Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Set-Cookie
Server
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
P3P
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
X-Xss-Protection
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Adblock-Key
X-Varnish
Referrer-Policy
X-Request-Id
X-Check
X-Generator
X-Language
X-Template
X-Buckets
X-Type
X-Cache-Group
X-Pass-Why
X-Drupal-Cache
WPE-Backend
X-Permitted-Cross-Domain-Policies
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Alt-Svc
X-Download-Options
X-Ac
X-Hacker
X-Cache-Hits
Host-Header
X-AspNetMvc-Version
X-Sorting-Hat-Section
X-Dc
X-Alternate-Cache-Key
X-ShopId
X-ShardId
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-Via
X-Runtime
X-Powered-By-Plesk
X-Served-By
P3p
X-Contextid
X-PC-Key
X-PC-Hit
X-Amz-Cf-Id
X-UA-Device
X-PC-AppVer
X-ServedBy
MS-Author-Via
Content-Location
X-PC-Host
X-PC-Date
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-Timer
X-IPLB-Instance
X-Seen-By
X-Wix-Request-Id
Status
X-Rid
X-Ua-Compatible
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Cartoon
CF-Cache-Status
X-Tumblr-Pixel-1
X-Iinfo
Access-Control-Allow-Credentials
X-Backend
X-Tumblr-Pixel-2
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
X-Host
Content-Encoding
X-Endurance-Cache-Level
X-CST
Powered-By
X-Mod-Pagespeed
X-Cache-Hit
X-Port
X-FRAME-OPTIONS
X-Cache-Enabled
X-NewRelic-App-Data
X-CDN
X-Tumblr-Pixel-3
X-Newrelic-App-Data
X-Logged-In
Keep-Alive
X-DIS-Request-ID
X-Server-Powered-By
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server
X-Robots-Tag
X-Accel-Version
X-Request-ID
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Turbo-Charged-By
X-Proxy-Cache
X-Page-Speed
X-Content-Powered-By
Content-Security-Policy-Report-Only
X-GitHub-Request-Id
X-LiteSpeed-Cache
X-Content-Digest
X-FW-Hash
X-AH-Environment
X-FW-Server
X-Rack-Cache
X-Tumblr-Pixel-4
X-FW-Static
X-FW-Serve
X-FW-Type
X-Pad
Request-Context
X-Varnish-Cache
X-Hits
Edge-Control
X-Request-Country
X-Webcom-Cache-Status
X-XRDS-Location
X-Trace
SPRequestGuid
Access-Control-Expose-Headers
X-SharePointHealthScore
X-BC-Stapler
X-MS-InvokeApp
X-Node
WP-Super-Cache
Edge-Cache-Tag
Cf-Railgun
MicrosoftSharePointTeamServices
X-HS-Cache-Config
X-HS-Content-Id
X-Amz-Id-2
X-Amz-Request-Id
X-CF-Powered-By
X-HS-Combine-CSS
X-SERVER
Timing-Allow-Origin
Charset
X-Died
X-Content-Security-Policy
X-Cache-Lookup
X-Webserver
X-FullPageCaching
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
X-Cnection
Request-Id
X-PhApp
X-Fastly-Request-ID
Access-Control-Max-Age
X-Backend-Server
SPIisLatency
SPRequestDuration
X-Edge-Cache
X-Edge-Cache-Key
MicrosoftOfficeWebServer
CONTENT-SECURITY-POLICY
EagleId
X-Swift-SaveTime
X-Swift-CacheTime
X-SS-Conf
X-SS-Location
Composed-By
X-CDN-Pop-IP
X-CDN-Pop
Rating
X-Server-Name
X-Device
X-Tumblr-Pixel-5
Grace
Served-By
X-Safe-Firewall
