Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
CF-RAY
Age
X-Cache
P3P
Expect-CT
Content-Language
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Varnish
Referrer-Policy
X-Xss-Protection
X-Request-Id
X-Adblock-Key
X-Generator
X-Check
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-Drupal-Cache
X-Language
X-Template
X-Buckets
X-Permitted-Cross-Domain-Policies
X-Download-Options
Alt-Svc
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Ac
X-Hacker
Host-Header
X-Cache-Hits
X-ShopId
X-ShardId
X-Dc
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sorting-Hat-Section
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PrivacyLevel
X-Alternate-Cache-Key
X-AspNetMvc-Version
X-Via
X-Contextid
X-Served-By
X-Runtime
X-Powered-By-Plesk
X-PC-Key
X-PC-Hit
X-PC-AppVer
X-ServedBy
X-UA-Device
X-Amz-Cf-Id
X-PC-Host
X-PC-Date
MS-Author-Via
Access-Control-Allow-Headers
Content-Location
Access-Control-Allow-Methods
X-Timer
X-IPLB-Instance
X-Powered-CMS
X-Rid
X-Seen-By
X-Wix-Request-Id
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Status
X-Ua-Compatible
X-Tumblr-Pixel-1
CF-Cache-Status
Cartoon
X-Tumblr-Pixel-2
X-FRAME-OPTIONS
X-Backend
X-Iinfo
Access-Control-Allow-Credentials
X-WPE-Loopback-Upstream-Addr
X-Host
X-Cache-Status
X-Shopify-Stage
X-CST
Content-Encoding
Powered-By
X-Endurance-Cache-Level
X-Cache-Enabled
X-Cache-Hit
P3p
X-Port
X-Mod-Pagespeed
X-Tumblr-Pixel-3
X-Request-ID
X-CDN
X-Logged-In
X-Server-Powered-By
X-Drupal-Dynamic-Cache
Keep-Alive
X-DIS-Request-ID
X-Nginx-Cache-Status
X-Server
X-Robots-Tag
X-Accel-Version
X-Proxy-Cache
X-Turbo-Charged-By
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-LiteSpeed-Cache
X-Page-Speed
Content-Security-Policy-Report-Only
X-Content-Powered-By
X-Content-Digest
X-Tumblr-Pixel-4
X-GitHub-Request-Id
X-FW-Hash
X-FW-Server
Request-Context
X-AH-Environment
X-Rack-Cache
X-FW-Type
X-FW-Serve
X-FW-Static
X-Pad
X-Hits
X-Varnish-Cache
X-Webcom-Cache-Status
Edge-Control
Access-Control-Expose-Headers
X-XRDS-Location
X-BC-Stapler
X-Trace
X-Newrelic-App-Data
SPRequestGuid
X-Node
X-SharePointHealthScore
X-MS-InvokeApp
Edge-Cache-Tag
Cf-Railgun
WP-Super-Cache
X-HS-Cache-Config
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-Request-Country
X-Amz-Request-Id
X-Amz-Id-2
X-CF-Powered-By
Timing-Allow-Origin
X-Content-Security-Policy
Charset
X-Died
X-FullPageCaching
X-PHP-Backend
X-INKT-SITE
X-INKT-URI
X-HS-Combine-CSS
Request-Id
X-Cache-Lookup
X-Fastly-Request-ID
Access-Control-Max-Age
X-SERVER
X-Backend-Server
X-Cnection
SPIisLatency
SPRequestDuration
X-Edge-Cache
X-Edge-Cache-Key
Rating
Composed-By
X-Swift-SaveTime
X-CDN-Pop
X-CDN-Pop-IP
X-Swift-CacheTime
Ali-Swift-Global-Savetime
MicrosoftOfficeWebServer
X-Tumblr-Pixel-5
EagleId
X-DDC-Arch-Trace
X-Tumblr-Content-Rating
Grace
X-Server-Name
X-Device
X-SS-Conf
X-SS-Location
