Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
X-Cache
P3P
X-AspNet-Version
Strict-Transport-Security
CF-RAY
X-Pingback
Age
Content-Language
Via
X-UA-Compatible
Access-Control-Allow-Origin
X-Adblock-Key
X-Xss-Protection
X-Varnish
Upgrade
X-Check
X-Language
X-Template
X-Cacheable
X-Generator
Content-Security-Policy
X-Buckets
X-Drupal-Cache
P3p
X-Request-Id
X-AspNetMvc-Version
X-Type
X-Cache-Group
X-Pass-Why
X-Hacker
X-Ac
Content-Location
X-Powered-By-Plesk
X-Cache-Hits
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Download-Options
MS-Author-Via
Host-Header
X-ShopId
X-Dc
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Alternate-Cache-Key
X-IPLB-Instance
Alt-Svc
X-Powered-CMS
Cartoon
Status
X-UA-Device
X-Served-By
WPE-Backend
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Via
X-Amz-Cf-Id
X-Iinfo
X-Request-ID
X-Cache-Status
X-Backend
X-ServedBy
X-Contextid
X-Timer
X-PC-Hit
X-PC-Key
Powered-By
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Mod-Pagespeed
X-DIS-Request-ID
X-PC-Date
X-PC-AppVer
X-PC-Host
X-Ua-Compatible
X-Logged-In
Keep-Alive
CF-Cache-Status
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-CDN
X-Cache-Hit
X-Server
X-Tumblr-Pixel-1
X-Host
X-Port
Content-Encoding
X-Tumblr-Pixel-2
X-Robots-Tag
X-Server-Powered-By
WP-Super-Cache
X-CST
X-Cache-Enabled
X-Rid
X-Pad
Referrer-Policy
X-Nginx-Cache-Status
X-Seen-By
X-Wix-Renderer-Server
X-Wix-Request-Id
X-Endurance-Cache-Level
X-Accel-Version
Fastly-Debug-Digest
X-Page-Speed
X-Turbo-Charged-By
X-Tumblr-Pixel-3
X-Content-Powered-By
X-Wix-PunisherID
X-Rack-Cache
X-Content-Digest
X-Forwarded-For
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-AH-Environment
Surrogate-Key-Raw
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
SPRequestGuid
Content-Security-Policy-Report-Only
X-SharePointHealthScore
MicrosoftSharePointTeamServices
X-Request-Country
X-Forwarded-Proto
X-Proxy-Cache
X-Cnection
X-MS-InvokeApp
X-XRDS-Location
X-GitHub-Request-Id
X-Cache-Lookup
X-Original-Date
X-Safe-Firewall
X-FullPageCaching
Cf-Railgun
X-Died
MicrosoftOfficeWebServer
X-LiteSpeed-Cache
Timing-Allow-Origin
Edge-Control
Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Webserver
X-Node
Charset
X-PhApp
SPIisLatency
SPRequestDuration
X-FW-Hash
X-Tumblr-Pixel-4
X-INKT-SITE
X-INKT-URI
Composed-By
X-FW-Serve
X-FW-Type
X-Content-Security-Policy
X-FW-Static
X-CF-Powered-By
X-Hits
Access-Control-Max-Age
Content-MD5
X-Swift-SaveTime
X-Swift-CacheTime
Rating
X-Hyper-Cache
EagleId
Served-By
Liferay-Portal
X-Spip-Cache
Access-Control-Expose-Headers
Grace
X-Firenze-Processing-Times
