Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
X-AspNet-Version
P3P
X-Pingback
Via
X-UA-Compatible
Upgrade
X-Xss-Protection
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Adblock-Key
X-Varnish
Referrer-Policy
X-Request-Id
X-Check
X-Generator
X-Language
X-Template
X-Buckets
X-Type
X-Drupal-Cache
X-Cache-Group
X-Pass-Why
WPE-Backend
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Download-Options
X-Ac
X-Hacker
X-Cache-Hits
Host-Header
X-AspNetMvc-Version
X-Sorting-Hat-Section
X-Dc
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-FeatureSet
P3p
X-Via
X-Runtime
X-Powered-By-Plesk
X-Served-By
X-Contextid
X-PC-Hit
X-PC-Key
X-Amz-Cf-Id
X-UA-Device
X-ServedBy
X-PC-AppVer
MS-Author-Via
Content-Location
X-PC-Host
X-PC-Date
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-IPLB-Instance
X-Timer
X-Wix-Request-Id
X-Seen-By
Status
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Rid
X-Ua-Compatible
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
CF-Cache-Status
Cartoon
X-Tumblr-Pixel-1
X-Iinfo
Access-Control-Allow-Credentials
X-Backend
X-Tumblr-Pixel-2
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
Content-Encoding
X-Host
X-CST
Powered-By
X-Endurance-Cache-Level
X-Mod-Pagespeed
X-Cache-Hit
X-Cache-Enabled
X-Port
X-FRAME-OPTIONS
X-NewRelic-App-Data
X-CDN
X-Tumblr-Pixel-3
X-Newrelic-App-Data
X-Logged-In
Keep-Alive
X-DIS-Request-ID
X-Server-Powered-By
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server
X-Robots-Tag
X-Accel-Version
X-Request-ID
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Page-Speed
X-Content-Powered-By
X-LiteSpeed-Cache
Content-Security-Policy-Report-Only
X-Content-Digest
X-GitHub-Request-Id
X-Rack-Cache
X-AH-Environment
X-FW-Hash
X-FW-Server
X-Tumblr-Pixel-4
X-FW-Static
X-FW-Serve
X-FW-Type
Request-Context
X-Pad
X-Varnish-Cache
X-Hits
Edge-Control
X-Request-Country
X-Webcom-Cache-Status
X-XRDS-Location
SPRequestGuid
X-Trace
X-BC-Stapler
X-MS-InvokeApp
X-SharePointHealthScore
Access-Control-Expose-Headers
X-Node
Cf-Railgun
MicrosoftSharePointTeamServices
WP-Super-Cache
Edge-Cache-Tag
X-HS-Cache-Config
X-HS-Content-Id
X-Amz-Id-2
X-Amz-Request-Id
X-CF-Powered-By
X-HS-Combine-CSS
Timing-Allow-Origin
X-SERVER
Charset
X-Content-Security-Policy
X-Died
X-Webserver
X-FullPageCaching
X-Cache-Lookup
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
X-Cnection
X-PhApp
Request-Id
X-Fastly-Request-ID
Access-Control-Max-Age
X-Backend-Server
SPIisLatency
SPRequestDuration
MicrosoftOfficeWebServer
X-Edge-Cache-Key
X-Edge-Cache
EagleId
CONTENT-SECURITY-POLICY
X-Swift-CacheTime
X-Swift-SaveTime
X-CDN-Pop
X-CDN-Pop-IP
X-SS-Conf
X-SS-Location
Composed-By
Rating
X-Tumblr-Pixel-5
Grace
X-Device
X-Server-Name
X-Safe-Firewall
Liferay-Portal
Served-By
X-DDC-Arch-Trace
X-NF-Request-ID
Ali-Swift-Global-Savetime
X-Dw-Request-Base-Id
X-Tumblr-Content-Rating
X-Spip-Cache
X-Servedby