Served-By
X-Spip-Cache
X-NF-Request-ID
Allow
X-Safe-Firewall
Liferay-Portal
X-Dw-Request-Base-Id
X-VCache
X-Hyper-Cache
Front-End-Https
P-LB
P-WS
X-LiteSpeed-Cache-Control
X-Cloud-Trace-Context
Surrogate-Control
X-RateLimit-Remaining
X-RateLimit-Limit
X-OneAgent-JS-Injection
X-TNCMS
X-Loop
X-RateLimit-Reset
X-Original-Date
X-Cluster-Node
X-Servedby
X-Kinsta-Cache
X-Webserver
X-Middleton-Display
Display
X-Sol
X-Jimdo-Instance
X-Jimdo-Wid
X-Vtex-Processado-Em
X-HeyJason
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-PhApp
X-Middleton-Response
Response
X-NewRelic-App-Data
X-Firenze-Processing-Times
X-Acc-Exp
X-Clacks-Overhead
X-FB-Debug
Content-Style-Type
X-StackifyID
Content-Script-Type
X-Debug-Info
Public-Key-Pins
X-Tumblr-Pixel-6
X-DNS-Prefetch-Control
X-Amz-Version-Id
Feature-Policy
X-LW-Cache
Xkey
X-Age
X-Magento-Tags
X-Ruxit-JS-Agent
X-XN-XNHTML
X-XN-Trace-Token
X-WebKit-CSP
X-Goog-Hash
Fpc-Cache-Id
Refresh
X-Frame-Option
X-DynaTrace-JS-Agent
X-User-Agent
X-Cached
X-Zen-Fury
X-N-OperationId
X-Px
X-Cache-Config
X-HOST
X-Version
X-ARC
X-Hostname
Retry-After
X-Edge-Location
X-Generated-By
X-Microcache
X-Handled-By
PageSpeed
X-Url
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Topify-Platform
X-Goog-Metageneration
X-Upstream
X-Source
X-FORWARDED-FOR
Fastcgi-Cache
Rt-Fastcgi-Cache
Powered
X-Loopia-Node
Access-Control-Request-Method
X-MiniProfiler-Ids
X-EdgeConnect-Origin-MEX-Latency
TCN
X-Outils-CS
X-B-Cache
X-Magento-Cache-Debug
X-CMS-Version
X-ET-API-ROOT
X-ET-API-ORIGIN
X-EdgeConnect-MidMile-RTT
X-ET-API-VERSION
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-VTEX-Janus-Router-Backend-App
X-Request-Time
X-VTEX-Cache-Status-Janus-ApiCache
X-Powered-By-VTEX-Janus-ApiCache
X-CacheServer
No
WPX
Pagespeed
X-SRCache-Store-Status
X-SRCache-Fetch-Status
ServedBy
X-RESOURCE
X-Cached-By
X-URLSCHEME
X-Accel-Expires
X-Platform-Cluster
X-Engine
X-Platform-Processor
X-Dns-Prefetch-Control
X-Platform-Router
X-Application-Context
X-Varnish-Cache-Hits
X-Whom
X-AspNetWebPages-Version
X-Varnish-HitMiss
X-Content-Options
X-DynaTrace
X-Varnish-Count
Last-Published
Cache-Key
X-Fastcgi-Cache
X-Platform-Server
Warning
Public-Key-Pins-Report-Only
X-From
X-Developer
X-Location-Id
Imagetoolbar
Fhost
X-Cache-Info
X-Actual-URL
X-S
X-URL
Product
X-LBLID
X-Passed-To-DLL
X-Cache-Key
X-Passed-To
X-Original-Request
X-Returned-From
X-Returned-From-DLL
X-Microcachable
Host
X-Signature
Dmn
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-PERF
X-Returned-From-BeforeDispatch
X-Device-Type
X-Shop-Id
X-Stale
X-Defender
Generator
X-ApacheServer
Cache-Provider
X-Returned-From-PostProcessResponse
X-F-Cache
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Ezoic-Cdn
X-Response-Time
X-Varnish-Host
X-Platform
X-Umbraco-Version
Alternate-Protocol
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Cache-Age
