Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
P3P
X-Cache
X-AspNet-Version
Strict-Transport-Security
CF-RAY
X-Pingback
Age
Content-Language
Via
X-UA-Compatible
Access-Control-Allow-Origin
X-Adblock-Key
X-Xss-Protection
X-Varnish
Upgrade
X-Check
X-Template
X-Language
X-Cacheable
X-Generator
Content-Security-Policy
X-Buckets
X-Drupal-Cache
X-Request-Id
X-AspNetMvc-Version
X-Type
P3p
X-Cache-Group
X-Pass-Why
X-Hacker
X-Ac
X-Powered-By-Plesk
Content-Location
X-Cache-Hits
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Download-Options
MS-Author-Via
Host-Header
X-ShopId
X-Sorting-Hat-ShopId
X-ShardId
X-Dc
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-IPLB-Instance
Cartoon
Alt-Svc
X-Powered-CMS
Status
X-UA-Device
X-Served-By
Access-Control-Allow-Credentials
WPE-Backend
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Via
X-Amz-Cf-Id
X-Iinfo
X-Request-ID
X-Backend
X-ServedBy
X-Cache-Status
X-Contextid
X-Timer
X-PC-Key
X-PC-Hit
Powered-By
X-Ua-Compatible
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-PC-Date
X-PC-AppVer
X-PC-Host
X-Mod-Pagespeed
X-Logged-In
X-DIS-Request-ID
CF-Cache-Status
Keep-Alive
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Server
X-CDN
X-Cache-Hit
X-Tumblr-Pixel-1
X-Port
X-Host
Content-Encoding
X-Tumblr-Pixel-2
X-Server-Powered-By
X-Robots-Tag
WP-Super-Cache
X-CST
X-Cache-Enabled
X-Rid
X-Pad
Referrer-Policy
X-Nginx-Cache-Status
X-Seen-By
X-Wix-Request-Id
X-Wix-Renderer-Server
X-Endurance-Cache-Level
X-Accel-Version
Fastly-Debug-Digest
X-Page-Speed
X-Turbo-Charged-By
X-Tumblr-Pixel-3
X-Content-Powered-By
X-Wix-PunisherID
X-Rack-Cache
X-Content-Digest
X-Forwarded-For
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-AH-Environment
X-Pantheon-Styx-Hostname
Surrogate-Key-Raw
X-Styx-Req-Id
SPRequestGuid
Content-Security-Policy-Report-Only
X-SharePointHealthScore
X-Forwarded-Proto
X-Proxy-Cache
MicrosoftSharePointTeamServices
X-Cnection
X-Request-Country
X-MS-InvokeApp
X-GitHub-Request-Id
X-XRDS-Location
X-Cache-Lookup
X-Original-Date
X-Safe-Firewall
X-Died
Cf-Railgun
X-FullPageCaching
X-LiteSpeed-Cache
Timing-Allow-Origin
MicrosoftOfficeWebServer
Edge-Control
Request-Id
X-Amz-Request-Id
X-Amz-Id-2
Charset
X-Node
X-Webserver
X-Tumblr-Pixel-4
X-FW-Hash
SPIisLatency
SPRequestDuration
X-PhApp
X-CF-Powered-By
X-FW-Type
Composed-By
X-FW-Static
X-FW-Serve
X-INKT-URI
X-INKT-SITE
X-Content-Security-Policy
X-Hits
Content-MD5
Rating
Access-Control-Max-Age
X-Swift-CacheTime
X-Swift-SaveTime
EagleId
X-Hyper-Cache
Served-By
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
Liferay-Portal
X-Spip-Cache