X-DDC-Arch-Trace
Liferay-Portal
Ali-Swift-Global-Savetime
X-NF-Request-ID
X-Tumblr-Content-Rating
X-Dw-Request-Base-Id
X-Spip-Cache
X-Servedby
Front-End-Https
X-Cloud-Trace-Context
X-VCache
X-Hyper-Cache
X-HeyJason
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-Original-Date
Surrogate-Control
P-WS
P-LB
X-Cluster-Node
X-Microcache
X-LiteSpeed-Cache-Control
X-Loop
X-TNCMS
X-Clacks-Overhead
X-RateLimit-Limit
X-RateLimit-Remaining
X-StackifyID
Content-Style-Type
X-OneAgent-JS-Injection
X-Sol
X-FB-Debug
Display
X-Middleton-Display
X-Kinsta-Cache
Content-Script-Type
X-Middleton-Response
Response
X-Wix-Punisher
X-Acc-Exp
X-Jimdo-Instance
X-Jimdo-Wid
X-RateLimit-Reset
X-Vtex-Processado-Em
X-DNS-Prefetch-Control
Public-Key-Pins
X-Debug-Info
X-Firenze-Processing-Times
X-Age
X-Shopid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid-Cached
X-Sorting-Hat-Podid
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Featureset
X-Shardid
X-Amz-Version-Id
X-DynaTrace-JS-Agent
X-Magento-Tags
X-HOST
X-Tumblr-Pixel-6
X-Zen-Fury
Fpc-Cache-Id
X-User-Agent
X-XN-Trace-Token
X-XN-XNHTML
X-Goog-Hash
X-Ruxit-JS-Agent
X-Cached
X-Px
X-LW-Cache
X-N-OperationId
X-Cache-Config
X-Url
Xkey
X-Version
Wpe-Backend
X-WebKit-CSP
PageSpeed
X-Hostname
Retry-After
X-Topify-Platform
X-Upstream
Feature-Policy
X-Frame-Option
X-Generated-By
Refresh
X-Edge-Location
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Handled-By
Allow
TCN
Rt-Fastcgi-Cache
X-FORWARDED-FOR
X-Source
X-Whom
Access-Control-Request-Method
X-MiniProfiler-Ids
X-B-Cache
Fastcgi-Cache
X-Request-Time
X-Cached-By
X-Loopia-Node
X-From
Powered
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-EdgeConnect-Origin-MEX-Latency
X-ET-API-ROOT
X-ET-API-ORIGIN
X-ET-API-VERSION
X-URLSCHEME
X-Outils-CS
X-AspNetWebPages-Version
X-Fastcgi-Cache
Last-Published
X-RESOURCE
X-Content-Options
X-Magento-Cache-Debug
Product
X-EdgeConnect-MidMile-RTT
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-CMS-Version
ServedBy
X-DynaTrace
X-VTEX-Cache-Status-Janus-ApiCache
X-Powered-By-VTEX-Janus-ApiCache
No
X-VTEX-Janus-Router-Backend-App
X-CacheServer
X-Guploader-Uploadid
X-Accel-Expires
X-Vtex-Remote-Cache
X-Vtex-Processed-At
X-Tec-Api-Origin
X-Application-Context
X-Tec-Api-Root
X-Varnish-Cache-Hits
X-Tec-Api-Version
X-Signature
X-Response-Time
Warning
X-Varnish-HitMiss
X-Varnish-Count
Imagetoolbar
X-Varnish-Host
X-Platform-Server
Generator
X-Umbraco-Version
X-Cache-Info
X-Engine
X-UD-Method
X-S
X-NWS-LOG-UUID
Dmn
X-ApacheServer
X-PERF
X-Location-Id
Public-Key-Pins-Report-Only
X-Device-Type
X-Microcachable
X-Cache-Key
X-Passed-To
X-Passed-To-DLL
X-LBLID
X-Original-Request
X-Returned-From-DLL
X-Returned-From
Pagespeed
X-Developer
Host
X-Actual-URL
Cache-Key
Fhost
X-ARC
Cache-Provider
X-F-Cache
X-Recruiting
X-Msg-2-Log
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Returned-From-BeforeDispatch