X-Guploader-Uploadid
X-Powered-By-360WZB
X-Microcache-Status
X-Translation
X-Hosted-By
X-Magento-Cache-Control
Origin
X-Platform-Cache
X-Gateway-Cache-Key
X-Gateway-Cache-Status
Content-Hash
X-Gateway-Skip-Cache
Arr-Disable-Session-Affinity
X-NWS-LOG-UUID
X-Track
X-Via-JSL
X-Cache-Rule
X-SSLUpstream
X-HS-Content-Campaign-Id
X-Msg-2-Log
X-SSLProxy
X-Forwarded-For
Surrogate-Key
Version
X-Micro-Cache
X-BS
X-SO
X-I-Sp
X-Varnish-TTL
X-Cache-Tags
USPLoggingUUID
X-Sapient
X-DealerOn
X-Rnd
X-Dealeron-Original-Url
X-Dealeron-Backend
SSPAppContext
X-Lambda-Id
X-Powered-By-VTEX-Janus-Edge
DynaTrace
X-Cache-Namespace
X-Dispatcher
X-SVR-IIS
X-Svr-Proxy
X-Correlation-Id
WZWS-RAY
X-ORACLE-DMS-ECID
X-Cache-TTL
X-Environment
Content-Disposition
X-GUploader-UploadID
MIME-Version
X-Akam-SW-Version
S-Cnection
X-Duration
X-NetCat-Version
RTSS
X-Powered-By-VelaWeb
X-Instart-Request-ID
X-SSL-Cipher
X-Server-Upstream
X-Server-ID
X-CSRF-Protection
X-Supported-By
X-Director
X-TransIP-Balancer
X-UD-Method
X-SSL-Protocol
X-Debug
X-Front
X-App-Hosting
X-App-Status
Wsr-Cache
X-Art-Request-Id
X-TransIP-Backend
X-Correlation-ID
X-Hypernode
X-Page-Cache
X-Gamma-Serve
X-Abgroup
X-Expires-Orig
X-Drupal-Cache-Tags
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-VARITI-CCR
X-Generated
X-Cache-Control-Orig
X-Revision
FAI-W-FLOW
X-Matrix-Proxy
Pool
X-Amz-Meta-S3cmd-Attrs
X-Matrix-Server
X-I
X-Sucuri-ID
X-ATG-Version
X-Client-IP
X-Route-Server
X-Rocket-Nginx-Bypass
X-ServerName
X-Cdn
X-Cache-Lifetime
X-Vcap-Request-Id
Content-Encoding-Handler
Powered-By-ChinaCache
X-Cache-Debug
Update-Time
X-Edge-IP
X-Helper-Autoassign-All
X-Grace
Src-Update
X-Cache-Server
SN
X-Storage
X-Sucuri-Cache
X-Varnish-Cacheable
X-Content-Encoded-By
X-Geo-Country
Cache-Tags
Node
Cache
X-LB-Server
X-Github-Request-Id
X-Country-Code
X-NoCache
X-Flow-Powered
X-Env
X-Cache-Engine
X-SmugMug-Hiring
X-Discourse-Route
X-TTFB
X-Last-Modified
X-TTFB-L
X-SmugMug-Values
ServerID
Edge-Control-Message
Service-Worker-Allowed
X-Daa-Tunnel
Contao-Page-Layout
X-SRV
Smug-CDN
X-Recruiting
X-Rocket-Nginx-Serving-Static
Cneonction
X-SV-Edge
X-SV-Pid
X-Cache-Handler
X-FTR-Request-ID
X-SV-Nginx-Duration
X-SV-Expires
X-SV-CacheTags
X-SV-CreatedAt
X-SV-Duration
X-SV-Cacheable
X-SV-FromDBCache
CF-Worker-Script
X-UPSTREAM
Accept-Encoding
X-IsCacheURL
X-Esi
X-Forwarded-Proto
X-Varnish-Url
X-Drupal-Cache-Contexts
Strikingly-Cached-Version
X-Vhost
Strikingly-Cache-Region
Strikingly-Cached
X-Cache-Level
X-Now-Id
X-Locale
X-Server-Id
X-Dispatch
X-Varnish-Age
X-ORACLE-DMS-RID
X-Url-Base
X-Pressidium-NinukisWP-Ver
X-Firenze-Processing-Time
Req-Id
Lsrequestid
X-Cache-Only-Varnish
X-GeoIP-Country-Code
X-Middleware-Start
SiteSpeed
Author
X-FIRSTBase
X-Ttl
X-Cache-Type
If-Modified-Since
X-PwB-Node
X-Cache-Control
X-Time
X-Trace-Id
CF-Worker-Version