X-Firenze-Processing-Times
Access-Control-Expose-Headers
Grace
X-CDN-Pop
X-CDN-Pop-IP
X-HS-Cache-Config
X-Tumblr-Content-Rating
Edge-Cache-Tag
X-HS-Content-Id
X-Server-Name
X-Device
X-BC-Stapler
X-Backend-Server
X-Newrelic-App-Data
X-Dw-Request-Base-Id
X-Microcache
X-Fastly-Request-ID
Request-Context
X-RateLimit-Remaining
X-RateLimit-Limit
X-SERVER
X-VCache
X-RateLimit-Reset
X-User-Agent
X-ServerName
X-Jimdo-Instance
Content-Style-Type
X-Jimdo-Wid
X-FB-Debug
Public-Key-Pins
Content-Script-Type
X-Clacks-Overhead
X-Acc-Exp
Refresh
X-Cache-Config
X-Cloud-Trace-Context
Xkey
X-Loop
X-TNCMS
Real-Hostname
X-DDC-Arch-Trace
X-XN-Trace-Token
X-XN-XNHTML
Front-End-Https
Fpc-Cache-Id
X-Age
X-Generated-By
X-Hostname
X-Tumblr-Pixel-5
X-Cached
X-Url
X-Microcachable
X-N-OperationId
X-LiteSpeed-Cache-Control
Surrogate-Control
X-DNS-Prefetch-Control
X-Px
PageSpeed
X-Middleton-Display
Display
Response
X-Middleton-Response
X-Sol
Surrogate-Key
X-Pantheon-Phpreq
X-Pantheon-Site
X-Pantheon-Environment
X-WebKit-CSP
X-MiniProfiler-Ids
X-Cached-By
X-Zen-Fury
X-CMS-Version
X-SS-Conf
X-Topify-Platform
X-SS-Location
X-HOST
X-Outils-CS
X-Content-Options
Rt-Fastcgi-Cache
X-Request-Time
TCN
X-Umbraco-Version
X-DynaTrace-JS-Agent
Edge-Control-Message
X-StackifyID
X-OneAgent-JS-Injection
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Handled-By
Access-Control-Request-Method
X-Amz-Version-Id
Product
X-PERF
X-ApacheServer
X-Ruxit-JS-Agent
X-AspNetWebPages-Version
X-Whom
X-DynaTrace
X-Varnish-Cache-Hits
Imagetoolbar
Alternate-Protocol
Host
X-Tumblr-Pixel-6
X-Cache-Rule
WZWS-RAY
X-Micro-Cache
X-Powered-By-360WZB
X-Engine
X-Magento-Tags
X-Kinsta-Cache
X-Varnish-TTL
Powered
X-NWS-LOG-UUID
X-URL
X-Recruiting
X-VARNISH-Cache
X-Correlation-Id
Fhost
ServedBy
X-Track
DynaTrace
Generator
X-CacheServer
X-FORWARDED-FOR
P-WS
P-LB
X-Hosted-By
X-Location-Id
X-Edge-Location
No
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processado-Em
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processed-At
X-Powered-By-VTEX-Janus-ApiCache
X-Powered-By-VTEX-Janus-Edge
X-Upstream
X-B-Cache
X-LBLID
X-From
X-Cache-Age
X-Instart-Request-ID
Origin
Akamai-IP
X-Varnish-Backend
X-Response-Time
X-Goog-Hash
X-BS
X-I-Sp
X-LB
X-Msg-2-Log
X-Cache-TTL
X-URLSCHEME
Arr-Disable-Session-Affinity
Fastcgi-Cache
X-Varnish-Host
X-RESOURCE
X-Application-Context
X-Actual-URL
X-Passed-To-DLL
X-Returned-From-DLL
X-Returned-From
X-Developer
X-Original-Request
X-App-Hosting
X-Passed-To
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Internal-ReqID
X-TransIP-Balancer
X-Cache-Info
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Stale