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-CDN-Pop-IP
X-CDN-Pop
X-SERVER
X-HS-Cache-Config
Edge-Cache-Tag
X-HS-Content-Id
X-Tumblr-Content-Rating
X-Server-Name
X-Device
X-BC-Stapler
X-Dw-Request-Base-Id
X-Backend-Server
X-Newrelic-App-Data
X-Microcache
Request-Context
X-Fastly-Request-ID
X-RateLimit-Remaining
X-RateLimit-Limit
Content-Style-Type
X-User-Agent
X-VCache
X-RateLimit-Reset
X-FB-Debug
X-ServerName
Content-Script-Type
Public-Key-Pins
X-Jimdo-Instance
X-Jimdo-Wid
X-Clacks-Overhead
X-Acc-Exp
X-Cache-Config
Refresh
X-Cloud-Trace-Context
Xkey
X-Loop
X-TNCMS
Real-Hostname
X-DDC-Arch-Trace
X-XN-XNHTML
X-XN-Trace-Token
Fpc-Cache-Id
Front-End-Https
X-Age
X-Hostname
Surrogate-Control
X-Url
X-Generated-By
X-N-OperationId
X-Microcachable
X-Cached
X-DNS-Prefetch-Control
X-Px
X-Tumblr-Pixel-5
X-LiteSpeed-Cache-Control
PageSpeed
Surrogate-Key
X-WebKit-CSP
X-Sol
X-Zen-Fury
X-Middleton-Display
X-Middleton-Response
Response
Display
X-MiniProfiler-Ids
X-Cached-By
X-Pantheon-Environment
X-Pantheon-Phpreq
X-Pantheon-Site
X-StackifyID
X-Topify-Platform
X-SS-Conf
X-SS-Location
X-CMS-Version
X-Outils-CS
TCN
Rt-Fastcgi-Cache
X-Content-Options
X-HOST
X-Request-Time
Edge-Control-Message
X-Umbraco-Version
X-Handled-By
Product
X-PERF
X-DynaTrace-JS-Agent
X-ApacheServer
Access-Control-Request-Method
Imagetoolbar
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-OneAgent-JS-Injection
X-DynaTrace
X-Amz-Version-Id
X-AspNetWebPages-Version
X-Whom
X-Varnish-Cache-Hits
X-Ruxit-JS-Agent
Alternate-Protocol
Host
X-Cache-Rule
X-Engine
X-Tumblr-Pixel-6
X-Recruiting
X-Correlation-Id
X-Kinsta-Cache
X-Varnish-TTL
X-Powered-By-360WZB
WZWS-RAY
X-From
X-Micro-Cache
X-NWS-LOG-UUID
Powered
ServedBy
X-Magento-Tags
X-Msg-2-Log
DynaTrace
X-URL
X-Location-Id
X-Track
X-VARNISH-Cache
Fhost
X-CacheServer
Generator
X-Hosted-By
Dmn
X-FORWARDED-FOR
P-WS
P-LB
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
No
X-Powered-By-VTEX-Janus-ApiCache
X-Vtex-Processado-Em
X-VTEX-Janus-Router-Backend-App
X-Edge-Location
X-Powered-By-VTEX-Janus-Edge
X-Upstream
X-Instart-Request-ID
X-B-Cache
Origin
X-Varnish-Backend
X-Cache-Age
X-Goog-Hash
X-LBLID
X-Varnish-Host
X-Response-Time
X-Actual-URL
X-LB
X-BS
X-I-Sp
X-Passed-To-DLL
X-Returned-From
X-Returned-From-DLL
X-Passed-To
Akamai-IP
X-Original-Request
Arr-Disable-Session-Affinity
X-Returned-From-BeforeDispatch
X-Cache-TTL
X-Returned-From-PostProcessResponse
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-URLSCHEME
X-Varnish-Beresp-Ttl
X-RESOURCE
Fastcgi-Cache
X-Stale
X-Application-Context
X-Cache-Info
X-Fastcgi-Cache
Expect-CT
X-App-Hosting
X-TransIP-Balancer