X-CJ-Soft
Server-Name
X-Varnish-Backend
X-NginX-Cache
Use-Proxy
X-TransIP-Reserved
X-Content-Type-Option
X-Varnish-IP
X-Unbounce-VisitorID
X-Cache-Expires
X-TTL
Akamai-IP
X-Hiawatha-Cache
X-Unbounce-Variant
X-N
Section-Io-Id
X-Unbounce-PageId
X-LB
X-Server-Instance
X-GeoIP-Country-Name
X-Transaction
X-SDS
X-Magnolia-Registration
X-Nginx-Cache
X-NA-CachePolicy
X-Twitter-Response-Tags
X-Connection-Hash
Location
Proxy-Connection
Custom-Header
X-Speed-Cache
X-Speed-Cache-Key
Server-Timing
AMF-Ver
Srv
PICS-Label
X-Cache-Operation
X-SRCache-Key
Page-Completion-Status
Backend
Https
X-Cache-Device-Type
X-Cache-Fix
X-Cache-PageType
X-LB-Node
FindLaw
Content-MD5
X-High-Performance
Nodo
X-Fastly-Request-Id
X-Akamai-Device-Model
X-Amz-Rid
X-Varnish-Retries
X-CF-Passed-Proto
X-Akamai-Device-Characteristics
S
MJ12bot
Accept-Charset
SEOMOZ
X-Empowered-By
X-FW
X-Wikidot-Backend
X-Wikidot-Static-Cache
W
IBM-Web2-Location
X-Service-Id
X-Content-Age
X-Rq
X-Config-Blacklist-Version
X-PF-Uncompressing
X-Processing-Time
X-Real-Server
X-BKSrc
NnCoection
X-Shard
NetMindSessionID
X-Cookie-Domain
ServerName
X-TB-M
X-Dynamic-Cache
Qs-Cache
X-Litespeed-Cache-Control
X-ServerID
X-Srv
Ohc-File-Size
From-Origin
Pv
Edit
Local-Info
X-Frontend
X-CacheFROM
X-Amz-Storage-Class
X-Now-Cache
X-Cache-2
X-BackendServer
X-Content-Security-Policy-Report-Only
X-Storage-Cache-Expires
X-Storage-Cache
X-A
X-Storage-Cache-Date
MC
X-Disney-Akamai-Rule
X-4ormat-Cacheable
X-Key
X-Symfony-Cache
Dtk-Cache-Check-0
X-WR-MODIFICATION
X-HW
X-SP-UniqueName
X-SP-Farm
Content_type
X-Browser
X-Worker
X-Adobe-Content
X-Nitro-Cache
X-ACMCache
X-CDN-Forward
X-Adobe-Loc
X-Ruxit-Js-Agent
Swift-Performance
Xc-Version
X-WEBSERVER
X-Processed-By
Content-Transfer-Encoding
X-Distributor
X-Nbs
X-Amz-Meta-Content-Md5
X-Runtime-Memory
Drupal-Pagecache-Memcache
X-Analytics
X-Webkit-CSP
X-ARRServer
X-ID
Pics-Label
Frame-Options
Tracecode
X-Stage
RequestId
X-Orig-Vary
Prama
X-WR-Flags
Cm-Server
Proxy-Agent
X-Cache-Miss-From
IM-Version
X-RequestId
X-Webstats-RespID
Cached
Backend-Timing
X-Sedo-Request-Id
X-CB-Server
X-JG-Page-Cache
CacheControlHeader
X-RealServer
HCVer
SHInfo
X-NginX-Server
X-App-Server
HAVer
X-Cache-TTL-Remaining
X-Hstore
X-EPiphany-Vid
X-Hrouter
X-Client-Vid
X-Remote-Addr
X-Client-Image-Vid
X-Shield-Request-Id
X-AEM
X-FireWall-Port
X-Redman-Backend
X-Sys-Req-ID
Adm-Server
X-GoCache-CacheStatus
X-Akamai-Edgescape
Cteonnt-Length
X-LP
X-Server-IP
X-Span
X-Drectory-Script
X-Request-Uri
X-Avg-Cookie-Expires
Pf.Web.Request.Id
X-Forwarded-Host
X-E
Server-Info
Access-Control-Allow-Method
X-Redman-Final-Url
X-AVG-Country-Code
X-VC-Enabled
X-Akamai-Transformed
X-CLOUD-TRACE-CONTEXT
X-Backend-Status
X-HydroSheep
X-Pantheon-Environment
X-Pantheon-Az
X-Pantheon-Site
Accept-CH
X-LW-Web-Server
Web-App-Origin-Name
Surrogate-Key-Raw
X-Session-ID
