Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
X-AspNet-Version
Age
P3P
X-Pingback
Content-Language
Via
X-UA-Compatible
Upgrade
Expect-CT
Access-Control-Allow-Origin
X-Adblock-Key
Content-Security-Policy
X-Cacheable
X-Check
X-Template
X-Language
X-Varnish
Alt-Svc
X-Generator
X-Buckets
X-Drupal-Cache
X-Request-Id
P3p
X-Type
X-Xss-Protection
WPE-Backend
X-Cache-Group
X-Pass-Why
Referrer-Policy
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Content-Location
Host-Header
MS-Author-Via
X-ShopId
X-Runtime
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId
X-Dc
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-ShardId
X-Sorting-Hat-PrivacyLevel
X-Alternate-Cache-Key
X-UA-Device
X-Powered-CMS
X-IPLB-Instance
X-Served-By
X-Sorting-Hat-FeatureSet
Cartoon
Access-Control-Allow-Methods
Access-Control-Allow-Headers
Access-Control-Allow-Credentials
X-Cache-Status
X-Amz-Cf-Id
Status
X-FRAME-OPTIONS
X-Via
X-Request-ID
X-Iinfo
X-Timer
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-ServedBy
X-Contextid
CF-Cache-Status
X-Ua-Compatible
X-PC-Key
X-PC-Hit
X-Mod-Pagespeed
X-PC-Host
X-PC-Date
X-PC-AppVer
Powered-By
X-Backend
X-CST
Content-Encoding
X-Host
X-WPE-Loopback-Upstream-Addr
X-Logged-In
X-CDN
X-Server
X-DIS-Request-ID
Keep-Alive
X-Rid
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Port
X-Cache-Enabled
X-Endurance-Cache-Level
X-Server-Powered-By
X-Tumblr-Pixel-1
X-Accel-Version
X-Original-Date
X-Nginx-Cache-Status
X-Robots-Tag
X-Drupal-Dynamic-Cache
X-NewRelic-App-Data
X-Page-Speed
X-Wix-Request-Id
X-Seen-By
X-Turbo-Charged-By
X-Tumblr-Pixel-2
X-Wix-Punisher
X-Content-Powered-By
X-Forwarded-For
X-Proxy-Cache
X-Content-Digest
X-Pad
X-AH-Environment
X-Forwarded-Proto
X-Varnish-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rack-Cache
WP-Super-Cache
X-LiteSpeed-Cache
Content-Security-Policy-Report-Only
X-GitHub-Request-Id
X-Request-Country
X-Tumblr-Pixel-3
SPRequestGuid
Edge-Control
X-MS-InvokeApp
X-XRDS-Location
X-SharePointHealthScore
MicrosoftSharePointTeamServices
X-Cache-Lookup
Timing-Allow-Origin
X-Cnection
X-Node
X-FW-Hash
X-Content-Security-Policy
X-Amz-Request-Id
Cf-Railgun
X-Amz-Id-2
X-FullPageCaching
X-FW-Serve
X-FW-Static
X-FW-Type
Charset
Request-Id
X-Trace
X-Webcom-Cache-Status
X-PhApp
X-Died
X-Hits
Request-Context
Edge-Cache-Tag
X-HS-Cache-Config
X-BC-Stapler
X-HS-Content-Id
X-CF-Powered-By
X-Newrelic-App-Data
X-PHP-Backend
SPIisLatency
X-INKT-SITE
X-INKT-URI
SPRequestDuration
X-Webserver
MicrosoftOfficeWebServer
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Safe-Firewall
Composed-By