X-Platform
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Micro-Cache
X-HS-Content-Campaign-Id
X-Stale
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
Alternate-Protocol
X-Hosted-By
X-Ezoic-Cdn
X-Defender
X-Shop-Id
DynaTrace
Surrogate-Key
X-Track
Arr-Disable-Session-Affinity
X-Translation
X-Microcache-Status
X-Platform-Cache
X-Akam-SW-Version
X-Instart-Request-ID
X-Lambda-Id
X-SSLUpstream
X-URL
X-Cache-Age
X-Dns-Prefetch-Control
X-SSLProxy
X-Cache-Rule
Content-Hash
Origin
X-Powered-By-360WZB
X-Forwarded-For
X-Magento-Cache-Control
Version
X-Acquia-Application-UUID
X-Via-JSL
MIME-Version
X-Rnd
X-BS
X-I-Sp
X-SO
X-SVR-IIS
X-Sapient
X-Svr-Proxy
X-Powered-By-VTEX-Janus-Edge
X-Cache-Tags
X-Dispatcher
X-Supported-By
USPLoggingUUID
WZWS-RAY
X-Duration
RTSS
Content-Disposition
SSPAppContext
Akamai-IP
S-Cnection
X-Director
X-Powered-By-VelaWeb
X-App-Status
X-Environment
X-CSRF-Protection
X-Abgroup
X-NetCat-Version
X-Correlation-Id
X-DealerOn
X-Cache-Namespace
X-Dealeron-Backend
X-Dealeron-Original-Url
X-TransIP-Balancer
X-Rocket-Nginx-Bypass
X-Art-Request-Id
Node
X-TransIP-Backend
X-I
X-Cache-TTL
X-Server-Id
Pool
X-Server-Upstream
X-App-Hosting
X-Page-Cache
X-SSL-Cipher
X-Debug
X-LB-Node
X-SSL-Protocol
X-Matrix-Server
Wsr-Cache
X-Matrix-Proxy
X-Varnish-Seen-By
X-Edge-IP
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-Varnish-RemainingTTL
X-Varnish-RemainingLife
FAI-W-FLOW
X-Daa-Tunnel
X-Correlation-ID
X-ORACLE-DMS-ECID
X-Revision
X-Generated
X-Drupal-Cache-Tags
X-ServerName
X-Hypernode
X-Expires-Orig
X-Cache-Handler
Update-Time
X-Cache-Lifetime
Src-Update
X-NoCache
X-Front
X-Varnish-Cacheable
X-Storage
SN
X-Server-ID
X-Vcap-Request-Id
X-Cache-Debug
X-Client-IP
X-Now-Id
X-Gamma-Serve
X-Route-Server
X-Hiawatha-Cache
X-Cache-Control-Orig
Accept-Encoding
SiteSpeed
X-Cache-Level
X-Amz-Meta-S3cmd-Attrs
X-VARITI-CCR
X-ATG-Version
X-SV-Cacheable
X-SV-CacheTags
Cneonction
X-LB-Server
X-SV-CreatedAt
X-SV-Pid
X-Vhost
Contao-Page-Layout
X-SV-Nginx-Duration
X-SV-FromDBCache
X-SV-Expires
X-SV-Edge
X-SV-Duration
ServerID
X-Grace
X-Rocket-Nginx-Serving-Static
X-GeoIP-Country-Code
X-Varnish-TTL
Req-Id
X-Discourse-Route
X-Acquia-Application-Trace
Content-Encoding-Handler
X-Url-Base
Powered-By-ChinaCache
X-Geo-Country
X-CJ-Soft
Cache
Edge-Control-Message
X-Cache-Server
X-SRV
X-Pressidium-NinukisWP-Ver
If-Modified-Since
X-Dispatch
X-Drupal-Cache-Contexts
X-Sucuri-ID
X-Litespeed-Cache-Control
X-Last-Modified
X-Flow-Powered
X-Esi
X-Ttl
X-Content-Type-Option
X-Cache-Only-Varnish
Lsrequestid
X-TransIP-Reserved
X-Country-Code
X-Cache-Expires
X-Locale
X-Varnish-Backend
Cache-Tags
X-Env
Backend
X-Trace-Id
X-Varnish-IP
X-Varnish-Age
X-Forwarded-Proto
X-Unbounce-PageId
X-Server-Instance
X-Unbounce-Variant
W
X-GeoIP-Country-Name
X-Unbounce-VisitorID
X-Firenze-Processing-Time
X-Content-Encoded-By
X-Sucuri-Cache
X-Cache-Engine