X-Cache-Ttl
Noq
Ram
Ramp
Url
X-Pantheon-Phpreq
Accept-Language
X-UnsetCookies
Lookup-Cache-Hit
X-Hit-Cache
X-Varnish-Server
X-Pagename
Front
X-Source-ID
X-Yottaa-Optimizations
X-Yadis-Location
X-Varnish-Hostname
X-Cache-Dispatcherpragma
Report-To
X-Role
X-Yottaa-Metrics
X-Force
Request-EU
X-HTML-Minification-Powered-By
X-Origin
Hummingbird-Cache
X-Proxy-Backend
X-Cache-Dispatchercachecontrol
X-RiS-PX
Environment
Request-Country
X-PRAM
SRV
X-Unique-ID
A-Powered-By
AsisCache
X-CAPServer
X-Culture
X-Appmachine-Environment
Nginx-Cache
IISExport
XDomainRequestAllowed
X-Distil-CS
Wpx
X-Nginx-Host
X-Real-IP
X-Debug-Token
WWW-Authenticate
X-Cacheable-TTL
X-Oneagent-Js-Injection
X-Framework
X-CacheDebug
X-Via-NSCOPI
X-HeBS-Cache-Status
X-Consent-Required
CDN-Cache
IES-Server
X-Always-Cache
Referer
Load-Balancer
NODE
X-Varnish-ID
Dispatcher
X-Varnish-Hits
X-SERVER-ID
X-Cache-Varnish
X-PBY
X-Unique-Id
X-Location
X-Purge-Host
X-WPL-DATA
X-Origin-Date
X-Jphone-Copyright
X-Purge-URL
X-Plat
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-GeoIP
X-App
Max-Age
X-Varnish-Debug-TTL
Eomportal-Instance
Access-Control-Request-Headers
X-Varnish-Debug-Age
Prot
X-Balanceador
X-Proxy-Cache-Key
X-CACHE-TTL
X-VCS-Cacheable
X-VCS-Ttl
X-Hosting-Env
X-WebNode
ScoreTracker
X-Generated-Timestamp
Copyright
X-Proxy
SVR
X-Envoy-Upstream-Service-Time
RN-Server
CDN-Uid
X-SDE-Name
CDN-RequestId
CDN-PullZone
CDN-CachedAt
X-Resource
X-Detected-Device
X-Map-Context
Pramga
X-WEBMGR-CACHE
X-V
X-Req-Head-Response
X-AOL-HN
Server-ID
Identity
Machine
Disablevcache
X-FastCGI-Cache
Lb
Dis-Env
X-Vcache
X-ClientSide-Caching
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
X-Atraveo-TTL
X-Atraveo-Expires
X-Atraveo-ETag
X-NginX-Upstream
X-Atraveo-Cache-Control
X-Atraveo-Varnish-Server-Id
X-Atraveo-From-Varnish-Cache
X-Atraveo-Zone
X-ETag
X-Middleton-PageSpeed
AETN-DEVICE
X-Cache-On
X-SE-Debug
Locale
X-MCB-Server
AETN-State-Code
Traffic-Origin
X-Amz-Apigw-Id
AETN-Country-Code
X-Resolver-IP
Upgrade-Insecure-Requests
AETN-Country-Name
AETN-EU
AETN-Latitude
TC-S-Cache
TC-Cache-U
TC-S-Cache-M
X-AF-Userserver
X-Amzn-RequestId
AETN-Longitude
AETN-Postal-Code
TC-Cache-IC
Access-Control-Allow-Header
X-JSESSIONID
X-Data-Request
AKA-DEVICE
TC-Cache
Cleartype
X-ACCELERATE
AETN-Area-Code
X-Upstream-Backend
X-HostName
X-SmartBan-URL
X-Response
XX
X-Upstream-Status
VServer
X-SmartBan-Host
X-Amcomm-Site
X-Highwire-RequestId
X-Rebelmouse-Cache-Control
X-Ms-Request-Id
X-Highwire-SessionId
X-Refresh
X-Amz-Id-1
X-Batcache
X-Id
X-VC-TTL
AETN-City
X-Nx
X-Nx-All
X-SAPP
X-HashTwo
X-HA-Backend
X-HA-Frontend
X-Garden-Version
X-Amzn-Trace-Id
X-CRA-DC
Filters
X-TKP-SRV-ID
X-Varnish-Grace
X-Runtime-Affili
BALANCEDTO
Arrnode
AETN-Continent-Code
AMP-Redirect-To
Worker
Nitro-Cache
X-FPC
X-ESI
*
X-MAT-GEO
X-Actindo-Thread-Id
X-Proxy-Cache-Control