X-VCache
X-Hyper-Cache
X-Cloud-Trace-Context
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-HeyJason
Front-End-Https
X-Original-Date
X-Cluster-Node
Surrogate-Control
P-WS
P-LB
X-Loop
X-Microcache
X-TNCMS
X-LiteSpeed-Cache-Control
X-Clacks-Overhead
X-RateLimit-Remaining
X-RateLimit-Limit
X-OneAgent-JS-Injection
Display
X-Sol
X-Middleton-Display
X-StackifyID
X-Firenze-Processing-Times
X-Kinsta-Cache
X-Middleton-Response
Response
Content-Style-Type
X-FB-Debug
X-Acc-Exp
X-Jimdo-Instance
X-Jimdo-Wid
X-RateLimit-Reset
X-Wix-Punisher
Content-Script-Type
X-Vtex-Processado-Em
Public-Key-Pins
X-DNS-Prefetch-Control
X-Debug-Info
X-Age
X-Shopid
X-Amz-Version-Id
X-Shardid
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Podid-Cached
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Featureset
X-Sorting-Hat-Privacylevel
X-Magento-Tags
X-HOST
X-Tumblr-Pixel-6
X-XN-XNHTML
X-XN-Trace-Token
X-DynaTrace-JS-Agent
X-Ruxit-JS-Agent
Fpc-Cache-Id
X-Zen-Fury
X-Cached
X-Px
X-User-Agent
X-Goog-Hash
X-Url
X-LW-Cache
X-N-OperationId
X-Cache-Config
PageSpeed
X-Hostname
X-Version
Wpe-Backend
X-WebKit-CSP
X-Topify-Platform
Feature-Policy
X-Upstream
Retry-After
X-Frame-Option
Xkey
X-Generated-By
Refresh
X-Edge-Location
TCN
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Rt-Fastcgi-Cache
Allow
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Handled-By
X-Source
Access-Control-Request-Method
X-FORWARDED-FOR
Fastcgi-Cache
X-MiniProfiler-Ids
X-Request-Time
X-Whom
X-Cached-By
X-B-Cache
X-Loopia-Node
X-EdgeConnect-Origin-MEX-Latency
X-Content-Options
X-Fastcgi-Cache
X-URLSCHEME
X-CMS-Version
X-EdgeConnect-MidMile-RTT
Powered
X-ET-API-ROOT
X-From
X-ET-API-ORIGIN
X-ET-API-VERSION
X-Outils-CS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-RESOURCE
X-AspNetWebPages-Version
X-Magento-Cache-Debug
Last-Published
X-Platform-Cluster
X-Platform-Router
X-Platform-Processor
Product
X-Accel-Expires
X-Application-Context
ServedBy
X-DynaTrace
X-Powered-By-VTEX-Janus-ApiCache
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
Imagetoolbar
X-CacheServer
X-Vtex-Processed-At
X-Guploader-Uploadid
X-VTEX-Janus-Router-Backend-App
No
X-Varnish-Host
X-UD-Method
X-Tec-Api-Root
X-Tec-Api-Version
X-Varnish-Cache-Hits
Generator
X-Tec-Api-Origin
Warning
X-Varnish-Count
X-Varnish-HitMiss
X-Signature
X-Cache-Info
X-Umbraco-Version
X-Platform-Server
X-S
X-Microcachable
X-Device-Type
Host
X-Response-Time
X-Developer
X-Engine
Dmn
X-Cache-Key
X-Location-Id
X-PERF
Public-Key-Pins-Report-Only
X-ApacheServer
X-NWS-LOG-UUID
Fhost
Cache-Provider
X-Passed-To-DLL
X-Passed-To
Pagespeed
X-LBLID
X-Returned-From
X-Returned-From-DLL
X-Original-Request
X-Actual-URL
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
Cache-Key
X-Micro-Cache
X-F-Cache
X-ARC
X-Defender
X-Msg-2-Log
X-Varnish-Beresp-Ttl
X-Shop-Id
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Platform