X-Source
X-Matrix-Server
X-Matrix-Proxy
X-Internal-ReqID
X-Platform
X-Developer
Powered-By-ChinaCache
X-Varnish-Cacheable
Pool
X-S
X-Defender
X-Shop-Id
X-Origin
X-NetCat-Version
X-Art-Request-Id
X-Powered-By-VelaWeb
X-Content-Encoded-By
X-Device-Type
X-Accel-Expires
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
Content-Hash
X-I
X-UD-Method
IBM-Web2-Location
X-Version
X-Expires-Orig
X-Daa-Tunnel
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-Varnish-ObjectSource
X-Varnish-Seen-By
X-Cache-Tags
X-Varnish-GracePeriod
X-Revision
X-VTEX-Cache-Status-Janus-Edge
X-Front
USPLoggingUUID
X-Storage
Version
X-LB-Node
HTTPS
X-Rocket-Nginx-Bypass
X-TransIP-Backend
X-Cache-Operation
X-Route-Server
X-Gamma-Serve
X-Signature
X-Firenze-Processing-Time
X-Cache-Debug
X-Varnish-Count
X-Microcache-Status
X-Translation
X-Varnish-HitMiss
X-Page-Cache
X-EdgeConnect-Origin-MEX-Latency
Cache-Tag
X-Dispatch
Content-Disposition
X-Server-ID
X-TTL
X-NoCache
X-Cache-Control-Orig
X-Dispatcher
X-Supported-By
X-HS-Content-Campaign-Id
X-Tec-Api-Root
X-Tec-Api-Origin
Node
X-Akamai-Transformed
X-Tec-Api-Version
Ohc-File-Size
X-EdgeConnect-MidMile-RTT
X-Cache-Only-Varnish
X-Abuse
X-Cache-Key
X-Server-Upstream
X-Flow-Powered
SSPAppContext
X-Hypernode
X-Varnish-Age
Lsrequestid
Last-Published
X-Director
X-SV-FromDBCache
X-SV-Nginx-Duration
X-SV-Pid
X-SV-Expires
X-SV-CacheTags
X-SV-Cacheable
MIME-Version
ServerName
X-SV-CreatedAt
X-SV-Duration
X-SV-Edge
X-ATG-Version
Page-Completion-Status
X-Github-Request-Id
X-F-Cache
X-Platform-Server
X-Cache-Lifetime
X-SSL-Protocol
Srv
X-Akamai-Device-Characteristics
X-Duration
X-Country-Code
X-NewRelic-App-Data
X-Magento-Cache-Debug
X-Last-Modified
FAI-W-FLOW
X-SSL-Cipher
Cache-Key
X-PwB-Node
S-Cnection
X-ARC
X-CJ-Soft
X-SDS
X-Platform-Cache
Cneonction
X-SE-Debug
X-Abgroup
PICS-Label
X-Amz-Meta-S3cmd-Attrs
ServerID
Content-Encoding-Handler
SN
IM-Version
X-Cookie-Domain
Proxy-Connection
X-Geo-Country
X-Url-Base
X-Grace
X-Cache-Server
Allow
X-UPSTREAM
X-ORACLE-DMS-ECID
X-Content-Age
X-Sapient
X-Debug
X-Internal-UserID
X-Edge-IP
X-Client-IP
X-GeoIP-Country-Code
Accept-Encoding
X-Vcap-Request-Id
X-ServerID
X-Server-Id
Magicmarker
X-Processing-Time
X-Cache-Engine
If-Modified-Since
X-Proxy
Location
X-Speed-Cache-Key
X-CDN-Cache-Status
X-CDN-Node
X-Speed-Cache
X-Orig-Vary
Req-Id
X-Time
Qs-Cache
X-Shield-Request-Id
NnCoection
X-Nbs
SRV
X-AOL-HN
CacheControlHeader
X-Akamai-Device-Model
X-GeoIP-Country-Name
X-Processed-By
AMF-Ver
X-Real-Server
X-Middleware-Start
X-N
X-NB-Cached-Page
X-VC-TTL
X-RequestId
X-Srv
X-Sucuri-ID
X-BackendServer
X-Lambda-Id