VANITY-HOST
Myheader
X-Actindo-Request-Id
X-Actindo-Rs
X-App-Runtime
X-Via-S
CS-SERVER
Aurora-Node
X-Compress-Hint
X-Secret
X-Session-Reinit
Paypal-Debug-Id
DNNOutputCache
WP-FROM-CACHE
X-ServerIndex
X-GSL-Server
X-Soro
X-Xml-Http-Blocked
X-Desc
X-RiS-UFDI
X-Adnet
Num
Resin-Trace
X-ZSITES-DNS
Home
X-Confluence-Request-Time
X-Cms-Mode
X-Server-Addr
Yoncu-Errno
X-Amz-Meta-S3b-Last-Modified
X-Dev
X-Nginx
X-Cache-CFC
X-FastCGI-Cache-Status
Nopic
Beyond-Iis
Magicmarker
Description
X-Cocoon-Version
MICROSOFTOFFICEWEBSERVER
X-We-Are-Hiring
Og
X-Bip
Keywords
X-Smartcache-Timeout
Serverid
NLCacheNote
X-Goog-Meta-Replace
X-WP
Response-Time
X-Fstrz
X-Dw-Trace-Id
X-Goog-Meta-Policy
X-Smartcache-Keys
X-M-Reqid
X-WebServer
X-7d-Trace-Id
X-7d-Instance-Id
N365rili
FRONT-END-SECUREBROWSER
X-Webcelerate
Actual-Object-TTL
OracleCommerceCloud-Sandiego
X-Qnm-Cache
X-Domain-Checked
X-Proxy-Skip
X-Upgrade-Enabled
X-Depends
X-Dynatrace-Js-Agent
X-Instance-Id
X-Cdn-Forward
OracleCommerceCloud-Version
X-Autoru-App-Id
X-Country
X-SH-Cache-Status
X-Provisioner-Version
X-Varnish-Id
X-NWS-UUID-VERIFY
X-Title
X-Static
X-M-Log
X-SERVER-NAME
CommercePlatform-Version
X-Route
Fastly-Backend-Name
MageStack-Config
MageStack-Cacheable
MageStack-Cache-Status
MageStack-Debug
MageStack-Loadbalancer
Cmstype
MageStack-PageSpeed
MageStack-Magento-Version
MageStack-Cache-Lifetime
X-Varnish-Ttl
X-Path-Route
Access-Control
AC-ELC
Edgecast
MageStack-Area
MageStack-Cache-Hits
Cf-Ipcountry
MageStack-Cache
Cmsid
Srv-Name
Xc
X-Flex-Tags
X-LBPoolMember
X-Podname
X-Varnish-Action
X-Reflector-Cache
X-Reflector
X-Geo
X-Flex-Tag
X-Flex-Lastmod
X-Flex-Community
MageStack-Web-Node
MageStack-Tag
Viewport
X-Flex-Evend
X-Cache-Me-Harder
X-Flex-Lang
X-Flex-Evstart
X-Nginx-Dummy
X-Custom-Name
X-Page
X-Rule
X-Requestid
X-Oferteo-Domain
X-Hit
X-Fedora-School-Id
X-Frames-Options
DrivedBy
X-Captured
X-Varnish-Cache-Local
X-Header
X-Info
X-Autoru-Host
X-Generated-Time
X-PHP-Response-Code
CLMOB
X-CacheID
X-UA-Bot
Pragrma
X-Domino-CacheValidationWithETagResult
X-Client-Id
X-Cache-Doesi
Il-Cl
X-Status
X-Timestamp
X-Lb
Firespring-Website-Id
X-Varnish-Backend-Beresp-Backend
Play-Detected-Device
Play-Detected-UserAgent
X-B2f-Not-Route
X-Cache-Detail
X-Domino-CacheValidationWithETagReason
X-Aramark-SID
X-Aramark-CSID
Proxy-Cache
X-Mobilized-By
X-Application
X-Layout
CommunityServer
X-Proto
Provider
X-Directory-Script
NZSpeedy
X-DataDome
X-Served
X-Tag-Playlist
X-Access-Control-Allow-Origin
X-ReqId
Bios
X-Cache-Extended
X-DevSrv-CMS
X-UUID
TP-L2-Cache
TP-Cache
X-IP
Device
X-Deity
X-Appversion
ServerSignature
ServerTokens
X-SSL-Host
X-Scheme
MachineName
SS
MwpReleaseVersion
Tempo
X-Meta-Imagetoolbar
X-Instance-Name
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
Ttl
HTTPS
Fw-Via
X-ProcessESI
X-Proxy-Server
X-RemovedCookies
X-Serv