X-Returned-From-BeforeDispatch
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Dns-Prefetch-Control
X-Stale
X-HS-Content-Campaign-Id
X-Recruiting
X-Ezoic-Cdn
X-Translation
X-Microcache-Status
X-Powered-By-360WZB
X-Hosted-By
X-Akam-SW-Version
Alternate-Protocol
Arr-Disable-Session-Affinity
Content-Hash
Origin
X-Cache-Age
DynaTrace
Surrogate-Key
X-Lambda-Id
X-Rnd
X-Via-JSL
X-Track
X-Platform-Cache
X-Acquia-Application-UUID
X-Cache-Rule
X-Instart-Request-ID
X-SSLProxy
X-SSLUpstream
X-I-Sp
X-SO
X-BS
X-Sapient
WZWS-RAY
X-Cache-Tags
X-Forwarded-For
Version
RTSS
Content-Disposition
MIME-Version
X-SVR-IIS
USPLoggingUUID
X-Dispatcher
X-Powered-By-VTEX-Janus-Edge
X-Magento-Cache-Control
X-Svr-Proxy
X-Duration
X-Supported-By
S-Cnection
SSPAppContext
X-App-Status
X-TransIP-Balancer
Akamai-IP
X-NetCat-Version
X-Environment
X-Powered-By-VelaWeb
X-URL
X-Abgroup
X-Matrix-Proxy
X-TransIP-Backend
X-Matrix-Server
X-Correlation-Id
X-Director
X-Dealeron-Backend
X-Cache-Namespace
X-DealerOn
X-Dealeron-Original-Url
X-Art-Request-Id
X-CSRF-Protection
X-ORACLE-DMS-ECID
Node
X-App-Hosting
Wsr-Cache
FAI-W-FLOW
X-Cache-TTL
X-Server-Id
X-Server-Upstream
X-Rocket-Nginx-Bypass
X-Expires-Orig
Pool
X-Page-Cache
X-I
X-SSL-Cipher
X-Cache-Debug
X-SSL-Protocol
X-LB-Node
X-Revision
Update-Time
Src-Update
X-Edge-IP
X-Cache-Lifetime
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Varnish-GracePeriod
X-Varnish-RemainingTTL
X-Cache-Control-Orig
X-Varnish-Seen-By
X-Debug
X-Correlation-ID
X-Daa-Tunnel
X-Generated
X-Hypernode
X-ServerName
X-Front
X-SV-CreatedAt
X-Gamma-Serve
X-SV-Cacheable
X-Drupal-Cache-Tags
X-SV-CacheTags
X-SV-Nginx-Duration
X-SV-FromDBCache
X-SV-Duration
X-SV-Pid
X-SV-Expires
X-SV-Edge
X-VARITI-CCR
X-ATG-Version
SN
X-Varnish-Cacheable
X-Storage
X-Vcap-Request-Id
X-Grace
X-Rocket-Nginx-Serving-Static
X-Client-IP
Accept-Encoding
X-Now-Id
X-Route-Server
X-Cache-Level
X-Cache-Handler
X-Cache-Server
X-Hiawatha-Cache
X-Acquia-Application-Trace
X-Server-ID
X-NoCache
SiteSpeed
X-Vhost
ServerID
Contao-Page-Layout
Cneonction
X-LB-Server
Req-Id
Powered-By-ChinaCache
X-Flow-Powered
X-Url-Base
X-Amz-Meta-S3cmd-Attrs
X-Discourse-Route
Content-Encoding-Handler
X-Geo-Country
X-Env
X-SRV
X-CJ-Soft
Edge-Control-Message
X-Forwarded-Proto
X-Pressidium-NinukisWP-Ver
X-Varnish-TTL
X-Dispatch
X-Content-Type-Option
If-Modified-Since
Cache
X-Firenze-Processing-Time
X-SmugMug-Values
X-Varnish-Url
X-Ttl
X-SmugMug-Hiring
X-TTFB
X-Drupal-Cache-Contexts
X-TTFB-L
X-Sucuri-ID
X-Litespeed-Cache-Control
Smug-CDN
X-Cache-Expires
X-GeoIP-Country-Code
X-Time
X-Cache-Only-Varnish
X-TransIP-Reserved
X-Middleware-Start
Lsrequestid
Cache-Tags
X-Trace-Id
Backend
X-Varnish-Backend
X-Varnish-IP
X-Locale
X-Last-Modified
X-Varnish-Age
X-Cache-Operation
Srv
X-Country-Code
X-Cache-Engine
X-Content-Encoded-By
X-GUploader-UploadID
X-Server-Instance
X-Unbounce-PageId