X-Swift-SaveTime
EagleId
X-Swift-CacheTime
Grace
Served-By
X-CDN-Pop
X-CDN-Pop-IP
X-Spip-Cache
X-SERVER
X-VCache
X-Fastly-Request-ID
X-Hyper-Cache
X-Firenze-Processing-Times
Liferay-Portal
X-Backend-Server
X-Dw-Request-Base-Id
X-Tumblr-Pixel-4
X-Server-Name
X-Device
X-FB-Debug
X-Microcache
X-LiteSpeed-Cache-Control
X-StackifyID
Surrogate-Control
Xkey
Front-End-Https
X-Cloud-Trace-Context
X-SS-Location
X-SS-Conf
Refresh
X-TNCMS
X-RateLimit-Remaining
X-Loop
X-Clacks-Overhead
X-RateLimit-Limit
Content-Style-Type
X-RateLimit-Reset
Public-Key-Pins
Rating
X-DNS-Prefetch-Control
X-Jimdo-Wid
X-Jimdo-Instance
Content-Script-Type
X-Acc-Exp
X-DDC-Arch-Trace
X-XN-Trace-Token
X-HS-Combine-CSS
X-XN-XNHTML
X-User-Agent
X-Vtex-Processado-Em
X-Dscp-Value
X-Age
Fpc-Cache-Id
X-Cache-Config
X-WebKit-CSP
Response
Display
X-Middleton-Response
X-Middleton-Display
X-Sol
X-Px
X-ServerName
X-Hostname
X-N-OperationId
X-Topify-Platform
X-Generated-By
X-Url
X-Tumblr-Content-Rating
X-Cached
X-Zen-Fury
X-Correlation-Id
X-Tumblr-Pixel-5
X-MiniProfiler-Ids
X-Magento-Tags
Edge-Control-Message
X-Request-Time
X-Kinsta-Cache
X-OneAgent-JS-Injection
X-Whom
P-LB
TCN
P-WS
X-Handled-By
X-Outils-CS
X-Amz-Version-Id
PageSpeed
X-DynaTrace
X-B-Cache
X-Loopia-Node
X-Msg-2-Log
X-From
X-CMS-Version
Rt-Fastcgi-Cache
X-Debug-Info
ServedBy
X-Content-Options
X-DynaTrace-JS-Agent
X-Ruxit-JS-Agent
X-Varnish-TTL
Dmn
X-URL
X-LBLID
Imagetoolbar
X-Cached-By
X-Edge-Location
Access-Control-Request-Method
X-Upstream
Host
Product
X-Varnish-Cache-Hits
Public-Key-Pins-Report-Only
X-Location-Id
X-Goog-Hash
Powered
X-AspNetWebPages-Version
DynaTrace
X-Shard
Surrogate-Key
X-Cache-Rule
X-Engine
X-Cluster-Node
X-SRCache-Store-Status
X-CacheServer
X-Signature
X-SRCache-Fetch-Status
Fhost
X-F-Cache
X-FORWARDED-FOR
X-Via-JSL
Retry-After
X-Fastcgi-Cache
X-Platform-Router
X-Platform-Processor
No
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processed-At
X-VTEX-Janus-Router-Backend-App
X-Vtex-Remote-Cache
X-Accel-Expires
X-Platform
X-Passed-To
X-NWS-LOG-UUID
X-Actual-URL
X-LW-Cache
X-Original-Request
X-Platform-Cluster
X-Passed-To-DLL
X-Micro-Cache
X-Returned-From-DLL
X-Returned-From
Alternate-Protocol
X-Recruiting
X-Passed-To-BeforeDispatch
X-Varnish-Beresp-Grace
X-Passed-To-PostProcessResponse
X-Varnish-Beresp-Ttl
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Response-Time
X-Varnish-Beresp-Status
X-Umbraco-Version
X-Source
X-Stale
X-Hosted-By
Arr-Disable-Session-Affinity
X-Developer
X-Magento-Cache-Debug
X-Device-Type
X-Cache-Info
X-Version
X-HS-Content-Campaign-Id