Cached
X-Always-Cache
WSR-Cache
HAVer
HCVer
X-Goog-Generation
X-Frontend
Section-Io-Id
X-AF-Userserver
Accept-Charset
S
X-EC-Security-Audit
X-Cache-Expires
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
A-Powered-By
Nodo
X-IsCacheURL
Server-Info
MC
MJ12bot
X-FW
Content-Transfer-Encoding
X-Sucuri-Cache
X-VC-Enabled
SEOMOZ
Pv
X-Varnish-Url
X-Config-Blacklist-Version
X-Discourse-Route
X-ID
X-SRCache-Key
Use-Proxy
X-Loopia-Node
X-Browser
NetMindSessionID
Cm-Server
Cteonnt-Length
X-TB-M
Fw-Via
X-Ttl
X-DealerOn
X-Worker
X-PF-Uncompressing
Buuteeq-Source
RTSS
X-Varnish-Hits
Retry-After
X-Trace
EagleEye-TraceId
X-Varnish-Hostname
Backend
X-Pressidium-NinukisWP-Ver
X-Cache-Level
NODE
Author
X-Magnolia-Registration
X-Healthy
X-Id
X-Cache-Type
X-Dns-Prefetch-Control
X-Nginx-Cache
X-Drectory-Script
Tracecode
X-Framework
X-ACMCache
X-BKSrc
SVR
X-Purge-URL
X-Varnish-Ttl
Cache
X-Correlation-ID
X-Cache-Control
X-Cocoon-Version
X-Vhost
Identity
X-Litespeed-Cache
X-WR-MODIFICATION
X-Traffic
X-Cache-Fix
X-Amz-Storage-Class
Nitro-Cache
X-Cache-TTL-Remaining
X-Route-To
X-Cache-PageType
X-Magento-Cache-Control
X-Empowered-By
Disablevcache
X-Generated
Keywords
X-Varnish-IP
X-Cache-Handler
X-Adobe-Loc
Server-Name
X-NginX-Cache
X-Powered-By-Server
X-OpenCart-Lightning
X-Adobe-Content
X-Mobilized-By
X-Yadis-Location
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-JG-Page-Cache
X-Directory-Script
X-WR-Flags
X-Pagename
X-Unique-ID
IISExport
X-Connection-Hash
X-Environment
X-FireWall-Port
X-Sys-Req-ID
Ufe-Result
X-Site-Name
X-Twitter-Response-Tags
X-Transaction
X-Hit-Cache
Cache-Provider
X-LB-Server
X-Purge-Host
X-Session-ID
Local-Info
X-Debug-Token
X-Served-Server
X-Cache-Dispatcherpragma
X-Resolver-IP
Frame-Options
BALANCEDTO
X-Garden-Version
X-Cache-Dispatchercachecontrol
X-Fastly-Request-Id
X-TTFB
Smug-CDN
Thanks
HitType
Description
X-LP
X-Content-Security-Policy-Report-Only
X-Runtime-Memory
SS
X-Litespeed-Cache-Control
X-SmugMug-Values
WWW-Authenticate
X-SmugMug-Hiring
X-TTFB-L
X-Distributor
X-Cache-Device-Type
X-ClientSide-Caching
X-EPiphany-Vid
X-Client-Vid
X-CB-Server
X-Cache-Node
X-App-Server
X-Author
X-HOSTNAME
Xc-Version
X-NginX-Server
X-Drupal-Cache-Tags
X-Client-Image-Vid
X-HTML-Minification-Powered-By
X-Session-Reinit
X-Unbounce-Variant
X-LW-Web-Server
X-Hiawatha-Cache
NLCacheNote
X-Runtime-Rack
X-Server-Instance
X-VARITI-CCR
X-Unbounce-VisitorID
X-Unbounce-PageId
X-High-Performance
X-CF-Passed-Proto
X-Varnish-Retries
X-Cache-Doesi
X-Render-Time
WN
X-WN-ClientGroup
Strikingly-Cached
Strikingly-Cached-Version
X-Balanceador
X-SmartBan-URL
X-SmartBan-Host