X-ORACLE-DMS-RID
X-Unbounce-VisitorID
X-Unbounce-Variant
X-Sucuri-Cache
X-Esi
X-Twitter-Response-Tags
X-LB
X-PwB-Node
Proxy-Connection
X-Transaction
X-Connection-Hash
Service-Worker-Allowed
X-Varnish-Retries
X-Frontend
X-CF-Passed-Proto
X-High-Performance
SEOMOZ
Strikingly-Cached
Strikingly-Cached-Version
MJ12bot
Strikingly-Cache-Region
X-Litespeed-Cache
X-Akamai-Device-Model
W
X-Amz-Rid
X-Akamai-Device-Characteristics
Use-Proxy
X-Speed-Cache
X-Cache-Type
X-FIRSTBase
X-Speed-Cache-Key
X-GeoIP-Country-Name
Server-Name
Location
X-Always-Cache
X-SRCache-Key
X-TTL
Content-MD5
Custom-Header
X-ServerID
NnCoection
X-Cache-Control
X-Service-Id
X-IsCacheURL
X-Webkit-CSP
AMF-Ver
X-WR-MODIFICATION
X-Cookie-Domain
X-Now-Cache
PICS-Label
ServerName
X-CDN-Forward
Page-Completion-Status
From-Origin
X-Wikidot-Static-Cache
X-N
X-Magnolia-Registration
X-Cache-Device-Type
MC
Section-Io-Id
X-Wikidot-Backend
X-BackendServer
Author
X-ID
X-Storage-Cache-Expires
FindLaw
X-Storage-Cache-Date
X-Origin
X-SDS
X-Storage-Cache
X-Srv
X-Nginx-Cache
X-Empowered-By
Pv
Nodo
X-Varnish-Server
X-Worker
S
X-Yadis-Location
Content-Transfer-Encoding
IBM-Web2-Location
Qs-Cache
X-Content-Age
NetMindSessionID
X-Xrds-Location
Adm-Server
Local-Info
Tracecode
X-Key
X-Pool
X-Symfony-Cache
Https
X-Pantheon-Phpreq
X-Pantheon-Site
X-Pantheon-Environment
X-BKSrc
Surrogate-Key-Raw
X-FTR-Request-ID
Edit
X-Dynamic-Cache
X-Processing-Time
Swift-Performance
X-TB-M
X-Amz-Storage-Class
X-Content-Security-Policy-Report-Only
Fw-Via
X-Amz-Meta-Content-Md5
X-Real-Server
Server-Timing
Accept-Charset
X-Nitro-Cache
X-ACMCache
Ohc-File-Size
X-Nbs
X-VC-Enabled
X-FW
X-Cache-PageType
Content_type
X-Cache-Fix
X-Vip
Hummingbird-Cache
X-Varnish-Ttl
X-HW
X-Analytics
X-Browser
CacheControlHeader
X-Distributor
X-NginX-Cache
X-Varnish-Hits
IM-Version
X-Role
X-LP
X-FireWall-Port
X-Cache-Miss-From
Access-Control-Allow-Method
X-Sedo-Request-Id
Drupal-Pagecache-Memcache
X-Shield-Request-Id
X-Shard
Pics-Label
X-Id
X-Orig-Vary
Prama
X-Adobe-Content
X-Adobe-Loc
X-A
X-Pagename
Backend-Timing
X-Hit-Cache
X-UPSTREAM
X-SP-Farm
X-PF-Uncompressing
X-SP-UniqueName
X-Disney-Akamai-Rule
Xc-Version
HCVer
Ram
X-4ormat-Cacheable
Ramp
X-Location
HAVer
Noq
X-WR-Flags
Cm-Server
X-LW-Web-Server
X-Varnish-ID
X-Stage
RequestId
X-Cache-2
X-ClientSide-Caching
X-Config-Blacklist-Version
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-WPL-DATA
X-Sys-Req-ID
X-E
X-Drectory-Script
X-Unique-ID
A-Powered-By
X-App
Server-Info
X-Resource
X-AEM
X-SERVER-NAME
X-Hstore
X-Remote-Addr
X-Redman-Backend
X-AVG-Country-Code
Cached
X-Redman-Final-Url
X-Varnish-Hostname
X-Cache-CFC
X-RequestId
X-Real-IP
X-Avg-Cookie-Expires
AsisCache
X-RealServer
SRV
X-JSESSIONID
X-Runtime-Rack
X-Hrouter
X-Akamai-Edgescape
X-App-Runtime
X-Runtime-Memory
X-Purge-URL
X-Purge-Host
X-Span
X-Proxy-Backend
Accept-Language
X-GoCache-CacheStatus
X-Proxy