X-Art-Request-Id
X-Rnd
X-S
X-Varnish-Host
Ohc-File-Size
X-Application-Context
Origin
X-UD-Method
Fastcgi-Cache
WZWS-RAY
X-Rocket-Nginx-Bypass
Cache-Provider
X-Supported-By
X-Powered-By-360WZB
X-URLSCHEME
X-ApacheServer
X-Instart-Request-ID
X-Microcachable
Generator
X-Matrix-Server
X-Matrix-Proxy
X-PERF
X-Shop-Id
X-Defender
X-TransIP-Balancer
X-Gamma-Serve
X-EdgeConnect-Origin-MEX-Latency
Pagespeed
X-Platform-Server
X-Dispatcher
Akamai-IP
X-TransIP-Backend
X-Litespeed-Cache
X-Cdn
X-Translation
X-Microcache-Status
X-I-Sp
X-RESOURCE
X-Track
X-Frame-Option
X-BS
X-App-Status
X-Storage
X-Tumblr-Pixel-6
Last-Published
Version
Content-Hash
X-App-Hosting
X-Server-ID
X-Platform-Cache
X-Route-Server
X-Cache-Age
X-Daa-Tunnel
X-Cache-TTL
X-HOST
X-Varnish-RemainingLife
X-Varnish-ObjectSource
X-Varnish-RemainingTTL
X-Varnish-Seen-By
X-Varnish-GracePeriod
X-Cache-Namespace
X-Varnish-HitMiss
X-I
X-Front
X-Varnish-Count
X-Hypernode
USPLoggingUUID
X-Flow-Powered
X-Powered-By-VelaWeb
X-ATG-Version
HTTPS
X-Cache-Tags
X-Cache-Key
X-Sapient
Allow
X-Drupal-Cache-Tags
X-Powered-By-VTEX-Janus-Edge
Pool
X-EdgeConnect-MidMile-RTT
X-NetCat-Version
X-Pantheon-Site
Surrogate-Key-Raw
X-Pantheon-Phpreq
X-Pantheon-Environment
Powered-By-ChinaCache
RTSS
X-Content-Encoded-By
X-CSRF-Protection
X-Duration
X-Expires-Orig
MIME-Version
X-ORACLE-DMS-ECID
X-Director
ServerID
X-WebServer
X-Firenze-Processing-Time
Content-Disposition
Cache-Key
X-Ttl
S-Cnection
X-Cache-Operation
X-SV-Duration
X-SV-CreatedAt
X-SV-Pid
X-Ezoic-Cdn
X-SV-Nginx-Duration
X-Vcap-Request-Id
X-SV-Edge
X-Varnish-Age
X-SV-FromDBCache
Lsrequestid
X-Vcache
X-Environment
X-Server-Upstream
X-SSL-Cipher
X-Last-Modified
X-Page-Cache
X-Abgroup
X-SV-Cacheable
X-SSL-Protocol
X-Cache-Debug
X-SV-Expires
X-SV-CacheTags
Cneonction
SSPAppContext
X-Drupal-Cache-Contexts
X-Generated
X-SDS
Wsr-Cache
X-Server-Id
Accept-Encoding
X-Magento-Cache-Control
AMF-Ver
SN
X-Revision
NnCoection
Pv
IBM-Web2-Location
FAI-W-FLOW
X-Client-IP
X-NoCache
X-Grace
X-Time
X-IsCacheURL
X-Hiawatha-Cache
X-Cache-Server
X-CJ-Soft
X-Lambda-Id
X-Cache-Control-Orig
X-Edge-IP
X-Debug
X-Varnish-Cacheable
Srv
Section-Io-Id
X-Gateway-Skip-Cache
X-Varnish-Ttl
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Amz-Meta-S3cmd-Attrs
Req-Id
X-Varnish-Url
X-ARC
X-PwB-Node
Node
X-Akamai-Device-Characteristics
X-LB-Node
X-Origin
Page-Completion-Status
Server-Timing
ServerName
X-Magnolia-Registration
Fw-Via
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
Backend
X-GUploader-UploadID
X-Cache-Lifetime
Location
X-Goog-Generation
X-Goog-Stored-Content-Length