X-Passed-To-BeforeDispatch
Pool
Dmn
X-Returned-From-BeforeDispatch
X-Source
X-Defender
X-Shop-Id
X-Fastcgi-Cache
X-Platform
Expect-CT
X-I
Content-Hash
X-S
X-UD-Method
X-Varnish-Cacheable
IBM-Web2-Location
X-Content-Encoded-By
Powered-By-ChinaCache
X-NetCat-Version
X-Revision
X-Front
X-Matrix-Proxy
X-LB-Node
X-Device-Type
X-Expires-Orig
X-Matrix-Server
X-Accel-Expires
X-Powered-By-VelaWeb
X-Varnish-GracePeriod
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-VTEX-Cache-Status-Janus-Edge
X-Origin
X-Platform-Cluster
X-Platform-Router
X-Daa-Tunnel
X-Varnish-Seen-By
X-Platform-Processor
X-Cache-Tags
HTTPS
USPLoggingUUID
X-Cache-Operation
X-TransIP-Backend
X-Rocket-Nginx-Bypass
X-Version
X-Page-Cache
X-Route-Server
Version
Cache-Tag
X-Signature
X-Firenze-Processing-Time
X-Storage
X-Dispatch
X-Server-ID
X-Gamma-Serve
X-Varnish-Count
X-Varnish-HitMiss
X-Cache-Debug
Node
X-Art-Request-Id
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Akamai-Transformed
X-Cache-Only-Varnish
Ohc-File-Size
X-Microcache-Status
X-TTL
X-Dispatcher
X-NoCache
X-Translation
X-Hypernode
X-Cache-Control-Orig
X-HS-Content-Campaign-Id
X-Supported-By
X-Cache-Key
X-EdgeConnect-Origin-MEX-Latency
Last-Published
X-Github-Request-Id
Content-Disposition
Page-Completion-Status
X-Abuse
SSPAppContext
X-Server-Upstream
X-Director
X-Varnish-Age
X-Cache-Lifetime
Srv
ServerName
MIME-Version
X-EdgeConnect-MidMile-RTT
X-Akamai-Device-Characteristics
Lsrequestid
FAI-W-FLOW
X-Last-Modified
X-F-Cache
X-Flow-Powered
X-ARC
X-SV-Edge
X-SV-Expires
X-SV-Duration
Cache-Key
X-SV-CreatedAt
X-SV-CacheTags
X-SV-FromDBCache
X-SV-Nginx-Duration
X-SV-Cacheable
X-SV-Pid
X-SDS
X-Platform-Server
X-CJ-Soft
X-SSL-Cipher
X-Magento-Cache-Debug
X-ATG-Version
X-SSL-Protocol
X-SE-Debug
X-PwB-Node
PICS-Label
X-Country-Code
S-Cnection
Content-Encoding-Handler
X-Duration
X-Geo-Country
X-Url-Base
X-Amz-Meta-S3cmd-Attrs
Proxy-Connection
X-Platform-Cache
IM-Version
Cneonction
X-Grace
X-Cookie-Domain
X-Content-Age
X-ORACLE-DMS-ECID
ServerID
X-Vcap-Request-Id
Accept-Encoding
X-Internal-UserID
X-UPSTREAM
X-Edge-IP
X-Abgroup
X-Cache-Engine
SN
If-Modified-Since
X-Orig-Vary
X-Cache-Server
X-Proxy
X-CDN-Node
X-Sapient
Allow
X-GeoIP-Country-Code
Location
X-CDN-Cache-Status
X-Client-IP
X-Processing-Time
X-ServerID
X-Nbs
X-Processed-By
X-NB-Cached-Page
Req-Id
X-Debug
X-Middleware-Start
X-Sucuri-ID
Pv
Magicmarker
X-Srv
X-BackendServer
X-Speed-Cache
X-Akamai-Device-Model
X-AOL-HN
X-Server-Id
X-Speed-Cache-Key
X-RequestId
X-Shield-Request-Id
X-GeoIP-Country-Name
X-NewRelic-App-Data
WSR-Cache
X-Frontend
X-Cache-Expires
X-Lambda-Id
X-N