X-Client-Vid
Pf.Web.Request.Id
Lookup-Cache-Hit
Web-App-Origin-Name
Cteonnt-Length
X-Client-Image-Vid
X-Runtime-Affili
X-EPiphany-Vid
WWW-Authenticate
X-AF-Userserver
X-V
X-Balanceador
X-Fedora-School-Id
X-Session-Reinit
X-Rq
Dtk-Cache-Check-0
X-NginX-Server
SHInfo
X-VC-TTL
X-Forwarded-Host
X-Generated-Timestamp
X-ServerIndex
Lb
Nginx-Cache
Accept-CH
X-Dw-Trace-Id
X-Force
Server-ID
X-Atraveo-Param-Rm
Identity
X-PRAM
X-Atraveo-Expires
X-Atraveo-From-Varnish-Cache
X-CLOUD-TRACE-CONTEXT
X-Atraveo-Set-Cookie
X-Atraveo-Varnish-Server-Id
X-Atraveo-Zone
X-Atraveo-TTL
X-Vcache
X-Appmachine-Environment
X-Atraveo-ETag
X-Request-Uri
X-Path-Route
X-Atraveo-Cache-Control
X-ARRServer
X-Culture
X-Dynatrace-Js-Agent
X-Source-ID
X-Ratelimit-Reset
Access-Control-Request-Headers
Proxy-Agent
X-Varnish-Debug-TTL
X-Ratelimit-Remaining
XDomainRequestAllowed
X-CB-Server
ScoreTracker
X-Jphone-Copyright
X-Pantheon-Az
X-Distil-CS
X-Session-ID
X-Debug-Token
X-Webstats-RespID
X-Varnish-Debug-Age
Request-Country
Beyond-Iis
Frame-Options
X-IIJ-Cache
Request-EU
X-CacheDebug
X-NWS-UUID-VERIFY
X-Ratelimit-Limit
Environment
X-Framework
VServer
X-Akamai-Transformed
X-Cache-Ttl
X-UA-Bot
X-Provisioner-Version
X-Server-IP
X-Cacheable-TTL
X-CacheFROM
Upgrade-Insecure-Requests
X-SDE-Name
X-Autoru-Host
X-Domain-Checked
X-Hosting-Env
WP-FROM-CACHE
Firespring-Website-Id
X-Frames-Options
X-VCS-Cacheable
X-Nginx-Host
X-Dev
X-Cms-Mode
X-ESI
X-App-Server
X-Processed-By
X-RiS-UFDI
Url
X-Envoy-Upstream-Service-Time
Worker
X-VCS-Ttl
CS-SERVER
SVR
Disablevcache
X-SE-Debug
X-Backend-Status
Front
IISExport
X-Req-Head-Response
Referer
X-GeoIP
Cmstype
X-Map-Context
Cmsid
CLMOB
X-Ms-Request-Id
Eomportal-Instance
Copyright
X-Detected-Device
X-HydroSheep
X-Proxy-Skip
X-JG-Page-Cache
X-HeBS-Cache-Status
X-Consent-Required
X-Agent
X-Upgrade-Enabled
X-SmartBan-URL
X-Adnet
X-SmartBan-Host
X-Rebelmouse-Cache-Control
X-Actindo-Request-Id
Myheader
X-Proxy-Cache-Key
X-Cache-Doesi
VANITY-HOST
X-Policy
AETN-State-Code
X-HTML-Minification-Powered-By
X-Actindo-Thread-Id
Access-Control
X-Cache-Dispatchercachecontrol
X-Soro
*
X-Rule
X-Cocoon-Version
X-Proxy-Cache-Control
X-Cache-Dispatcherpragma
X-Via-S
X-Refresh
X-Resty-Request-Id
X-Upstream-Backend
X-WebNode
X-PHP-Response-Code
X-Upstream-Status
X-PBY
X-Batcache
X-Oferteo-Domain
X-Header
X-TKP-SRV-ID
Max-Age
X-Amz-Id-1
X-Amcomm-Site
X-HashTwo
X-Data-Request
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-SID
AMP-Redirect-To
Num
Paypal-Debug-Id
X-GSL-Server
AETN-DEVICE
AETN-Country-Name
AETN-EU
AETN-Latitude
AETN-Postal-Code
AETN-Longitude
AETN-Country-Code
AETN-Continent-Code
X-Confluence-Request-Time
WP-AdvCache-MemCached
AKA-DEVICE
AETN-Area-Code
AETN-City
X-HA-Frontend
X-HA-Backend
X-Amz-Apigw-Id
Il-Cl
Play-Detected-Device
Play-Detected-UserAgent
X-7d-Trace-Id
Proxy-Cache
X-Amzn-RequestId
Home
X-CRA-DC
X-Highwire-RequestId