X-Origin-Server
X-Nginx-Request-Processing-Time
X-ASAP-Cache
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-IIJ-Cache
X-Cache-Via
X-Firewall
Id
Httpd-Identifier
X-Expires
MSSmartTagsPreventParsing
MSThemeCompatible
Hosted-By
X-Geo-IP
X-Varnish-Cached-TTL
X-Varnish-Cached
X-Pj-Cache-Status
X-Node-App
X-HA
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
X-Cache-LB
X-Clara-ASAP
X-Beatles
X-Cache-TTL-Age
X-Cache-TTL-Current
X-Cname-TryFiles
StatusCode
X-CSRF-Token
Server-Ip
ServerIP
Session-From
X-Server-Generated
X-HS-Content-Group-Id
X-Served-Server
X-Vary-Options
X-Origin-Upstream-Status
X-GZip
X-Mighty-Proxy
YF-ID
NGX
ViewMode
VSID
X-Cache-HT
X-GeoIP-Country
X-Optimization
X-PM-ID
PB-RID
PB-PID
PBS
REFRESH
X-Backside-Transport
GranicusServer
X-Global-Transaction-ID
X-Origin-Cache
X-Mobile-Rewrite
X-Src-Webcache
X-Instance
Thanks
Ssl-Proxy-Server
X-WA-Info
Apachenode
X-UPServer
X-Airee-Node
X-Blog
HitType
From
X-FromPodPressCache
CINC-Endpoint
X-Cache-FS-Status
X-Zendesk-User-Id
X-BPool-Back
X-BServer
X-Rewritten-By
X-Render-Time
X-W3TC-Minify
X-Cache-Date
X-Rack-CORS
X-Protected-By
X-NodeID
X-Built-By
X-Gannett-Site-Version
X-ManagedFusion-Rewriter-Version
X-Netrix-ID
EQ-Cache
X-Zendesk-Origin-Server
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Beluga-Trace
Web
X-Cache-Action
Amfplus-Ver
X-ProBase-Server
X-AppServer-Cache-Exception
X-Agent
X-AppServer-Cache-Rule
X-AppServer-Status
X-Box
X-CH-Device
X-Beluga-Response-Time
F5-IpCliente
X-Beluga-Record
X-Policy
X-UT-Cache
ClientIP
X-Beluga-Status
HSTS
X-Vid
X-Beresp-Ttl
X-RAMCache
X-Amzn-Remapped-Date
X-Fastly-Backend-Reqs
X-V-Cache
X-WN-ClientGroup
X-FORWARDED-PROTO
X-Rack-Cors
X-ENV
X-Time-Spent
X-Phpwcms-Page-Processed-In
X-Phpwcms-Release
X-HS-Status
X-Sid
X-SilverStripe-Cache
X-Pageid
X-Cluster
UrlWatchModule-Time
Webserver
SBSS
X-Compressed-By
X-SV
X-Ghost-Cache-Status
X-Streams-Distribution
X-Beluga-Node
X-Beluga-Response-Time-X
Debug-Status
X-This-Proto
ModuleCacheType
TYPO3-Pid
X-Proxy-Id
D
X-PBS-Fwsrvname
X-MCF-ID
Content-Sn
TYPO3-Sitename
VC-NoCache
X-Skip-Cache
X-Cdn-Origin
Content
X-PBS-Appsvrip
X-PBS-Appsvrname
X-Batcache-Reason
X-Avvio-Cms-Cacheload
X-Catalyst
X-EC2-Instance-Id
SINA-TS
X-DynamicCache
Session-Id
WN
X-Beget-Proxy
X-Middleton-Pagespeed
CF-Cache-Key
Gzip
ProxiaInstanceId
X-Beluga-Cache-Status
X-Server-Hostname
X-Processed
X-MyName
MageStack-Cache-Lifetime-Sent
X-Resty-Request-Id
Generate-Time
Provided-Host
MageStack-Cache-Warning
MageStack-Last-Modified
SINA-LB
Origin-Vm
Z
X-Clx-Request
AMP-Access-Control-Allow-Source-Origin
X-Ms-Version
X-OpenCart-Lightning
X-CACHE-KEY
X-Appid
X-Gateway-Rate-Limit-Delayed
X-MSU-SOURCE
PServer
X-Cache-Warmer
X-Serverid
X-WHO
MS-CV
X-RunCloud-Cache
X-Az
Tesla.Performance
X-Activity-Id
X-TLS-Version
VAR-Cache
TestCC
X-Custom-Header
X-DN-Cache-Control