X-Real-Server
X-AF-Userserver
Qs-Cache
Section-Io-Id
Accept-Charset
X-Time
X-VC-TTL
CacheControlHeader
A-Powered-By
X-VC-Enabled
X-Sucuri-Cache
X-Varnish-Url
X-FW
X-IsCacheURL
NnCoection
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
Fw-Via
X-Goog-Generation
Cached
S
X-GUploader-UploadID
X-Loopia-Node
X-Discourse-Route
Use-Proxy
X-Ttl
AMF-Ver
Cm-Server
X-Always-Cache
SRV
X-Browser
X-SRCache-Key
X-Goog-Stored-Content-Length
X-Config-Blacklist-Version
X-DealerOn
HCVer
HAVer
Server-Info
X-Worker
X-Varnish-Hits
Backend
X-Cache-Level
EagleEye-TraceId
X-Pressidium-NinukisWP-Ver
X-PF-Uncompressing
SEOMOZ
MJ12bot
Nodo
Author
Tracecode
X-Nginx-Cache
MC
X-Dns-Prefetch-Control
X-Id
X-Magnolia-Registration
X-TB-M
X-Cache-Type
Content-Transfer-Encoding
X-Varnish-Hostname
Cteonnt-Length
X-Purge-URL
X-Framework
SVR
Buuteeq-Source
NetMindSessionID
X-Varnish-Ttl
X-Correlation-ID
Cache
X-BKSrc
Retry-After
X-Cache-PageType
X-Cache-Fix
X-Route-To
X-Drectory-Script
X-WR-MODIFICATION
Identity
X-Litespeed-Cache
X-Healthy
X-ID
X-Traffic
Nitro-Cache
X-Trace
X-Vhost
X-Cache-Control
X-Directory-Script
RTSS
X-ACMCache
X-OpenCart-Lightning
X-Empowered-By
Server-Name
X-Varnish-IP
X-Powered-By-Server
X-Yottaa-Optimizations
Keywords
X-Adobe-Content
X-Cache-Handler
X-Yottaa-Metrics
X-JG-Page-Cache
X-Adobe-Loc
X-Cache-TTL-Remaining
X-Resolver-IP
X-Connection-Hash
Local-Info
X-Sys-Req-ID
X-Session-ID
X-Garden-Version
X-Environment
X-Twitter-Response-Tags
X-Transaction
BALANCEDTO
X-LB-Server
X-Pagename
X-Unique-ID
X-Magento-Cache-Control
Frame-Options
X-Served-Server
X-Site-Name
X-Hit-Cache
X-Fastly-Request-Id
Ufe-Result
X-WR-Flags
Cache-Provider
X-Purge-Host
X-FireWall-Port
Smug-CDN
X-Mobilized-By
NODE
X-SmugMug-Values
X-Generated
X-Content-Security-Policy-Report-Only
X-NginX-Cache
X-TTFB-L
X-TTFB
X-SmugMug-Hiring
X-LP
X-EC-Security-Audit
HitType
Thanks
X-Yadis-Location
SS
X-Runtime-Memory
Description
Disablevcache
Xc-Version
X-ClientSide-Caching
X-Cache-Device-Type
X-Author
X-Cache-Dispatchercachecontrol
X-Amz-Storage-Class
X-VARITI-CCR
X-CB-Server
X-EPiphany-Vid
X-Cache-Dispatcherpragma
X-Server-Instance
X-Cocoon-Version
X-Unbounce-VisitorID
X-Unbounce-Variant
X-Client-Image-Vid
X-Hiawatha-Cache
X-Unbounce-PageId
X-Client-Vid
X-Debug-Token
X-Cache-Node
X-LW-Web-Server
X-Balanceador
X-Highwire-SessionId
X-SmartBan-URL
X-Env
X-HOSTNAME
X-SmartBan-Host
WWW-Authenticate
X-High-Performance
X-Varnish-Retries
X-Cache-Doesi
X-CF-Passed-Proto
X-Highwire-RequestId
X-WN-ClientGroup
Strikingly-Cached
WN
Strikingly-Cached-Version
X-ARRServer
X-OPNET-Transaction-Trace
X-CAPServer
X-Session-Reinit