X-Cache-Varnish
X-Cache-On
X-Amzn-Trace-Id
X-Bip
Thanks
X-Aramark-SID
X-Varnish-Cache-Local
X-Plat
X-MAT-GEO
Traffic-Origin
X-Desc
X-Application
Access-Control-Allow-Header
X-DSMX-Rewrite-MS
X-7d-Instance-Id
X-B2f-Not-Route
X-Domino-CacheValidationWithETagReason
X-Domino-CacheValidationWithETagResult
X-DSMX-Render-MS
X-Highwire-SessionId
X-Actindo-Rs
IES-Server
RN-Server
Cleartype
Dispatcher
Resin-Trace
Machine
X-Smartcache-Keys
X-Resolver-IP
CF-Worker-Script
X-Smartcache-Timeout
X-WP
Xc
Load-Balancer
X-Compress-Hint
Pramga
X-Via-NSCOPI
X-CACHE-TTL
Dynatrace
Bios
X-DataDome
ServerTokens
X-Varnish-URL
X-Dynatrace
X-Highwire-Smart-Code
X-Highwire-Sitecode
COMMERCE-SERVER-SOFTWARE
X-SV
X-Rack-Cors
ServerSignature
X-HostName
NtCoent-Length
Web
X-Now-Trace
X-OpenCart-Lightning
Now
X-Skip-Cache
X-SilverStripe-Cache
X-Test
X-Flex-Tags
X-ASAP-Cache
Yoncu-Errno
X-Gyrobase-Publication
Ibf5scheme
X-Requestid
X-Flex-Tag
X-Served-Server
X-Flex-Lang
X-AutoRu-App-Id
MageStack-Cache-Lifetime
DNNOutputCache
X-SH-Cache-Status
X-Geo
Aurora-Node
X-Nx-All
X-Flex-Evstart
X-Flex-Evend
X-Flex-Community
X-Flex-Lastmod
N365rili
X-Qnm-Cache
X-Generated-Time
X-Beatles
X-M-Reqid
X-Timestamp
X-RiS-PX
X-Directory-Script
Ttl
VAR-Cache
X-Cache-Time
X-M-Log
X-Varnish-Id
X-Response
X-Nx
XX
Dis-Env
X-WEBMGR-CACHE
X-Proxy-Id
Webserver
X-Lb
SBSS
X-DN-Cache-Control
X-UnsetCookies
X-Geo-IP
Fastly-Backend-Name
X-AOL-HN
X-LBPoolMember
Viewport
X-Info
ServerNode
Provider
X-Protected-By
MageStack-Config
X-Middleton-PageSpeed
X-Blog
X-MCB-Server
MageStack-Tag
X-Custom-Name
MageStack-PageSpeed
MageStack-Magento-Version
X-Depends
X-Beget-Proxy
X-Garden-Version
MageStack-Web-Node
MageStack-Debug
X-CacheID
MageStack-Loadbalancer
HitType
Magicmarker
X-WebKit-CSP-Report-Only
MageStack-Area
MageStack-Cache
X-Ghost-Cache-Status
MageStack-Cacheable
Edgecast
MageStack-Cache-Status
Prot
X-Fastly-Request-Id
X-Cache-Detail
MageStack-Cache-Hits
FRONT-END-SECUREBROWSER
X-Secret
From
Fastly-Debug-Digest
X-Clara-ASAP
PServer
X-CAPServer
X-Vary-Options
NLCacheNote
Report-To
X-FORWARDED-PROTO
Device
X-APIVERSION
X-RAMCache
X-APIAUTH-VAL
X-Pj-Cache-Status
X-Appversion
X-Cdn-Forward
X-IP
BackendServer
X-ROUTING
X-Varnish-Debug-Hits
X-ENDPOINT
X-ORIKEY
X-Sid
X-TLS-Version
ViewMode
X-Access-Control-Allow-Origin
X-Deity
X-DB-Content-Length
X-Cache-Me-Harder
X-FastCGI-Cache-Status
CommunityServer
X-Varnish-Action
X-Reflector
X-Reflector-Cache
X-Tag-Playlist
X-Served
X-Gateway-Rate-Limit-Delayed
X-Appid
X-Varnish-Ip
X-Serv
VSID
Serverid
NODE
CDN-RequestId
OracleCommerceCloud-Sandiego
SINA-LB
CDN-Uid
SINA-TS
EagleEye-TraceId
CDN-PullZone
CommercePlatform-Version
CDN-CachedAt
X-ENV
X-Aramark-CSID
X-MainProfileCategory
X-MainProfileID
X-MainProfileName
X-Instance-Id
X-HS-Status
X-Title
X-Cache-FS-Status
YF-ID
X-DynamicCache
CDN-Cache
X-ZSITES-DNS
ServerIP
X-SAPP