X-ORACLE-DMS-RID
X-N
X-Cache-Expires
X-Bb-Deploy-Id
If-Modified-Since
X-TTL
X-UPSTREAM
X-Vhost
X-LB
X-Yadis-Location
X-Runtime-Rack
Server-Name
X-BackendServer
Content-MD5
X-Cache-Engine
X-ID
X-Akamai-Device-Model
X-GeoIP-Country-Code
X-Esi
Server-Info
X-Oneagent-Js-Injection
X-Nginx-Cache
X-Url-Base
X-WEBSERVER
Proxy-Connection
Nodo
PICS-Label
X-Cache-Type
X-ServerID
Content-Encoding-Handler
X-Content-Security-Policy-Report-Only
IM-Version
X-Content-Age
X-Amz-Storage-Class
X-Geo-Country
X-Dispatch
X-Real-Server
Content-Transfer-Encoding
X-App-Server
X-SO
X-Country-Code
X-FTR-Request-ID
Pf.Web.Request.Id
X-Varnish-Backend
X-RequestId
X-AVG-Country-Code
X-AOL-HN
X-Cache-Only-Varnish
Qs-Cache
X-Speed-Cache-Key
X-Avg-Cookie-Expires
X-Discourse-Route
X-Speed-Cache
Front
X-Processing-Time
X-Akamai-Edgescape
X-Frontend
X-Redman-Backend
Fastly-Debug-Digest
X-Redman-Final-Url
X-Middleware-Start
X-Config-Blacklist-Version
Cache
Accept-Charset
S
X-Cache-Level
X-HTML-Minification-Powered-By
X-Varnish-IP
Author
X-Always-Cache
Frame-Options
X-Empowered-By
X-Varnish-Retries
X-CF-Passed-Proto
X-High-Performance
X-FW
CacheControlHeader
X-Pressidium-NinukisWP-Ver
W
X-Cache-CFC
X-Rocket-Nginx-Serving-Static
Nitro-Cache
X-Cache-Device-Type
HCVer
X-Cache-Handler
HAVer
X-Cookie-Domain
X-GeoIP-Country-Name
X-SRV
Local-Info
Eomportal-Instance
X-VARITI-CCR
X-WR-Flags
Use-Proxy
X-Cache-Fix
BALANCEDTO
SRV
X-AF-Userserver
X-Nbs
X-Worker
X-Server-Instance
X-Cache-PageType
X-Sucuri-ID
X-Unbounce-PageId
X-Unbounce-VisitorID
X-Unbounce-Variant
X-PF-Uncompressing
X-Dealeron-Backend
X-Dealeron-Original-Url
X-DealerOn
X-Purge-Host
Cached
X-ACMCache
Environment
X-Rq
X-Stage
X-Location
Cache-Tags
X-Purge-URL
X-Proxy
WWW-Authenticate
X-BKSrc
X-Akamai-Transformed
X-Airee-Node
X-Env
X-Framework
MC
X-Dynatrace-Js-Agent
Thanks
X-Id
Adm-Server
X-Content-Type-Option
X-SRCache-Key
VANITY-HOST
X-Server-IP
X-Resource
Xc-Version
X-Browser
X-Client-Image-Vid
X-Hit-Cache
Pics-Label
X-Client-Vid
X-Sucuri-Cache
X-EPiphany-Vid
MJ12bot
IISExport
X-Shield-Request-Id
X-Litespeed-Cache-Control
NtCoent-Length
Custom-Header
X-Ruxit-Js-Agent
X-WPL-DATA
X-Pagename
Cache-Tag
X-Symfony-Cache
X-Garden-Version
X-Correlation-ID
Contao-Page-Layout
X-Varnish-Server
SEOMOZ
X-HW
X-Source-ID
X-CAPServer
X-Abuse
X-Akam-SW-Version
X-Akamai-3PM-SW-Version
From-Origin
X-Remote-Addr
X-Srv
X-TTFB-L
X-TTFB
X-SmugMug-Values
X-AEM
X-LW-Web-Server
Tracecode
Cm-Server
X-SmugMug-Hiring
X-CDN-Forward
X-CB-Server
Smug-CDN
X-HydroSheep
X-Trace-Id
X-Session-Reinit
X-Varnish-Hostname
X-WebKit-CSP-Report-Only