X-Drupal-Cache-Tags
Dispatcher
Web-App-Origin-Name
X-Webcelerate
X-DEBUG
X-NginX-Server
X-RiS-UFDI
Content_type
IISExport
Max-Age
X-HydroSheep
Front
X-Location
ServerSignature
X-App-Server
X-HTML-Minification-Powered-By
X-Disney-Akamai-Rule
X-ORACLE-DMS-RID
ServerTokens
From-Origin
X-Domain-Checked
X-App
X-Optimization
X-Nginx-Host
X-Rack-Cors
X-Generated-Time
X-App-Status
Eomportal-Instance
X-HITS
X-WebKit-CSP-Report-Only
X-Distributor
X-Provisioner-Version
X-Cache-CFC
Ohc-Upstream-Trace
AsisCache
Dis-Env
X-HP-Trace-Project
X-HP-Trace-ID
X-Varnish-ID
X-Cache-Provider
X-Render-Time
X-AEM
X-CDN-Forward
X-Cache-Source
X-Node-Name
SiteSpeed
X-Varnish-Debug-TTL
X-Site
NLCacheNote
X-Config-By
OriginServer
X-Hosting-Env
X-Varnish-Debug-Age
X-Server-IP
X-Culture
X-C2M-Runtime
X-C2M-Server
X-Machine
XDomainRequestAllowed
X-HW
X-SDE-Name
Set-Cookie2
X-WP
X-Trace-Id
Access-Control-Allow-Method
Id
X-Cf-Powered-By
X-Symfony-Cache
X-Cache-Keep
X-Runtime-Rack
X-Smartcache-Keys
X-Jphone-Copyright
X-Smartcache-Timeout
X-Nginx
X-GeoIP
X-A
X-We-Are-Hiring
Og
Machine
X-Fedora-School-Id
X-CacheResult
Public-Key-Pins-Report-Only
X-Ser
X-Resty-Request-Id
WP-AdvCache-MemCached
X-Resource
X-RealServer
X-Esi
X-Source-ID
ScoreTracker
X-Wikidot-Static-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Wikidot-Backend
CP
X-RDP
X-Rebelmouse-Cache-Control
X-Fpc
X-SV
Hname
X-Magento-Action
X-Rebelmouse-Surrogate-Control
X-HA-Backend
X-MidCOM-Meta-Cache
Traffic-Origin
X-PageType
X-Data-Request
X-CRA-DC
X-HashTwo
X-HA-Frontend
X-Time-Microsecs
X-Machine-Name
X-App-Runtime
X-DataDome
X-Remote-Addr
X-ASAP-Cache
Nginx-Cache
TC-Cache
X-Bcwwwid
X-Clara-ASAP
X-Desc
X-Rewrite
Yoncu-Errno
X-MAT-GEO
MW-Webserver
X-Lb
TC-S-Cache-M
SG
Paypal-Debug-Id
Cluster-ID
TC-S-Cache
TC-Cache-U
TC-Cache-IC
X-E
X-GSL-Server
X-Server-Generated
X-Distil-CS
CLMOB
X-Amcomm-Site
N365rili
Ibf5scheme
Sophnep-Edge-FX
ViewMode
X-Pageid
X-Powered-By-Home.Pl
X-Cache-On
Content-Server
X-Key
X-Dw-Trace-Id
X-DTC
X-Page
X-IIJ-Cache
X-Blog
X-Refresh
X-Varnish-Server
Ttl
Xc
X-Response
X-Proto
X-Cdn-Forward
X-Viator-Tapersistentcookie
Strikingly-Cache-Region
From
Expect-Ct
Url
X-Detected-Device
MS-CV
X-Cache-Detail
X-Hstore
RN-Server
DNNOutputCache
Ctx
X-Runtime-Affili
X-Grid-Server
X-Artvisual-Server
VANITY-HOST
X-WA-Info
NS-VaryByCustom-Key
X-Batcache
X-Atg-Version
X-UA
Cmsid
X-Info
X-CACHE-KEY
Cmstype
X-Mobile-URL
X-Beresp-Ttl
X-Dynatrace-Js-Agent
Debug-Status
Bios
Resin-Trace
X-SERVER-NAME
X-Captured
X-ServerIndex
X-Pagely-Cache
X-AutoRu-App-Id
X-SCM-Server-Number
X-PRAM
X-Force
DrivedBy
Server-Ip
X-Hosting