X-Speed-Cache
X-GUploader-UploadID
X-Speed-Cache-Key
X-Cache-Operation
X-Connection-Hash
X-Transaction
X-Varnish-Url
X-Twitter-Response-Tags
Service-Worker-Allowed
Smug-CDN
X-SmugMug-Hiring
X-SmugMug-Values
X-TTFB-L
X-TTFB
X-PwB-Node
X-Akamai-Device-Characteristics
X-Akamai-Device-Model
Proxy-Connection
MJ12bot
Strikingly-Cache-Region
X-Amz-Rid
SEOMOZ
X-Litespeed-Cache
X-ORACLE-DMS-RID
Strikingly-Cached
X-Middleware-Start
Strikingly-Cached-Version
X-FIRSTBase
X-Time
PICS-Label
X-Cookie-Domain
ServerName
Server-Name
Location
X-Always-Cache
X-SRCache-Key
Content-MD5
X-TTL
Custom-Header
X-High-Performance
Srv
X-Varnish-Retries
X-Webkit-CSP
X-Cache-Control
Nodo
X-Service-Id
X-CF-Passed-Proto
X-IsCacheURL
X-Now-Cache
X-WR-MODIFICATION
X-ServerID
NnCoection
FindLaw
From-Origin
X-SDS
X-LB
Page-Completion-Status
X-ID
Section-Io-Id
X-Wikidot-Static-Cache
X-BackendServer
X-N
X-Cache-Type
X-Magnolia-Registration
Swift-Performance
X-Frontend
X-Wikidot-Backend
AMF-Ver
Author
MC
X-Processing-Time
X-Empowered-By
X-Storage-Cache-Date
Pv
Use-Proxy
X-Origin
X-Storage-Cache
X-Varnish-Server
X-Srv
X-FW
X-Storage-Cache-Expires
X-Nginx-Cache
S
Qs-Cache
X-Xrds-Location
X-Content-Age
NetMindSessionID
X-Yadis-Location
X-Pantheon-Environment
X-Dynamic-Cache
Surrogate-Key-Raw
X-Symfony-Cache
Https
X-Key
X-Pool
Local-Info
X-Pantheon-Phpreq
X-BKSrc
Edit
Tracecode
X-CDN-Forward
X-FTR-Request-ID
X-Pantheon-Site
X-HW
Fw-Via
Server-Timing
X-Nitro-Cache
X-Real-Server
X-Amz-Meta-Content-Md5
X-Amz-Storage-Class
X-Cache-Device-Type
CacheControlHeader
X-Worker
X-Content-Security-Policy-Report-Only
X-Id
Content-Transfer-Encoding
X-VC-Enabled
Content_type
X-Nbs
X-Cache-PageType
X-Vip
X-ACMCache
X-Location
X-Cache-Fix
X-Shield-Request-Id
X-Varnish-Hits
Drupal-Pagecache-Memcache
X-Varnish-Ttl
X-Browser
X-NginX-Cache
Pics-Label
X-Analytics
X-FireWall-Port
X-Sedo-Request-Id
IM-Version
X-Distributor
X-Cache-Miss-From
Hummingbird-Cache
X-Shard
Access-Control-Allow-Method
X-WR-Flags
Ohc-File-Size
X-SP-UniqueName
Cm-Server
X-A
Ram
X-SP-Farm
Xc-Version
X-Orig-Vary
X-UPSTREAM
X-Unique-ID
Backend-Timing
Ramp
Prama
X-4ormat-Cacheable
Noq
X-Hit-Cache
HCVer
X-Pagename
HAVer
X-Role
X-Disney-Akamai-Rule
X-WPL-DATA
X-Varnish-ID
X-Config-Blacklist-Version
X-LW-Web-Server
X-App-Runtime
Accept-Charset
X-TB-M
X-ClientSide-Caching
IBM-Web2-Location
X-Yottaa-Optimizations
RequestId
X-Runtime-Affili
X-Yottaa-Metrics
X-Stage
X-Hstore
X-Runtime-Rack
X-Remote-Addr
X-RealServer
SRV
X-AEM
X-Hrouter
X-Cache-CFC
X-RequestId
X-Real-IP
X-V
Lb
A-Powered-By
X-Sys-Req-ID
X-App
X-Resource
X-Avg-Cookie-Expires
X-Akamai-Edgescape
Server-Info
X-AVG-Country-Code
X-Redman-Final-Url
X-Redman-Backend
X-E
Cached
X-JSESSIONID
X-SERVER-NAME
X-Drectory-Script
Identity
X-Adobe-Content
Accept-CH
AsisCache
X-Adobe-Loc
X-Hosting-Env
X-Cache-2
X-Proxy-Backend
X-Proxy
X-IIJ-Cache
Lookup-Cache-Hit