Debug-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
Ufe-Result
TC-S-Cache-M
Tk
X-ACCELERATE
X-Origin-Date
X-FPC
X-Obvious-Tid
X-Obvious-Info
X-Client-Id
TC-S-Cache
TC-Cache-U
X-Layout
X-MrHost
X-Webcelerate
Nitro-Cache
OracleCommerceCloud-Version
BALANCEDTO
Session-From
TC-Cache-IC
TC-Cache
Provided-Host
Session-Id
X-Static
X-PBS-Appsvrname
X-Beluga-Node
X-Page
X-Beluga-Cache-Status
Ohc-Response-Time
X-Svr
X-Reqid
X-Beluga-Record
X-Compressed-By
X-Beluga-Status
X-Beluga-Response-Time-X
X-Beluga-Response-Time
Og
Content
X-We-Are-Hiring
X-Varnish-Grace
X-AppServer-Cache-Exception
CF-Cache-Key
UrlWatchModule-Time
X-Phpwcms-Page-Processed-In
X-Phpwcms-Release
Keywords
Filters
Description
X-AppServer-Cache-Rule
X-Cluster
X-Cache-Extended
X-Autoru-App-Id
X-ServiceProvider
X-Amzn-Remapped-Date
X-PBS-Fwsrvname
X-Status
X-PBS-Appsvrip
X-NewsFlow-Sitename
X-MainProfileURL
X-Streams-Distribution
X-MyName
X-Server-Hostname
X-DevSrv-CMS
HSTS
X-Box
X-Cache-Action
X-Block-Rule
X-Beluga-Trace
TP-L2-Cache
TP-Cache
X-CacheLoc
X-Nginx
X-AppServer-Status
X-Block-RuleID
Arrnode
MS-CV
X-BPool-Back
X-Now-Instance
X-Server-Generated
X-Airee-Node
X-Vol-Mrp
X-Vol-Correlation
X-Global-Transaction-ID
X-BServer
X-Gannett-Site-Version
X-ManagedFusion-Rewriter-Version
X-Captured
X-Firefox-Spdy
X-FromPodPressCache
X-Wodby-Node
Hosted-By
X-Instance
X-EC2-Instance-Id
X-NoIndex
X-Origin-Cache
X-Shopware-Allow-Nocache
X-Route
CDCHOST
X-Custom-Header
Server-Id
NGX
SB-Cache-Life
SB-Cache-Remaining
SB-Site-IE-VERSION
X-Backside-Transport
X-Node-Id
X-Mighty-Proxy
X-Max-Age
X-Varnish-Cache-Ttl
X-Test-Debug
X-SCM-Server-Number
X-Pass-Through
Ssl-Proxy-Server
X-W3TC-Minify
Cf-Ipcountry
X-XHTML-Minification-Powered-By
Hit-Count
Purge-Cache-Tags
Response-Time
X-PM-ID
Pragrma
X-Cache-Warmer
X-Powered-By-ADS
PBS
X-Enhanced-By
REFRESH
X-NodeID
AMP-Access-Control-Allow-Source-Origin
X-Src-Webcache
X-Search-Id
Page-Template
NZSpeedy
X-Rewritten-By
Id
X-Shopware-Cache-Id
SB-Site-Device
X-ProBase-Server
X-Cname-TryFiles
X-MID-Host
X-Build-Id
X-Say-Cacheable
X-Proxy-Server
X-ProcessESI
X-Say-TTL
X-Cache-LB
WN
X-HA
X-ReqId
X-Powered-By-Home.Pl
X-Processed
X-This-Proto
AC-ELC
MageStack-Cache-Lifetime-Sent
MageStack-Last-Modified
X-M
MageStack-Cache-Warning
Tempo
HTTPS
X-Ms-Version
X-Nginx-Request-Processing-Time
X-ETag
X-Who
X-Cache-Node
X-RemovedCookies
X-AMAZEEIO
X-CH-Device
X-Goog-Meta-Replace
X-Goog-Meta-Policy
GranicusServer
X-Origin-Server
X-V-Cache
X-SayCDN-TTL
Amfplus-Ver
X-Varnish-Backend-Beresp-Backend
X-Rack-CORS
X-WN-ClientGroup
Server-Ip
X-Mobilized-By
SERVER-ID
X-Oracle-Dms-Ecid
X-Actual-Url
X-DEBUG
X-CACHE-KEY
X-PROCESSED-BY
X-Xml-Http-Blocked
X-Server-Addr
X-COUNTRY-CODE
X-Scheme
X-RENDER-TIME
Language
X-ASAP-Age
PB-RID
PB-PID
X-Ssl-Cipher
WebServer
X-JoinUs
X-Old-Content-Length
X-Cache-Via
X-Machine
PROGMA
LB
X-FG-RequestId
Amp-Access-Control-Allow-Source-Origin
