-Expires
Returned-Status
X-Requestid
X-Varnish-Grace
Accept-CH
X-Varnish-Cached-TTL
HA-Servedtime
HA-Ipaddr
HA-Urlpath
IES-Server
L5d-Success-Class
HA-Host
HA-Georegion
HA-Geocity
HA-Cloudapp
HA-Geocountry
HA-Geolat
HA-Geolon
Load-Balancer
NKBVHEADER
X-Hcom-Styx-Info
X-Hcom-Origin-Id
X-MCF-ID
X-Sn-Servicetimems
X-Varnish-Cached
X-Group
X-CGP
X-B3-Spanid
Redkiwi-Cloud
X-B3-Traceid
X-Batcache-Reason
X-Cache-Origin
Apple-Itunes-App
X-Pj-Cache-Status
X-Scache
X-Skip-Cache
X-Geo-IP
X-XHTML-Minification-Powered-By
XX
Referer-Policy
Copyright
X-Static
X-Protected-By
X-UType
X-Rewritten-By
X-GRACE
Unique-Request-Id
Ina-Bwaf
X-Status
X-TargSmaku
X-Transaction-Name
X-Rack-CORS
X-Powered-Developer
MageStack-Response-Ttl
X-Pool-Info
MageStack-Cacheable-Reason
Developer
X-COUNTRY-CODE
X-LOCATION
ReqUrl
MachineName
MageStack-Cache-Warning
X-NMT-Proxy
X-ManagedFusion-Rewriter-Version
X-Ssl-Cipher
Cache-Status
AC-ELC
Aurora-Node
X-Varnish-Store
Language
X-FORWARDED-PROTO
Edgecast
X-Highwire-Sitecode
X-Instance
X-NodeID
X-Cache-Why
X-Pass-Through
X-Varnish-Set-Cookie
TheAnswer
X-BServer
X-BPool-Fx-Cache
X-Cjtype
X-Turpentine-Cache
X-Netrix-ID
X-Gannett-Site-Version
X-BPool-Bx-Cache
X-BPool-Back
X-Varnish-Esi-Access
X-Varnish-Esi-Method
X-Varnish-Currency
X-BC
X-BPool
X-Count
X-CH-Device
Aoestatic
EQ-Cache
X-Goog-Meta-Policy
X-Goog-Meta-Replace
X-Ss-Conf
X-NO-BREACH
X-Flex-Community
X-Does-He-Have-Time
X-Cache-ID
X-Beatles-Hits
X-Cache-Set
X-CCM
X-Content-Type-Option
X-Ss-Location
X-TTL-Age
X-Csrf-Token
X-Cache-LB
X-Debug-Message
X-Imforza-Hosted
X-Highwire-Smart-Code
X-Ocache
X-Cache-HT
X-Cache-BE
X-Your-GrandPa-Would-Wait
X-Would-Your-GrandPa-Wait
GranicusServer
Tempo
X-Amz-Meta-Version-Id
X-Beatles
X-Flex-Evend
X-Xrds-Location
X-DN-Cache-Control
X-Gyrobase-Publication
X-Varnish-Debug-Hits
X-NID
X-Name
LB
X-Cache-Id
X-Cachable
V-Age
PB-RID
PB-PID
X-Backend-Name
X-Origin-Cache
X-Pixelsilk-Server
X-Flex-Lastmod
EagleEye-TraceId-Daily
X-Flex-Lang
INFO
X-Flex-Evstart
X-Flex-Tag
X-Flex-Tags
X-PM-ID
X-Pixelsilk-Version
X-Real-IP
X-Reason-Bp
X-Magento-Lifetime
X-Processed