Eomportal-Instance
X-Highwire-SessionId
X-Env
X-Highwire-RequestId
Content_type
X-HydroSheep
Dispatcher
X-ARRServer
X-OPNET-Transaction-Trace
X-Varnish-Server
Web-App-Origin-Name
ServerSignature
X-ORACLE-DMS-RID
X-Webcelerate
ServerTokens
X-Source-ID
X-Config-By
Front
X-Location
X-RiS-UFDI
X-Disney-Akamai-Rule
Max-Age
X-Symfony-Cache
X-CAPServer
X-DEBUG
Url
X-Nginx-Host
From-Origin
X-Amz-Meta-Cb-Modifiedtime
X-Generated-Time
X-App
X-HITS
X-Provisioner-Version
X-Domain-Checked
X-App-Status
X-Distil-CS
X-WebKit-CSP-Report-Only
X-Rack-Cors
X-Optimization
Cmstype
X-Machine
X-C2M-Runtime
Set-Cookie2
X-SDE-Name
X-Culture
X-Varnish-Debug-TTL
Bios
Ohc-Upstream-Trace
X-Cache-Source
X-Varnish-ID
X-Grid-Server
X-HW
Access-Control-Allow-Method
X-C2M-Server
X-Cache-CFC
X-Node-Name
X-Cf-Powered-By
SiteSpeed
X-Blog
X-HP-Trace-Project
OriginServer
X-Hosting-Env
Cmsid
VANITY-HOST
X-WP
X-Server-IP
Id
X-Jphone-Copyright
X-Smartcache-Timeout
XDomainRequestAllowed
AsisCache
X-Trace-Id
X-AEM
From
X-Varnish-Debug-Age
X-Smartcache-Keys
Dis-Env
X-Cache-Keep
CLMOB
X-Site
X-Dynatrace-Js-Agent
X-Cache-Provider
X-CDN-Forward
X-HP-Trace-ID
X-Esi
X-UA
Og
X-Fedora-School-Id
X-Resty-Request-Id
X-CacheResult
X-GeoIP
X-Wikidot-Static-Cache
X-Ser
X-We-Are-Hiring
WP-AdvCache-MemCached
ScoreTracker
X-Resource
X-PRAM
X-A
X-Captured
DrivedBy
X-Nginx
Machine
X-Wikidot-Backend
Public-Key-Pins-Report-Only
X-Force
Sophnep-Edge-FX
Ibf5scheme
N365rili
X-OCTOPOD
Nginx-Cache
X-Amcomm-Site
X-Webapp
X-E
X-GSL-Server
Cluster-ID
ViewMode
X-MCB-Server
X-Rewrite
Ttl
X-Cacheable-TTL
RequestId
X-Depends
X-Page
X-Dw-Trace-Id
X-Powered-By-Home.Pl
X-Pageid
X-Desc
X-Data-Request
X-Bcwwwid
X-MAT-GEO
Traffic-Origin
CP
X-Server-Generated
SG
X-Fpc
X-Magento-Action
Hname
Paypal-Debug-Id
X-HashTwo
X-HA-Backend
X-HA-Frontend
Content-Server
X-Refresh
TC-S-Cache-M
X-PageType
X-APP
Beyond-Iis
X-App-Runtime
X-Artvisual-Server
X-Detected-Device
TC-Cache-U
X-Key
X-Time-Microsecs
Yoncu-Errno
TC-Cache
TC-Cache-IC
X-Rq
X-Obj.Ttl
X-IIJ-Cache
X-DTC
X-Remote-Addr
Strikingly-Cache-Region
X-Adnet
X-Lb
X-Cache-Detail
X-Clara-ASAP
Ctx
MW-Webserver
Expect-Ct
RN-Server
X-ASAP-Cache
X-Proto
TC-S-Cache
X-Rebelmouse-Surrogate-Control
X-Response
X-Machine-Name
X-SV
X-MidCOM-Meta-Cache
X-RDP
X-Hstore
X-Rebelmouse-Cache-Control
X-DataDome
X-CRA-DC
X-Viator-Tapersistentcookie
Xc
DNNOutputCache
X-Cache-On
X-Cdn-Forward
X-Runtime-Affili
X-WA-Info
NS-VaryByCustom-Key
X-SERVER-NAME
X-RealServer
X-Atg-Version
Debug-Status
X-CACHE-KEY
X-Beresp-Ttl
X-ServerIndex
X-Batcache
X-Info
X-This-Proto
Resin-Trace
X-Mobile-URL
X-PBY
MS-CV
X-AWS
X-Layout