MwpReleaseVersion
X-From-Cache
X-Cache-HT
X-Appmachine-Name
Fastly-Restarts
X-Appmachine-Duration
X-GZip
X-Optimization
X-Appmachine-CreatedOn
X-Ruxit-Js-Agent
X-Serverid
X-Varnish-TTL-Debug
X-Varnish-Age-Debug
Returned-Status
X-NMT-Proxy
X-Magento-Route
X-Pageid
X-No-Session
X-Tradeindia-Request-GUID
X-Tradeindia-SMgmt
ClientIP
X-Vid
X-Front-Cache
X-Fastly-Backend-Reqs
Fastly-Drupal-Html
X-UT-Cache
Origin-Vm
RSL-Trace-ID
X-Country
X-Beresp-Ttl
F5-IpCliente
Gzip
SERVER-NAME
Actual-Object-TTL
D
X-Amz-Meta-S3b-Last-Modified
X-AWS
X-Unique-Id
X-Middleton-Pagespeed
X-Healthy
VC-NoCache
ProxiaInstanceId
X-Avvio-Cms-Cacheload
X-Bitrix-Composite
X-Catalyst
X-Time-Spent
X-TEST
Servername
Ews
X-Cache-Id
X-Enabled1
X-Enabled3
X-Enabled2
X-Telligent-Evolution
X-Router
X-InDy-Query
X-InDy-Memory
X-InDy-Time
X-Mobile-Rewrite
X-ORIGN-SERVER
X-Origin-Upstream-Status
EQ-Cache
PagesDisplayed
Generate-Time
X-SG-Server
Prototype-RootPath
X-Accel-Cache-Control
X-SSLTerm-Server
X-Itkg-Cache-Tags
MachineName
X-Expires
X-CAMPUSSUITE-DEBUGGING
V-Cache-Ttl
X-CAMPUSSUITE-ENVIRONMENT
X-CAMPUSSUITE-TENANT
X-CSRF-Token
X-Grid-Server
X-UPServer
X-MSU-SOURCE
X-DDM-SERVER-UPDATED
X-CloudBurst-WordPress
X-CloudBurst-Frontend
X-CloudBurst-Cache
X-PoweredBy
X-DDM-SERVER
X-Pagely-Cache
Web-Server
Unique-Request-Id
X-BIT-Node
X-Batcache-Reason
X-Clx-Request
X-Server-Ip
X-CloudBurst-Backend
X-Requested-With
Content-Sn
BlockPHPCallEnd
DB-Nickname
HA-Cloudapp
HA-Geocountry
HA-Geocity
Backend-Powered-By
X-VG-WebCache
X-Rocket-Nginx-Reason
X-Rocket-Nginx-File
Sl-Pgid
X-SuperCache
X-UType
Requested-Host
X-Served-From
X-Mobile-Device-Type
X-HP-CAM-COLOR
X-Mobile-Device
X-Debug-Message
X-Olaf
X-Navigation-Version
X-SCProxy
X-D2id
X-Cachable
X-SEA-Instance-Name
X-BeResp-Ttl
X-Content-Type
X-UPSTREAM-Address
X-Az
X-Amz-Meta-Version-Id
X-Log
ID
X-VHosting-Cache
X-Oracle-Dms-Rid
X-Varnish-Cache-Control
X-Qiniu-Zone
X-Boot
X-FastCGI-Cache
HitInfo
X-Activity-Id
X-SSL
X-OPNET-Transaction-Trace
X-Cache-ID
HA-Geolat
HA-Geolon
MSThemeCompatible
MSSmartTagsPreventParsing
X-Abuse
FastCGI-Cache
StatusCode
EN-User
Httpd-Identifier
CmsfirstPublishTimestamp
X-Varnish-Cached
X-Transaction-Name
X-Varnish-Cached-TTL
X-XHR-Current-Location
X-Built-By
X-Dck
X-Zendesk-User-Id
X-Zendesk-Origin-Server
X-Meta-MSSmartTagsPreventParsing
X-Meta-Imagetoolbar
X-Meta-MSThemeCompatible
X-Nginx-Page-Cache
X-Proto
X-Node-App
X-Instance-Name
X-Hit
X-Cache-TTL-Age
X-WA-Info
X-Cache-TTL-Current
X-Firewall
X-RequesterIP
X-Sn-Servicetimems
X-Render-Time
X-PressLabs-Stats
NKBVHEADER
Progma
Request-Time
TYPO3-Sitename
TYPO3-Pid
ModuleCacheType
L5d-Success-Class
HA-Host
HA-Georegion
HA-Ipaddr
HA-Servedtime
HA-Urlpath
X-B3-Sampled
X-Bcwwwid
X-Homeaway-Requestmarker
X-HAProxy
X-Jcms-Ajax-Id
X-MCF-ID
X-Ruby-Cluster-ID
X-NginX-Upstream
X-Fpc
X-Ser
Arrow-RequestId
SS
X-Built-With
X-Cdn-Origin
X-CGP
DrivedBy