Accept-CH
NetMindSessionID
X-Cache-Control
X-Runtime-Memory
Identity
X-Webkit-CSP
Cmsid
X-JG-Page-Cache
Cmstype
X-Smartcache-Timeout
X-Atraveo-Set-Cookie
X-Atraveo-Param-Rm
X-Atraveo-TTL
X-Atraveo-Varnish-Server-Id
From
X-Atraveo-Zone
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
Ufe-Result
X-Page
X-Cacheable-TTL
X-Compress-Hint
X-Atraveo-ETag
X-Atraveo-Cache-Control
VServer
Proxy-Agent
X-WP
X-Mobilized-By
X-Locale
X-Drectory-Script
X-NginX-Cache
X-Omnis-SiteID
X-Smartcache-Keys
X-Cache-Dispatchercachecontrol
X-Cache-Dispatcherpragma
X-Real-IP
X-Time-Microsecs
Machine
X-ClientSide-Caching
X-OpenCart-Lightning
Beyond-Iis
X-IP
X-Provisioner-Version
NLCacheNote
X-Nginx-Host
X-Cdn-Forward
X-DEBUG
X-SmartBan-URL
X-Highwire-SessionId
X-Info
SVR
X-FW-Server
X-Highwire-RequestId
X-App
X-SmartBan-Host
X-PRAM
X-Adobe-Loc
X-Adobe-Content
RN-Server
Id
X-Domain-Checked
X-Directory-Script
X-Force
X-Unique-ID
X-LP
X-IIJ-Cache
ScoreTracker
X-WA-Info
Access-Control-Allow-Method
A-Powered-By
Ibf5scheme
X-Adnet
N365rili
Hamster
X-Cache-On
X-CRA-DC
SG
Swift-Performance
AC-ELC
X-Clara-ASAP
X-ASAP-Cache
X-Fedora-School-Id
SERVER-ID
X-RealServer
Service-Worker-Allowed
AsisCache
Access-Control-Allow-Header
X-W3TC-Minify
ServerTokens
Hummingbird-Cache
Disablevcache
X-Rebelmouse-Cache-Control
X-Secret
Accept-Language
X-GeoIP
X-Refresh
X-Sys-Req-ID
Backend-Timing
X-Plat
Description
Content_type
X-Orig-Vary
X-Hosting-Env
X-SDE-Name
HitType
Keywords
Server-ID
X-CACHE-TTL
X-Response
X-Viator-Tapersistentcookie
X-Rebelmouse-Surrogate-Control
X-Resty-Request-Id
X-Blog
X-RDP
X-FireWall-Port
X-RTag
X-Cache-Node
X-SERVER-NAME
X-Dns-Prefetch-Control
X-Analytics
X-WN-ClientGroup
EagleEye-TraceId
ServerSignature
WN
X-Ser
X-NodeID
X-Backend-Status
X-LB-Server
X-FPC
SS
X-Fstrz
Ohc-Response-Time
X-Request-Uri
X-Sites
X-Resolver-IP
X-Cache-Doesi
X-DTC
X-VC-Enabled
Bios
X-GoCache-CacheStatus
X-Connection-Hash
X-A
X-Batcache
X-VC-TTL
X-Transaction
X-Twitter-Response-Tags
X-Search-Id
NODE
X-MCB-Server
X-Route-To
X-Rewritten-By
X-ManagedFusion-Rewriter-Version
Fastly-Backend-Name
X-Server-Addr
X-Cf-Powered-By
X-ACCELERATE
Web-App-Origin-Name
X-TB-M
X-ServerIndex
X-Session-ID
Url
X-Rack-Cors
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Balanceador
X-Traffic
Yoncu-Errno
X-Varnish-Action
X-EC2-Instance-Id
X-FORWARDED-PROTO
X-Cache-Varnish
X-Captured
X-Webstats-RespID
EN-User
X-Render-Time
SBGI-Device
X-Cache-TTL-Age
SBGI-RealPath
SBGI-9
SBGI-10
SBGI-RenderTime
X-BPool
SBGI-5
X-Cache-TTL-Current
X-BServer
Resin-Trace
X-BPool-Bx-Cache
X-BPool-Back