X-SDE-Name
Accept-Language
Web-App-Origin-Name
X-Span
X-GoCache-CacheStatus
Cteonnt-Length
X-Runtime-Memory
X-VC-TTL
X-Request-Uri
X-Framework
X-CLOUD-TRACE-CONTEXT
X-ARRServer
Server-ID
X-Varnish-Hostname
X-PRAM
X-Atraveo-Cache-Control
X-ServerIndex
X-NginX-Server
Nginx-Cache
X-Dw-Trace-Id
Firespring-Website-Id
X-Source-ID
X-Appmachine-Environment
WWW-Authenticate
Dtk-Cache-Check-0
X-Vcache
X-Rq
X-Atraveo-ETag
SHInfo
X-AF-Userserver
X-Atraveo-Zone
X-Path-Route
X-Force
X-Generated-Timestamp
X-PF-Uncompressing
X-Balanceador
X-Atraveo-Varnish-Server-Id
X-Fedora-School-Id
X-Atraveo-TTL
X-Atraveo-Param-Rm
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
X-Culture
X-Atraveo-Set-Cookie
X-CacheDebug
X-Pantheon-Az
X-Debug-Token
XDomainRequestAllowed
X-Ratelimit-Remaining
X-Ratelimit-Limit
Copyright
Access-Control-Request-Headers
X-Jphone-Copyright
X-Webstats-RespID
X-LP
Pf.Web.Request.Id
Request-Country
ScoreTracker
X-NWS-UUID-VERIFY
Request-EU
X-Varnish-Debug-Age
X-CB-Server
X-Distil-CS
X-Ratelimit-Reset
Beyond-Iis
X-Session-ID
X-Varnish-Debug-TTL
Environment
X-Frames-Options
SVR
X-RiS-UFDI
X-CacheFROM
VServer
X-SE-Debug
X-Rack-Cors
X-ESI
X-Server-IP
Thanks
X-Akamai-Transformed
Upgrade-Insecure-Requests
X-Nginx-Host
X-Cms-Mode
Worker
X-VCS-Ttl
X-Dev
X-Domain-Checked
X-Backend-Status
X-VCS-Cacheable
AR-PoweredBy
AR-CACHE
AR-ATIME
IISExport
Disablevcache
X-Provisioner-Version
CS-SERVER
X-App-Server
X-Cacheable-TTL
Url
AR-SID
WP-FROM-CACHE
X-Processed-By
X-Cache-Ttl
Front
Eomportal-Instance
X-Ms-Request-Id
X-JG-Page-Cache
CLMOB
X-EPiphany-Vid
Cmsid
Cmstype
X-Client-Vid
X-Client-Image-Vid
X-Req-Head-Response
X-Detected-Device
Referer
X-Purge-Host
X-Upgrade-Enabled
X-Purge-URL
NtCoent-Length
X-Proxy-Skip
Frame-Options
X-Map-Context
X-Consent-Required
X-GeoIP
X-HeBS-Cache-Status
X-Agent
Resin-Trace
X-7d-Trace-Id
X-Session-Reinit
Machine
X-Resty-Request-Id
X-Rebelmouse-Cache-Control
Myheader
X-Resolver-IP
X-Autoru-Host
X-CRA-DC
X-PBY
X-Cache-Dispatchercachecontrol
X-Upstream-Backend
X-Actindo-Request-Id
X-Adnet
X-Cache-On
X-Actindo-Thread-Id
From
X-7d-Instance-Id
X-Upstream-Status
X-MAT-GEO
X-Cache-Doesi
X-HTML-Minification-Powered-By
VANITY-HOST
X-Actindo-Rs
X-Aramark-SID
Max-Age
X-TKP-SRV-ID
X-Cache-Dispatcherpragma
AKA-DEVICE
AETN-State-Code
X-Oferteo-Domain
X-Header
Num
X-HA-Frontend
X-Data-Request
WP-AdvCache-MemCached
X-HashTwo
X-Amcomm-Site
AETN-Postal-Code
AETN-Country-Code
AETN-Country-Name
AETN-Area-Code
AETN-City
AETN-Continent-Code
X-Confluence-Request-Time
X-Amz-Id-1
AETN-Latitude
AETN-Longitude
AETN-EU
AETN-DEVICE
CF-Worker-Script
X-HA-Backend
X-Application
AMP-Redirect-To
Access-Control
Home
Il-Cl
Play-Detected-Device
X-Desc
X-WebNode
X-Rule
X-Proxy-Cache-Control
X-Soro
X-UA-Bot
X-Via-S
Play-Detected-UserAgent
Proxy-Cache
X-Plat
X-DSMX-Rewrite-MS
X-GSL-Server
X-Varnish-Cache-Local
Traffic-Origin