X-XHTML-Minification-Powered-By
X-CDN-RULE
X-Frame-Option
X-Vary-Options
X-SO
X-Header
X-Title
X-EC-Lua
X-CDN-COMPRESS
X-HP-Redirect
X-Airee-Node
X-Secret
X-Webstats-RespID
X-Ezoic-Cdn
X-Fstrz
X-AutoRu-App-Id
X-Server-Instance-Name
X-Sc-Cache
X-Autoru-Host
NtCoent-Length
X-Autoru-LB
SINA-LB
SINA-TS
X-Phpwcms-Page-Processed-In
X-7d-Trace-Id
X-Phpwcms-Release
X-7d-Instance-Id
W
Warning
X-Avvio-Cms-Cacheload
X-Application
Actual-Object-TTL
Access-Control-Request-Headers
SHInfo
X-Pagely-Cache
Myheader
X-SCM-Server-Number
X-Unique-Id
X-Ghost-Cache-Status
X-Actindo-RS
X-Agent
Response-Time
X-Backend-Status
X-Cache-Warmer
Pics-Label
X-Cache-Via
X-Atraveo-ETag
X-Atraveo-Cache-Control
X-Hosting
X-Atraveo-Expires
Mime-Version
X-Atraveo-From-Varnish-Cache
X-M
X-Cms-Mode
SBMCLOUD
Webluker-Edge
VServer
Server-Ip
X-Test
Worker
X-Compressed-By
ClientIP
X-Dev
X-Hrouter
X-CACHE-TTL
X-Atraveo-Zone
X-Cache-Action
X-Amz-Id-1
X-Analytics
X-Atraveo-Varnish-Server-Id
X-Atraveo-TTL
Gzip
X-Atraveo-Set-Cookie
F5-IpCliente
X-Atraveo-Param-Rm
Backend-Timing
X-Tag-Playlist
X-Varnish-Action
X-ChromeLogger-Data
X-Cache-Extended
X-Reflector
Web
X-Cache-Varnish
X-Reflector-Cache
Provider
Device
X-IP
X-Ssl-Cipher
X-DB
X-KoobooCMS-Version
X-ReqId
X-DSS
X-RPS
X-Cluster-Node
Ibm-Web2-Location
X-Map-Context
X-DW
X-Webkit-Csp
PagesDisplayed
Ews
X-Client-Ip
X-Sid
X-Req-Head-Response
X-RSL
X-Nginx-Request-Time
X-RAMCache
SERVER-ID
X-Drupal-Cache-Contexts
X-RPM
X-Varnish-URL
X-Middleton-PageSpeed
X-Enhanced-By
X-AG-MIPS
X-Forwarded-By
X-Generated-Date
X-DS1D
Server-ID
X-4ormat-Cacheable
MwpReleaseVersion
NZSpeedy
X-ASAP-Age
X-Instance-Name
X-Node-ID
X-XHR-Current-Location
Httpd-Identifier
MSThemeCompatible
X-MSEdge-Ref
X-Built-With
X-Turpentine-Esi
X-Varnish-Instance
X-Varnish-VCL
X-VLoc
StatusCode
X-Cache-TTL-Age
X-Wm-1
X-Wm-VIP
X-WPL-DATA
AGI-Request-ID
X-Server-Addr
X-Meta-MSThemeCompatible
X-Cache-TTL-Current
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
Container
X-Pass-Through
X-B2f-Not-Route
X-Amz-Meta-Content-Md5
X-ACLR-Version
X-EC2-Instance-Id
X-Svr
Home
Accept-Language
X-Varnish-Cache-Local
MageStack-Web-Node
MageStack-Tag
MageStack-Config
MageStack-Cacheable
MageStack-Cache-Status
MageStack-Debug
MageStack-Loadbalancer
MageStack-PageSpeed
MageStack-Magento-Version
Il-Cl
Proxy-Cache
GP-Remote-Addr
GP-Version
Hostname
X-Rocket-Nginx-Serving-Static
X-Nocache
Ez
X-FIRSTBase
X-Forwarded-Host
X-ProcessESI
X-Domino-CacheValidationWithETagResult
X-Domino-CacheValidationWithETagReason
X-Apm-Telemetry-Syncmark
X-Frames-Options
X-Plat
X-RemovedCookies
X-UnsetCookies
MageStack-Cache-Lifetime