X-BPool-Fx-Cache
X-Debug-Token
Home
X-Depends
Og
SBGI-7
Gzip
F5-IpCliente
ClientIP
X-Cache-Via
X-Grid-Server
X-Key
X-Distil-CS
X-Layout
X-CacheID
X-Lb
X-Map-Context
X-Powered-By-Home.Pl
X-Protected-By
X-Origin-Server
SBGI-1
X-PROCESSED-BY
X-Autoru-LB
X-Autoru-Host
X-Proxy-Cache-Key
X-Gannett-Site-Version
X-Src-Webcache
X-Req-Head-Response
X-Title
X-RiS-UFDI
X-Redirector
X-AutoRu-App-Id
Magicmarker
X-Agent
X-ARRServer
SHInfo
Play-Detected-Device
Max-Age
Paypal-Debug-Id
Play-Detected-UserAgent
X-4ormat-Cacheable
X-DataDome
X-Machine
X-Disney-Akamai-Rule
Edit
X-Cocoon-Version
X-Webcelerate
X-Culture
X-Varnish-Id
X-Varnish-Debug-TTL
X-Node-Name
X-Desc
X-E
X-Bip
TheAnswer
RequestId
Report-To
X-NginX-Server
X-MAT-GEO
Xc
Myheader
X-Varnish-Debug-Age
X-Varnish-ID
XDomainRequestAllowed
Ram
Ramp
X-Serv
Noq
X-Highwire-Sitecode
X-Client-Ip
Dis-Env
Web
X-Highwire-Smart-Code
Ctx
X-Sid
X-Role
X-Forwarded-Host
X-Amz-Meta-Cb-Modifiedtime
X-Middleton-Pagespeed
X-V
Lb
X-Detected-Device
X-Jphone-Copyright
X-Batcache-Reason
X-Goog-Meta-Goog-Reserved-File-Mtime
AMP-Access-Control-Allow-Source-Origin
X-Pagely-Cache
Device
X-Distributor
SiteSpeed
NZSpeedy
X-Amz-Meta-Content-Md5
X-SCM-Server-Number
Hostname
X-UnsetCookies
Www.Aujourdhui.Com
X-Who
Prama
DrivedBy
X-Cjtype
X-ZSITES-DNS
X-Nginx-Request-Processing-Time
Language
X-Varnish-Grace
Upgrade-Insecure-Requests
X-Dw-Trace-Id
X-CacheDebug
X-SH-Cache-Status
X-Compressed-By
X-DynamicCache
X-JSESSIONID
X-Hosting
X-Header
X-ESI
Edgecast
X-Amcomm-Site
X-Proxy-Skip
MS-CV
X-Amz-Id-1
X-App-Runtime
X-Geo-IP
X-Cache-Me-Harder
X-Runtime-Affili
X-Wikidot-Backend
X-Origin-Id
X-GSL-Server
X-Ghost-Cache-Status
X-Rewrite
X-Zendesk-Origin-Server
X-Zendesk-User-Id
SINA-LB
X-Confluence-Request-Time
OracleCommerceCloud-Version
Backend-IP-Port
SINA-TS
X-Wikidot-Static-Cache
Backend-Name
BackendServer
OracleCommerceCloud-Sandiego
CommercePlatform-Version
X-Rack-CORS
X-OPNET-Transaction-Trace
X-B2f-Not-Route
X-Aramark-SID
TZ-Server
X-Cluster
X-DB-Content-Length
X-Generated-Time
X-Frames-Options
X-DN-Cache-Control
X-MidCOM-Meta-Cache
Proxy-Cache
X-XHTML-Minification-Powered-By
X-Varnish-Cache-Ttl
X-Old-Content-Length
CLMOB
COMMERCE-SERVER-SOFTWARE
MW-Webserver
Il-Cl
X-Gyrobase-Publication
X-Svr
X-Cache-Time
Apachenode
Traffic-Origin
X-Data-Request
X-Goog-Meta-Policy
X-HashTwo
X-Goog-Meta-Replace
X-Skip-Cache
Warning
Content-Generator
X-Varnish-Hits
X-Varnish-Cache-Local
ID
NS-VaryByCustom-Key
PagesDisplayed
OriginServer
X-Node-Id
X-ReqId
X-7d-Instance-Id
X-Config-By
X-D-Time
X-Generation-Time
X-VNode
X-7d-Trace-Id