Paypal-Debug-Id
X-DSMX-Render-MS
X-B2f-Not-Route
X-Batcache
X-Domino-CacheValidationWithETagReason
X-Domino-CacheValidationWithETagResult
X-Cocoon-Version
*
X-Cdn-Forward
IES-Server
Cleartype
Dispatcher
X-Forwarded-Host
Load-Balancer
COMMERCE-SERVER-SOFTWARE
Adm-Server
Pramga
X-Varnish-URL
ServerTokens
X-Highwire-Sitecode
X-OpenCart-Lightning
X-HostName
Bios
X-Varnish-Action
X-Via-NSCOPI
X-DataDome
Dynatrace
X-Envoy-Upstream-Service-Time
X-Dynatrace
X-Compress-Hint
Web
X-Now-Trace
Now
X-SV
X-CACHE-TTL
Proxy-Agent
X-Highwire-Smart-Code
X-HydroSheep
ServerSignature
MageStack-Loadbalancer
MageStack-Cache-Hits
MageStack-Cache-Lifetime
MageStack-Cache-Status
MageStack-Debug
MageStack-Config
MageStack-Cache
MageStack-Cacheable
X-Cache-Detail
MageStack-Area
X-LBPoolMember
X-Qnm-Cache
X-Timestamp
Ttl
VAR-Cache
X-M-Reqid
X-M-Log
X-Flex-Lastmod
X-Flex-Tag
X-Flex-Tags
X-Geo
X-Beatles
MageStack-Web-Node
MageStack-Tag
MageStack-PageSpeed
Viewport
X-Test
X-DN-Cache-Control
X-Gyrobase-Publication
X-Served-Server
MageStack-Magento-Version
Prot
X-Fastly-Request-Id
X-Cache-Varnish
ServerNode
X-Highwire-RequestId
X-Bip
X-Amzn-Trace-Id
X-Varnish-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Highwire-SessionId
X-Response
X-Nx
X-Nx-All
X-Requestid
X-RiS-PX
X-Clara-ASAP
X-CAPServer
X-SmartBan-Host
X-SmartBan-URL
X-ASAP-Cache
N365rili
Ibf5scheme
X-Flex-Lang
DNNOutputCache
Aurora-Node
Dis-Env
X-WEBMGR-CACHE
X-SH-Cache-Status
X-Info
X-Middleton-PageSpeed
X-Ghost-Cache-Status
X-Directory-Script
X-Beget-Proxy
X-Skip-Cache
Yoncu-Errno
Access-Control-Allow-Header
Content
X-SilverStripe-Cache
X-Geo-IP
X-CacheID
X-Lb
FRONT-END-SECUREBROWSER
PServer
X-Garden-Version
X-AOL-HN
Provider
X-Protected-By
Fastly-Backend-Name
Edgecast
X-Blog
Fastly-Debug-Digest
X-MCB-Server
X-Secret
X-AutoRu-App-Id
X-Custom-Name
HitType
X-Generated-Time
X-Flex-Evstart
X-UnsetCookies
X-WebKit-CSP-Report-Only
X-Depends
X-Flex-Community
Magicmarker
X-Cache-Time
X-Flex-Evend
Device
X-WP
X-Appid
X-DB-Content-Length
X-Tag-Playlist
X-TLS-Version
X-Smartcache-Timeout
X-Served
X-Pj-Cache-Status
VSID
X-RAMCache
X-Sid
X-Smartcache-Keys
X-Access-Control-Allow-Origin
BackendServer
X-Vary-Options
X-FORWARDED-PROTO
X-Serv
X-Varnish-Ip
X-IP
NODE
X-Appversion
X-Deity
Serverid
X-Reflector
X-Reflector-Cache
NLCacheNote
Report-To
X-Gateway-Rate-Limit-Delayed
CommunityServer
X-ORIKEY
ViewMode
X-ROUTING
X-Varnish-Debug-Hits
X-FastCGI-Cache-Status
X-ENDPOINT
X-Cache-Me-Harder
X-APIVERSION
X-APIAUTH-VAL
SBSS
Webserver
Requested-Host
X-Clx-Request
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-MSU-SOURCE
X-PHP-Response-Code
X-Ms-Version
X-Nginx-Request-Processing-Time
X-RemovedCookies
X-Proxy-Server
X-ProcessESI
X-Origin-Server
X-ReqId
TP-L2-Cache
X-MainProfileURL
X-MainProfileName
X-MyName
X-NewsFlow-Sitename
X-PBS-Appsvrname
X-PBS-Appsvrip
X-MainProfileID