MageStack-Cache-Hits
AC-ELC
X-Proxy-Cache-Key
X-Time-Zone
Aurora-Node
Language
X-BPool
X-BC
TheAnswer
X-Nginx-Request-Processing-Time
Cache-Tags
X-Src-Webcache
X-Sites
X-Serv
X-AMAZEEIO
X-Cache-Time
X-Ezpublish-Nodeid
X-Ezpublish-Installationid
X-BPool-Back
X-BPool-Bx-Cache
COMMERCE-SERVER-SOFTWARE
X-W3TC-Minify
X-Static
Fastly-Backend-Name
FastCGI-Cache
MageStack-Cache
MageStack-Area
X-Search-Id
X-Rewritten-By
X-Cjtype
X-BServer
X-BPool-Fx-Cache
X-Gannett-Site-Version
X-ManagedFusion-Rewriter-Version
X-Protected-By
X-NMT-Proxy
X-Restarts
MSSmartTagsPreventParsing
X-Deity
BackendServer
X-Zendesk-User-Id
X-Cluster
X-Container
Lb
SB-Cache-Life
Session-Id
SB-Site-Device
SB-Cache-Remaining
X-Box
X-Cname-TryFiles
X-Geo-IP
ENV
X-Upgrade-Enabled
Drupal-Pagecache-Memcache
Cache-Ctrol
X-Cms-Server
X-Skip-Cache
X-SH-Cache-Status
X-REDIRECTSERVER
RSB-LINK
X-Zendesk-Origin-Server
X-Backend-TTL
Cleartype
Brightspot-Id
X-Len
X-PHP-Response-Code
X-WebNode
X-LBPoolMember
X-Varnish-Auto-Cache-Miss
X-PBS-Fwsrvname
X-PBS-Appsvrname
X-Obj-Ttl
X-Varnish-Mode
X-JSESSIONID
X-PBS-Appsvrip
X-UPSTREAM-Address
X-Served
Vserver
X-CacheID
X-Cached-Status
X-Cache-FS-Status
VAR-Cache
TP-L2-Cache
X-WHOIS-Cached
X-Made-On
X-Catalyst
TP-Cache
X-NewsFlow-Sitename
Content-Legth
X-ELB
X-Country
X-FastCGI-Cache
X-HAProxy
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-Provided-By
X-VID
Progma
UrlWatchModule-Time
X-AppServer-Cache-Rule
X-RiS-PX
AMFplus-Ver
X-PG
X-Built-By
Provided-Host
Server-Hostname
X-Streams-Distribution
X-ServiceProvider
Note
FastCGI-Cache-Status
X-FreeTag-Count
X-Server-FQDN
X-Pubstack
X-UseReverse-Proxy
Kanooh-Host
X-Goog-Meta-Goog-Reserved-File-Mtime
X-DI
X-Clx-Request
X-Serendipity-InterfaceLangSource
X-DDM-SERVER
AR-ATIME
AR-CACHE
AR-SID
Hamster
Requested-Host
Server-Id
AR-PoweredBy
X-DDM-SERVER-UPDATED
X-Serendipity-InterfaceLang
X-Router-Backend
X-VG-WebCache
Content-Cache
X-Router
X-Uncacheable
X-SuperCache
X-PoweredBy
X-V
X-NewCloud-V-Cache
X-MSU-SOURCE
X-CSRF-Token
X-Srcache-Fetch-Status
X-Srcache-Store-Status
X-ENV
X-Oracle-DMS-ECID
X-ACCELERATE
X-DB-Content-Length
X-Stage
PServer
X-FF
X-Lima-Id
X-Varnish-Grace
X-HASH
WebServer
X-SilverStripe-Cache
X-Tt-Dbg
X-Grow-Guest
X-Grow-Cache
X-DEBUG-TTL
X-Brought-To-You-By
X-DeliveryServer
X-Dynamic
X-AISO-Cache
X-PvInfo
X-Archive-Orig-Content-Length
HA-Geocity
HA-Cloudapp
HA-Geocountry
HA-Geolat
HA-Geolon
X-Archive-Guessed-Charset
X-Requestid
Apple-Itunes-App
BlockPHPCallEnd
DB-Nickname
X-Archive-Orig-Connection
X-Bip
X-AISO-Cacheable
X-Dynamic-Cache
VC-NoCache
X-Faeria
X-Cache-V
X-MainProfileCategory