Kanooh-Host
Progma
X-Mobile-URL
X-HP-Trace-Project
X-HAProxy
X-Streams-Distribution
XX
Requested-Host
X-Bcwwwid
X-ServiceProvider
X-S-Misc
X-Nitro-Cache
X-PHP-Response-Code
Nginx-Cache
Cteonnt-Length
X-Application
X-Phpwcms-Page-Processed-In
X-Phpwcms-Release
X-SE-Debug
X-Sentry-ID
X-KoobooCMS-Version
X-Hash
X-DDM-SERVER
Dispatcher
X-DDM-SERVER-UPDATED
X-SuperCache
X-Acquia-Debug-Password
X-Artvisual-Server
X-Processed-By
X-CACHE-KEY
Cleartype
Actual-Object-TTL
X-SV
X-VG-WebCache
X-VTEX-Cache-Status-Janus-Edge
X-Built-With
X-Proxy-Id
X-Meta-MSThemeCompatible
X-Proto
X-SilverStripe-Cache
X-Meta-MSSmartTagsPreventParsing
X-Meta-Imagetoolbar
MSThemeCompatible
SB-Cache-Life
X-FG-RequestId
X-Enhanced-By
SB-Site-Device
SB-Cache-Remaining
Page-Template
SB-Site-IE-VERSION
X-HP-Trace-ID
X-DS1D
X-ASAP-Age
MSSmartTagsPreventParsing
Server-Ip
X-Actindo-Rs
X-Varnish-Cached-TTL
X-ServerAddr
X-Actindo-Thread-Id
X-Varnish-Cached
X-UPServer
X-Script
X-Actindo-Request-Id
Provider
X-MCF-ID
X-AMAZEEIO
X-AISO-Cacheable
X-NID
VC-NoCache
X-AISO-Cache
X-Reflector-Cache
TP-Cache
X-Origin-Cache
X-Upgrade-Enabled
PServer
TP-L2-Cache
X-PM-ID
X-Reflector
Aoestatic
X-Cms-Mode
Strikingly-Cached
X-LBPoolMember
MyHeader
X-Tag-Playlist
X-Magento-Lifetime
X-CacheResult
Strikingly-Cached-Version
Ttl
X-Author
X-Magento-Action
Viewport
Strikingly-Cache-Region
X-Cache-Detail
X-Dev
X-HS-Status
Ews
Worker
X-AISO-Server
Unique-Request-Id
HA-Geocity
X-Reqid
X-Uncacheable
X-MSU-SOURCE
X-PoweredBy
HA-Cloudapp
BlockPHPCallEnd
X-Qnm-Cache
X-Qiniu-Zone
X-REDIRECTSERVER
DB-Nickname
X-Clx-Request
X-UType
X-Distributed-By
X-Via-NSCOPI
X-Nginx-Request-Time
X-NewsFlow-Sitename
X-PBS-Appsvrip
X-PBS-Appsvrname
X-SSLProxy
X-PBS-Fwsrvname
X-MyName
X-Instance-Id
X-Catalyst
X-Cache-FS-Status
X-Container
X-Healthy
X-HP-CAM-COLOR
X-SSLUpstream
X-Svr-Proxy
X-Cache-Extended
X-Box
X-Hrouter
X-Hstore
X-M-Log
X-Log
X-Backend-Host
X-Avvio-Cms-Cacheload
HA-Geocountry
X-UPSTREAM-Address
X-WebNode
Fastly-Restarts
FRONT-END-SECUREBROWSER
X-M-Reqid
Response-Time
X-TA-CDN-Provider
X-SATserver
X-RequesterIP
X-RemovedCookies
CDCHOST
X-Ants-Host
X-COUNTRY-CODE
X-Cache-Ttl
X-Ants-Machine-Id
X-ProcessESI
X-Original-IP
Tk
Request-EU
Request-Country
Dtk-Cache-Check-0
WSCLoggingUUID
X-Feed
X-Obvious-Tid
X-Obvious-Info
X-Instance
X-Custom-Name
X-Pubstack
X-Max-Age
X-Global-Transaction-ID
X-Flex-Tags
X-Flex-Tag
X-Nginx
X-Pool
X-We-Are-Hiring
X-Profiler
X-PressLabs-Stats
X-Flex-Lastmod
X-Flex-Lang
X-Backside-Transport
V-TTL
HSTS
X-Test-Debug
X-CD
X-Device-Item
X-Flex-Evstart
X-Flex-Evend