X-MainProfileCategory
X-Cache-FS-Status
SINA-TS
X-DynamicCache
X-Enhanced-By
X-Instance-Id
X-HS-Status
X-PBS-Fwsrvname
X-Status
CDCHOST
X-Compressed-By
AC-ELC
X-Reqid
X-Who
X-Svr
X-Cluster
X-Cache-Extended
TP-Cache
HSTS
X-Phpwcms-Page-Processed-In
X-Box
X-Cache-Action
Id
Description
X-Goog-Meta-Goog-Reserved-File-Mtime
Ufe-Result
TC-S-Cache-M
X-SAPP
Debug-Status
X-Client-Id
X-ACCELERATE
Tk
TC-S-Cache
TC-Cache-U
OracleCommerceCloud-Sandiego
EagleEye-TraceId
CommercePlatform-Version
OracleCommerceCloud-Version
ServerIP
TC-Cache-IC
TC-Cache
Session-From
X-Obvious-Info
X-Obvious-Tid
X-Nginx
X-ENV
X-Aramark-CSID
X-Page
X-We-Are-Hiring
CF-Cache-Key
X-Server-Generated
X-Cache-Warmer
YF-ID
X-ZSITES-DNS
X-FPC
X-Varnish-Grace
X-Origin-Date
Pragrma
X-Layout
X-Title
X-Static
CDN-Uid
CDN-RequestId
Keywords
Filters
SINA-LB
Og
Ohc-Response-Time
X-Beluga-Node
X-Beluga-Cache-Status
SB-Site-IE-VERSION
XX
X-VG-WebCache
NZSpeedy
X-Proxy-Id
X-Policy
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
X-SuperCache
Page-Template
X-AMAZEEIO
X-Beluga-Record
X-Beluga-Response-Time
X-Streams-Distribution
X-Refresh
X-DevSrv-CMS
Arrnode
BALANCEDTO
CDN-PullZone
CDN-CachedAt
CDN-Cache
SB-Cache-Life
SB-Cache-Remaining
X-Beluga-Trace
X-Beluga-Status
X-Beluga-Response-Time-X
X-Block-Rule
X-Block-RuleID
X-CacheLoc
SB-Site-Device
X-Phpwcms-Release
X-Proxy-Cache-Key
X-Goog-Meta-Policy
X-ETag
X-Goog-Meta-Replace
X-Rack-CORS
X-SCM-Server-Number
X-Varnish-Backend-Beresp-Backend
X-Test-Debug
X-Varnish-Cache-Ttl
X-Origin-Cache
X-NoIndex
X-Route
X-Shopware-Allow-Nocache
X-Shopware-Cache-Id
X-Rewritten-By
GranicusServer
X-HA
X-Node-Id
X-M
X-ManagedFusion-Rewriter-Version
X-Powered-By-Home.Pl
X-Cname-TryFiles
X-Cache-LB
MS-CV
HTTPS
X-Powered-By-ADS
Tempo
X-NodeID
X-Instance
X-W3TC-Minify
REFRESH
PBS
X-Backside-Transport
X-Firefox-Spdy
X-Global-Transaction-ID
X-FromPodPressCache
AMP-Access-Control-Allow-Source-Origin
X-Src-Webcache
X-Mighty-Proxy
X-Max-Age
X-Pass-Through
X-PM-ID
X-Search-Id
X-Now-Instance
Ssl-Proxy-Server
Hit-Count
Server-Id
Cf-Ipcountry
X-XHTML-Minification-Powered-By
X-EC2-Instance-Id
Purge-Cache-Tags
NGX
X-Vol-Mrp
X-Vol-Correlation
X-Wodby-Node
Response-Time
Hosted-By
X-Processed
X-Custom-Header
X-MrHost
X-BPool-Back
Nitro-Cache
X-Gannett-Site-Version
X-Say-Cacheable
X-SayCDN-TTL
Session-Id
X-ProBase-Server
X-MID-Host
X-BServer
X-CH-Device
X-Captured
X-Cache-Node
X-Build-Id
X-Webcelerate
Amfplus-Ver
WN
X-Say-TTL
MageStack-Cache-Lifetime-Sent
X-Airee-Node
MageStack-Cache-Warning
MageStack-Last-Modified
X-This-Proto
Provided-Host
X-WN-ClientGroup
X-V-Cache
X-Scheme
X-CACHE-KEY
X-Oracle-Dms-Ecid
X-COUNTRY-CODE
SERVER-ID
X-PROCESSED-BY
X-Server-Addr
X-Mobilized-By
X-DEBUG
Server-Ip
X-Oracle-DMS-ECID
X-RENDER-TIME
X-Actual-Url
X-Xml-Http-Blocked
PB-PID
LB
PROGMA
Amp-Access-Control-Allow-Source-Origin
PB-RID
X-Origin-Upstream-Status
X-ORIGN-SERVER