X-Avvio-Cms-Cacheload
X-Atraveo-Cache-Control
Backend-Timing
NtCoent-Length
X-Obj.Ttl
X-Sc-Cache
X-MCB-Server
X-Adnet
X-Ezoic-Cdn
Worker
X-Rq
X-Cacheable-TTL
X-Webstats-RespID
X-Header
X-CDN-COMPRESS
X-Depends
X-Frame-Option
X-CDN-RULE
X-Dev
X-Server-Instance-Name
SHInfo
X-Analytics
X-Amz-Id-1
Beyond-Iis
X-Cms-Mode
X-Cache-Via
Mime-Version
X-Webapp
X-Autoru-Host
X-Test
X-OCTOPOD
Response-Time
X-Ghost-Cache-Status
X-Fstrz
X-CACHE-TTL
X-Autoru-LB
X-Atraveo-ETag
VServer
X-M
X-Unique-Id
X-Cache-Warmer
X-Phpwcms-Page-Processed-In
Actual-Object-TTL
X-Hrouter
ClientIP
X-SO
X-Phpwcms-Release
F5-IpCliente
X-Cache-Action
X-Backend-Status
X-HP-Redirect
Gzip
X-7d-Trace-Id
X-Actindo-RS
SINA-LB
SINA-TS
X-Atraveo-TTL
X-Agent
X-Atraveo-Set-Cookie
X-Application
X-Compressed-By
X-Atraveo-Expires
X-Atraveo-From-Varnish-Cache
X-Atraveo-Param-Rm
Warning
W
Webluker-Edge
X-Atraveo-Zone
Access-Control-Request-Headers
X-EC-Lua
X-7d-Instance-Id
SBMCLOUD
X-Atraveo-Varnish-Server-Id
X-Client-Ip
X-Reflector-Cache
X-Sid
Device
Web
X-Reflector
X-ChromeLogger-Data
X-This-Proto
X-Drupal-Cache-Contexts
X-Nginx-Request-Time
X-RAMCache
X-Varnish-URL
X-Middleton-PageSpeed
X-Map-Context
X-Req-Head-Response
SERVER-ID
X-KoobooCMS-Version
X-Webkit-Csp
Provider
X-ReqId
X-Cache-Varnish
Ibm-Web2-Location
X-Cache-Extended
X-Varnish-Action
Ews
PagesDisplayed
X-Tag-Playlist
X-DW
X-RSL
X-RPS
X-RPM
X-APP
X-PBY
X-DSS
X-DB
X-XHR-Current-Location
X-Server-FQDN
Httpd-Identifier
X-PG
MSSmartTagsPreventParsing
X-Time-Zone
X-Streams-Distribution
X-ServiceProvider
MSThemeCompatible
X-FastCGI-Cache
X-ELB
X-Varnish-VCL
X-VLoc
X-Built-With
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-MSEdge-Ref
X-HAProxy
StatusCode
X-Varnish-Instance
X-Node-ID
X-Turpentine-Esi
MageStack-Config
MageStack-Web-Node
MageStack-Tag
MageStack-PageSpeed
MageStack-Magento-Version
X-ACLR-Version
X-Amz-Meta-Content-Md5
X-Svr
X-EC2-Instance-Id
X-B2f-Not-Route
MageStack-Loadbalancer
MageStack-Debug
MageStack-Area
Fastly-Backend-Name
COMMERCE-SERVER-SOFTWARE
MageStack-Cache
MageStack-Cache-Hits
MageStack-Cacheable
MageStack-Cache-Status
MageStack-Cache-Lifetime
X-Varnish-Cache-Local
Accept-Language
X-UnsetCookies
GP-Remote-Addr
X-FIRSTBase
GP-Version
X-RemovedCookies
X-Forwarded-Host
X-ProcessESI
Hostname
X-Rocket-Nginx-Serving-Static
X-Plat
Proxy-Cache
Il-Cl
Home
X-Apm-Telemetry-Syncmark
X-Domino-CacheValidationWithETagReason
X-Frames-Options
X-Country
X-Domino-CacheValidationWithETagResult
X-XHTML-Minification-Powered-By
X-W3TC-Minify
Server-ID
NZSpeedy
MwpReleaseVersion
Container
X-4ormat-Cacheable
X-AG-MIPS
X-Enhanced-By
X-DS1D
X-ASAP-Age