X-Flex-Community
X-Server-Generated
X-Dynamic-Cache
X-Fpc
X-CGP
X-B3-Traceid
X-B3-Spanid
X-FreeTag-Count
X-Homeaway-Requestmarker
X-OCTOPOD
X-Member
X-Jcms-Ajax-Id
X-AWS
NKBVHEADER
HA-Ipaddr
HA-Host
HA-Georegion
HA-Geolon
HA-Servedtime
HA-Urlpath
Load-Balancer
L5d-Success-Class
IES-Server
X-OpenUrlRewriter-Debug
X-PG
CS-SERVER
X-Unique-Id
X-Node-App
X-Hit
Debug-Status
Expiries
WP-FROM-CACHE
Session-From
ServerIP
X-CO-Host
X-Cache-Bypass
Xcache
X-XHR-Current-Location
X-Sn-Servicetimems
TC-Cache
TC-Cache-IC
TC-S-Cache-M
TC-S-Cache
TC-Cache-U
HA-Geolat
X-SayCDN-TTL
X-Pixelsilk-Version
X-Pixelsilk-Server
CD4
X-Route
X-Served-Server
X-Shopware-Cache-Id
X-Shopware-Allow-Nocache
Content-Cache
X-Full-Url
X-Custom-Header
X-ClusterID
X-Cache-Original-TTL
No-Cache
X-DSMX-Render-MS
DbServerName
X-DSMX-Rewrite-MS
X-VCS-Cacheable
X-VCS-Ttl
X-Debug-Token-Link
X-CDN-RULE
X-CSRF-Token
X-Deity
X-ETag
X-Gateway-Rate-Limit-Delayed
X-Gateway-Rate-Limit-Conn
X-Cname-TryFiles
X-Cache-ID
GranicusServer
EQ-Cache
Be
HostName
RSB-LINK
X-Beatles
X-Apm-Telemetry-Syncmark
X-Cache-Id
Rewriter
StatusCode
X-Instance-Name
Container
Httpd-Identifier
X-NMT-Proxy
Cache-Status
X-BackendProxy
MachineName
MwpReleaseVersion
X-Site
X-PBY
X-Pass-Through
X-Ssl-Cipher
X-Timestamp
DeleGate-Ver
X-Status
Amp-Access-Control-Allow-Source-Origin
X-WHOIS-Cached
V-Age
User-Agent
X-AppServer-Cache-Rule
X-Ab-Selection
X-ACLR-Version
UrlWatchModule-Time
Webserver
Server-Id
CpuTime
X-VC-Cache
X-Server-Hostname
X-Static
X-VC-Cacheable
X-VC-Debug
Cacheid
X-VC-Hash
X-CDN-COMPRESS
X-Amz-Meta-S3b-Last-Modified
X-UT-Cache
X-UA
X-T
Amfplus-Ver
CommunityServer
HA-Front
Copyright
X-Serverid
X-Say-TTL
X-HA
X-FastCGI-Cache-Status
X-Debug-Message
X-NewCloud-V-Cache
X-Ocache
X-Say-Cacheable
X-ProBase-Server
Provided-Host
Referer
X-RAMCache
X-Pool-Info
X-Pageid
X-Transaction-Name
XDisk
ReqUrl
ProxiaInstanceId
X-Litespeed-Tag
X-IP-Address
X-CH-Device
X-Beresp-Ttl
RSL-Trace-ID
X-Country
X-FIRSTBase
X-Instart-Cache-Id
X-Front-Cache
X-BP-NSA-REQID
X-Backend-TTL
IsMobile
Generate-Time
1A-CountryCode
MageStack-Area
MageStack-Cache
MageStack-Cache-Lifetime
MageStack-Cache-Hits
X-Varnish-Debug-Hits
WP-AdvCache-MemCached
X-M
X-Header-Treatment
X-HEAD
X-Made-On
X-Pj-Cache-Status
X-Sorting-Hat-Expire-Cache
X-Served
MageStack-Cache-Status
MageStack-Cacheable
X-Activity-Id
Tesla.Performance
Request-Filtered-By
X-Amz-Meta-Version-Id
X-AppVersion
X-B
X-Az
FindLaw
Hname
MageStack-Loadbalancer
MageStack-Debug
MageStack-Config
MageStack-Magento-Version
MageStack-PageSpeed
MageStack-Web-Node
MageStack-Tag
Session-Id