X-Router
X-Telligent-Evolution
X-Mobile-Rewrite
X-InDy-Time
X-InDy-Memory
X-InDy-Query
X-Grid-Server
Fastly-Restarts
Sl-Pgid
X-CloudBurst-Backend
X-BeResp-Ttl
X-HP-CAM-COLOR
X-Content-Type
X-Old-Content-Length
X-CloudBurst-Cache
X-FG-RequestId
X-CloudBurst-WordPress
X-JoinUs
X-Machine
X-CloudBurst-Frontend
X-Ssl-Cipher
Language
X-From-Cache
X-Cache-HT
X-GZip
X-Optimization
X-Varnish-Age-Debug
X-Appmachine-Name
X-Appmachine-Duration
X-NMT-Proxy
X-Ruxit-Js-Agent
X-Serverid
X-Appmachine-CreatedOn
X-Varnish-TTL-Debug
X-Enabled1
X-Vid
X-Tradeindia-SMgmt
ClientIP
F5-IpCliente
ProxiaInstanceId
Gzip
X-Tradeindia-Request-GUID
X-Pageid
X-Country
X-Beresp-Ttl
X-Fastly-Backend-Reqs
X-Front-Cache
X-No-Session
VC-NoCache
X-Avvio-Cms-Cacheload
X-Unique-Id
X-Amz-Meta-S3b-Last-Modified
Cache-Ctrol
X-Autoru-App-Id
X-SID
D
SERVER-NAME
X-Catalyst
X-Bitrix-Composite
X-Healthy
X-Middleton-Pagespeed
Actual-Object-TTL
RSL-Trace-ID
Origin-Vm
V-Cache-Ttl
PagesDisplayed
X-CAMPUSSUITE-DEBUGGING
X-CAMPUSSUITE-ENVIRONMENT
X-CSRF-Token
X-CAMPUSSUITE-TENANT
EQ-Cache
X-Enabled3
X-D2id
Servername
X-Cache-Id
X-ASAP-Age
X-Enabled2
X-Expires
X-Magento-Route
X-TEST
X-SSLTerm-Server
X-Time-Spent
X-UT-Cache
Fastly-Drupal-Html
X-Itkg-Cache-Tags
X-Accel-Cache-Control
X-SG-Server
X-PressLabs-Stats
X-UPSTREAM-Address
Generate-Time
Prototype-RootPath
Ews
X-Meta-Imagetoolbar
HA-Urlpath
HA-Servedtime
X-Log
L5d-Success-Class
ModuleCacheType
HA-Ipaddr
HA-Host
HA-Geocountry
HA-Geocity
HA-Geolat
HA-Geolon
HA-Georegion
NKBVHEADER
X-Cache-ID
EN-User
X-Bcwwwid
ID
X-VHosting-Cache
X-Varnish-Cache-Control
X-B3-Sampled
X-Boot
Request-Time
Progma
RN-Server
TYPO3-Pid
TYPO3-Sitename
HA-Cloudapp
X-Ser
X-Amz-Meta-Version-Id
X-Az
X-Activity-Id
X-WA-Info
X-PoweredBy
X-Cache-Via
X-Debug-Message
X-Mobile-Device-Type
X-SCProxy
X-Mobile-Device
Web-Server
Unique-Request-Id
X-Requested-With
X-Zendesk-Origin-Server
Backend-Powered-By
X-OPNET-Transaction-Trace
BlockPHPCallEnd
Content-Sn
DB-Nickname
X-Oracle-Dms-Rid
X-UType
X-Render-Time
X-Zendesk-User-Id
X-Qiniu-Zone
X-SSL
X-FastCGI-Cache
FastCGI-Cache
X-Server-Ip
SS
X-Transaction-Name
X-Pagely-Cache
X-Cache-TTL-Age
X-Navigation-Version
StatusCode
MSThemeCompatible
MSSmartTagsPreventParsing
X-Built-By
X-SEA-Instance-Name
X-Olaf
X-Cache-TTL-Current
X-Firewall
DrivedBy
X-Proto
MachineName
MwpReleaseVersion
Returned-Status
X-Node-App
X-Nginx-Page-Cache
X-Instance-Name
X-Hit
X-RequesterIP
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
Httpd-Identifier
CmsfirstPublishTimestamp
X-Jcms-Ajax-Id
X-Homeaway-Requestmarker
X-MCF-ID
X-NginX-Upstream
X-Ruby-Cluster-ID
X-HAProxy
X-Fpc
X-Served-From
X-Dck
X-Built-With
X-Cdn-Origin
X-CGP
X-ServiceProvider
X-Sn-Servicetimems
Arrow-RequestId
X-BIT-Node
X-Batcache-Reason
HitInfo
X-Cachable
X-Abuse
Xc
X-UPServer
X-Varnish-Cached
X-Varnish-Cached-TTL
X-XHR-Current-Location
WebServer