X-ETag
Tk
X-W-Cache-Hits
XDisk
X-W-Cache
Lookup-Cache-Hit
X-MainProfileID
X-MainProfileName
FindLaw
X-VC-Debug
X-Archive-Orig-Date
X-AISO-Server
X-Content-Parsed-By
X-SRV
X-Obvious-Tid
X-Archive-Orig-ETag
X-MainProfileURL
X-Not-Cacheable
X-Obvious-Info
HA-Georegion
HA-Host
X-D2id
Session-From
Memento-Datetime
DeleGate-Ver
X-MCF-ID
Returned-Status
X-Hcom-Styx-Info
LCache
X-Hcom-Origin-Id
X-Request-Processing-Time
X-Test-Debug
Proxy-Agent
X-Sn-Servicetimems
X-Ants-Machine-Id
Accept-CH
X-Varnish-Cached-TTL
X-Varnish-Cached
X-Ants-Host
X-AppVersion
X-Cache-Ttl
X-Vol-Mrp
X-RequesterIP
X-Custom-Name
Origin-Content-Encoding
Server-Node
Debug-Expires
Type
CD4
Debug-Cache-Control
HA-Urlpath
IES-Server
HA-Servedtime
X-Nginx-Page-Cache
X-UUID
X-Archive-Orig-Server
HA-Ipaddr
X-Request-Received
L5d-Success-Class
Load-Balancer
X-Cache-Origin
Z-Tpl
X-ACache
X-CGP
X-Group
X-Batcache-Reason
X-Vol-Correlation
NKBVHEADER
Redkiwi-Cloud
X-B3-Spanid
X-B3-Traceid
CDCHOST
X-LOCATION
X-Varnish-Currency
X-Turpentine-Cache
X-Varnish-Esi-Access
X-Varnish-Esi-Method
X-Varnish-Store
X-Varnish-Set-Cookie
X-Netrix-ID
X-UType
X-Scache
Referer-Policy
Copyright
Unique-Request-Id
X-GRACE
Cache-Status
X-FORWARDED-PROTO
MageStack-Cache-Warning
Ina-Bwaf
MageStack-Cacheable-Reason
MageStack-Response-Ttl
V-Age
X-Origin-Server
X-NodeID
X-Cache-Why
Edgecast
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-Instance
XX
X-Status
X-Flex-Tags
X-Flex-Tag
X-Magento-Lifetime
X-Varnish-Debug-Hits
LB
X-Xrds-Location
X-Flex-Lastmod
X-Flex-Lang
EQ-Cache
Aoestatic
X-Flex-Community
X-Flex-Evend
X-Flex-Evstart
PB-PID
PB-RID
Developer
X-Transaction-Name
MachineName
ReqUrl
X-COUNTRY-CODE
X-TargSmaku
X-Rack-CORS
X-CH-Device
X-Cachable
X-Count
X-Pool-Info
X-Powered-Developer
X-Backend-Name
X-Cache-Id
X-Pj-Cache-Status
X-Ocache
X-Processed
X-SCProxy
IsMobile
Application
X-Imforza-Hosted
X-Debug-Message
X-Cache-BE
X-Amz-Meta-Version-Id
X-Cache-HT
X-Cache-LB
X-Csrf-Token
Prototype-RootPath
X-Accel-Cache-Control
X-Front-Cache
WFE
X-IP-Address
X-No-Session
X-Tradeindia-Request-GUID
SB-Site-IE-VERSION
RSL-Trace-ID
X-Cache-Me-Harder
X-App-Version
X-FRUIT
CommunityServer
Fw-Cache-Status
Tempo
GranicusServer
X-Real-IP
X-PM-ID
X-Reason-Bp
EagleEye-TraceId-Daily
X-Beatles
INFO
X-Pixelsilk-Version
X-Pixelsilk-Server
X-Gyrobase-Publication
X-DN-Cache-Control
X-Name
X-NID
X-Origin-Cache
X-Beatles-Hits
X-Cache-ID
X-Ss-Location
X-Ss-Conf
X-TTL-Age
X-Would-Your-GrandPa-Wait
X-Your-GrandPa-Would-Wait
X-NO-BREACH
X-Goog-Meta-Replace
X-CCM
X-Cache-Set
X-Content-Type-Option
X-Does-He-Have-Time
X-Goog-Meta-Policy
X-Tradeindia-SMgmt