X-MainProfileID
X-MainProfileName
Fastly-Debug-Digest
X-Vol-Mrp
X-Vol-Correlation
X-Wodby-Node
X-MainProfileURL
COMMERCE-SERVER-SOFTWARE
X-Gyrobase-Publication
X-NoIndex
NS-VaryByCustom-Key
ID
X-Cache-ID
X-Cache-Time
X-DB-Content-Length
Ews
X-Varnish-Ip
X-Served-From
X-Nws-Log-Uuid
X-Shopware-Allow-Nocache
X-Shopware-Cache-Id
X-Test
X-MainProfileCategory
196prxHost
X-Enhanced-By
X-ASAP-Age
Page-Template
X-LAKANA-AB
X-Request-Processing-Time
HitInfo
X-Request-Received
X-TNCMS-Bot-Tier
X-Built-With
X-Croise-Owner
X-AWS
Progma
X-ServiceProvider
AddDefaultCharset
NtCoent-Length
Apple-Itunes-App
Language
Www.Aujourdhui.Com
X-Appmachine-Duration
X-Appmachine-CreatedOn
NEL
X-Appmachine-Name
X-Enabled1
X-Enabled3
X-Enabled2
X-Bitrix-Composite
X-VC-Hash
X-InstanceId
X-Cjtype
X-Pool
X-VC-Cache
X-VC-Debug
X-VC-Cacheable
No-Cache
X-VG-WebCache
X-UPSTREAM-Address
X-Stiffia-Cache
X-OCTOPOD
129prxHost
135prxHost
259pxline
X-Varnish-URL
X-Dispatcher-Number
NB-Cache
X-B
X-ZORequestID
X-Req-Counter
X-T
X-Healthy
X-Transaction-Name
262prline
316pxxline
X-DDM-SERVER
X-Amz-Meta-Cb-Modifiedtime
Requested-Host
X-DDM-SERVER-UPDATED
X-Newrelic-Synthetics
X-Thanos
X-SuperCache
AR-SID
AR-PoweredBy
X-Author
Powered-By-115
X-Container
Xxline
AR-CACHE
AR-ATIME
X-Debug-Message
X-No-Session
X-AMAZEEIO
TTL
X-Apache2-RT-MicroSec
X-Build-Id
X-Client-Ip
Tk
SB-Site-IE-VERSION
PagesDisplayed
Origin-Edge-Control
SB-Cache-Life
SB-Cache-Remaining
SB-Site-Device
X-Itkg-Cache-Tags
X-Machine
Ibf5scheme
X-Say-Cacheable
X-User-Agent-Tier
X-Say-TTL
CDCHOST
X-SATserver
X-RequesterIP
X-Nginx-VM-RT
X-Obvious-Info
X-Obvious-Tid
X-Page-Cacheable
Origin-Cache-Control
X-UA
X-CacheLoc
Expiries
X-Block-RuleID
X-Block-Rule
X-B3-Sampled
X-Fpc
X-SG-Server
X-Powered-By-Home.Pl
X-Sn-Servicetimems
X-Cache-Bypass
X-Magento-Route
X-M
DB-Nickname
X-CAMPUSSUITE-TENANT
X-LB-Frontend
X-LB-Backend
X-Accel-Cache-Control
V-Cache-Ttl
X-Old-Content-Length
Prototype-RootPath
X-DODN-Region
X-CAMPUSSUITE-ENVIRONMENT
X-CAMPUSSUITE-DEBUGGING
Backend-Powered-By
X-DODN-Id
X-SayCDN-TTL
HA-Status
SERVER-NAME
X-Search-Id
X-Tradeindia-SMgmt
X-Varnish-Debug-Hits
Cache-Ctrol
X-ROUTING
X-PressLabs-Stats
X-Max-Age
X-Front-Cache
X-Tradeindia-Request-GUID
X-ORIKEY
WP-AdvCache-MemCached
Now
PROGMA
X-Now-Trace
X-InDy-Time
X-NewsFlow-Sitename
X-Reqid
X-Router
X-InDy-Query
X-InDy-Memory
Sl-Pgid
X-Firefox-Spdy
X-From-Cache
X-Grid-Server
X-ENDPOINT
X-APIVERSION
X-Pass-Through
BackendServer
X-Powered-By-ADS
Fastly-Drupal-Html
X-Rocket-Nginx-File
X-Node-Id
X-NMT-Proxy
Ohc-Response-Time
X-SSLTerm-Server
X-Abuse
X-TEST
X-Dck
X-Rocket-Nginx-Reason
X-SCM-Server-Number
RSL-Trace-ID
Purge-Cache-Tags
Value-Of-Url
X-Cache-Node
X-APIAUTH-VAL
Hit-Count
Fastly-Restarts
X-Test-Debug
X-Varnish-Cache-Ttl
X-WebKit-CSP-Report-Only
X-XHTML-Minification-Powered-By
X-Telligent-Evolution