AGI-Request-ID
X-WPL-DATA
X-Meta-Imagetoolbar
X-Instance-Name
X-Cache-TTL-Current
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
X-Wm-VIP
X-Wm-1
X-Server-Addr
X-Forwarded-By
X-Generated-Date
Pics-Label
Myheader
X-Ssl-Cipher
X-Airee-Node
X-Layout
X-Vary-Options
X-Title
X-Search-Id
X-Proxy-Cache-Key
X-Nginx-Request-Processing-Time
X-Sites
X-Serv
X-Restarts
X-Src-Webcache
X-AMAZEEIO
X-Ezpublish-Nodeid
X-Ezpublish-Installationid
X-Cache-Time
X-Cache-TTL-Age
X-CacheID
X-Provided-By
X-FreeTag-Count
X-RiS-PX
X-Router
X-Router-Backend
Server-Hostname
RequestId
FastCGI-Cache-Status
X-VID
Note
X-Nocache
Provided-Host
X-Secret
X-Serendipity-InterfaceLang
Session-Id
SB-Site-Device
X-AWS
X-Cache-FS-Status
X-Cached-Status
SB-Cache-Remaining
SB-Cache-Life
X-UseReverse-Proxy
X-Serendipity-InterfaceLangSource
X-Zendesk-Origin-Server
X-Zendesk-User-Id
BackendServer
X-V
X-NewCloud-V-Cache
RSB-LINK
X-AppServer-Cache-Rule
X-Cname-TryFiles
X-Deity
X-Made-On
ENV
Drupal-Pagecache-Memcache
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-SID
Content-Legth
X-Served
X-UPSTREAM-Address
X-Backend-TTL
Lb
X-Cms-Server
X-DI
X-Goog-Meta-Goog-Reserved-File-Mtime
Cleartype
Brightspot-Id
X-Varnish-Mode
X-Varnish-Auto-Cache-Miss
X-JSESSIONID
X-LBPoolMember
X-WHOIS-Cached
X-Catalyst
AMFplus-Ver
X-Box
Hamster
X-Uncacheable
Requested-Host
Server-Id
X-REDIRECTSERVER
VAR-Cache
Vserver
X-VG-WebCache
X-Cluster
Progma
UrlWatchModule-Time
X-SH-Cache-Status
X-Container
Kanooh-Host
Cache-Ctrol
Content-Cache
X-Upgrade-Enabled
TP-Cache
TP-L2-Cache
X-DDM-SERVER-UPDATED
X-MSU-SOURCE
X-PBS-Fwsrvname
X-PBS-Appsvrname
X-PBS-Appsvrip
X-NewsFlow-Sitename
X-Obj-Ttl
X-PHP-Response-Code
X-PoweredBy
X-SuperCache
X-Clx-Request
X-WebNode
X-DDM-SERVER
X-Len
X-CSRF-Token
X-ACCELERATE
X-Oracle-DMS-ECID
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-FF
X-Cluster-Node
X-ENV
PServer
X-Stage
X-Litespeed-Cache-Control
X-Lima-Id
X-DB-Content-Length
X-Dynamic
BlockPHPCallEnd
X-Grow-Cache
X-DeliveryServer
WFE
X-DEBUG-TTL
X-Bip
X-Brought-To-You-By
X-Front-Cache
X-Grow-Guest
SB-Site-IE-VERSION
CommunityServer
X-FRUIT
X-SilverStripe-Cache
Fw-Cache-Status
Apple-Itunes-App
X-HASH
X-IP-Address
RSL-Trace-ID
X-Tt-Dbg
X-Tradeindia-Request-GUID
X-Obvious-Tid
X-Obvious-Info
X-SRV
X-VC-Debug
FindLaw
X-Not-Cacheable
X-Faeria
X-MainProfileID
X-MainProfileName
DB-Nickname
X-MainProfileURL
X-Dynamic-Cache
VC-NoCache
X-W-Cache
X-Tradeindia-SMgmt
X-Request-Received
X-MainProfileCategory
X-UUID
X-W-Cache-Hits
Tk
Lookup-Cache-Hit
Ez
XDisk
X-No-Session
X-Content-Parsed-By
Session-From
Proxy-Agent
Origin-Content-Encoding
Type
WebServer
X-AISO-Cacheable
X-AISO-Cache
Web-Server
Cache-Tags
X-Sn-Servicetimems
X-MCF-ID
X-ACache
X-Varnish-Cached
Accept-CH
X-Varnish-Cached-TTL
X-AISO-Server
X-Cache-V
X-Vol-Mrp
DeleGate-Ver
LCache
Returned-Status
X-RequesterIP
X-Vol-Correlation
X-Requestid
Debug-Expires
Memento-Datetime
X-Nginx-Page-Cache
X-ETag
X-PvInfo
CD4
Server-Node
Debug-Cache-Control
X-Archive-Guessed-Charset
X-Cache-Me-Harder
X-Varnish-Grace
X-IP
HA-Ipaddr
X-Built-By
HA-Servedtime
X-Archive-Orig-Server
HA-Urlpath
HA-Host
X-Pubstack
HA-Geocountry
HA-Geocity
HA-Geolat
X-Request-Processing-Time
HA-Georegion
HA-Geolon
X-Archive-Orig-ETag
X-Archive-Orig-Date
X-Cache-Origin
X-Batcache-Reason
X-B3-Traceid
X-CGP
X-Group
X-Hcom-Styx-Info
X-Hcom-Origin-Id
X-B3-Spanid
Redkiwi-Cloud
IES-Server
X-Archive-Orig-Content-Length
L5d-Success-Class
Load-Balancer
NKBVHEADER
X-Archive-Orig-Connection
HA-Cloudapp
EQ-Cache
PB-RID
X-Pass-Through
PB-PID
AC-ELC
Language
Aurora-Node
X-Origin-Server
X-NodeID
X-CH-Device
X-Count
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-Instance
X-Cachable
LB
TheAnswer
X-ManagedFusion-Rewriter-Version
X-Gannett-Site-Version
X-NMT-Proxy
X-Protected-By
X-Static
X-Rewritten-By
X-Cjtype
X-BServer
X-BPool
X-BC
X-BPool-Back
X-BPool-Bx-Cache
X-BPool-Fx-Cache
X-Pool-Info
X-Cache-Why
Unique-Request-Id
X-Varnish-Store
Cache-Status
Copyright
X-Scache
X-Skip-Cache
X-Varnish-Set-Cookie
X-Varnish-Esi-Method
X-UType
X-Netrix-ID
X-GRACE
X-Turpentine-Cache
X-Varnish-Esi-Access
X-Varnish-Currency
X-Geo-IP
Referer-Policy
X-Transaction-Name
Developer
X-TargSmaku
X-Rack-CORS
X-Powered-Developer
Edgecast
MachineName
ReqUrl
X-Status
XX
X-FORWARDED-PROTO
X-LOCATION
X-COUNTRY-CODE
X-Xrds-Location
Ina-Bwaf
X-TTL-Age
X-Ss-Location
X-Would-Your-GrandPa-Wait
X-Your-GrandPa-Would-Wait
Tempo
GranicusServer
X-Ss-Conf
X-NO-BREACH
X-Content-Type-Option
X-CCM
X-Does-He-Have-Time
Aoestatic
X-Goog-Meta-Replace
X-Goog-Meta-Policy
X-Amz-Meta-Version-Id
X-Cache-BE
X-SCProxy
X-Processed
Application
IsMobile
X-Accel-Cache-Control
Prototype-RootPath
X-Pj-Cache-Status
X-Ocache
X-Cache-LB
X-Cache-HT
X-Csrf-Token
X-Debug-Message
X-Imforza-Hosted
X-Cache-Set
X-Cache-ID
V-Age
X-Flex-Lang
X-Flex-Evstart
X-Flex-Evend
X-Backend-Name
X-Flex-Community
X-Flex-Lastmod
MageStack-Response-Ttl
MageStack-Cache-Warning
X-Varnish-Debug-Hits
MageStack-Cacheable-Reason
X-Magento-Lifetime
X-Flex-Tag
X-Flex-Tags
X-Cache-Id
X-DN-Cache-Control
X-Reason-Bp
X-Real-IP
EagleEye-TraceId-Daily
INFO
X-Beatles-Hits
X-Beatles
X-PM-ID
X-Pixelsilk-Version
X-Name
X-Gyrobase-Publication
X-NID
X-Origin-Cache
X-Pixelsilk-Server
X-App-Version