Threat Level: green Handler on Duty: John Bambenek

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
X-Cache
Strict-Transport-Security
P3P
X-AspNet-Version
CF-RAY
X-Pingback
Age
Content-Language
X-UA-Compatible
Via
Access-Control-Allow-Origin
X-Adblock-Key
Upgrade
X-Varnish
X-Cacheable
X-Check
X-Template
X-Language
P3p
Content-Security-Policy
X-Generator
X-Buckets
X-Drupal-Cache
X-Type
X-Xss-Protection
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Request-Id
X-Ac
X-Powered-By-Plesk
Content-Location
X-Cache-Hits
X-Runtime
X-Permitted-Cross-Domain-Policies
MS-Author-Via
X-Download-Options
Host-Header
Alt-Svc
X-ShopId
X-IPLB-Instance
X-Sorting-Hat-PodId-Cached
X-ShardId
X-Dc
X-Sorting-Hat-PodId
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Request-ID
X-Powered-CMS
Cartoon
Status
X-Served-By
X-UA-Device
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Via
X-Amz-Cf-Id
X-Iinfo
X-Cache-Status
X-Wix-Server-Artifact-Id
X-Backend
X-Contextid
X-Timer
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-ServedBy
X-DIS-Request-ID
X-PC-Hit
X-PC-Key
CF-Cache-Status
X-Mod-Pagespeed
Powered-By
X-PC-AppVer
X-PC-Date
X-PC-Host
X-Logged-In
X-Server
Content-Encoding
Keep-Alive
Expect-CT
X-Host
X-Rid
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Hit
X-CDN
X-Port
X-CST
X-Tumblr-Pixel-1
Referrer-Policy
X-Server-Powered-By
X-Pad
X-Robots-Tag
X-Tumblr-Pixel-2
X-Cache-Enabled
X-Nginx-Cache-Status
X-Endurance-Cache-Level
WP-Super-Cache
X-Accel-Version
Fastly-Debug-Digest
X-Seen-By
X-Wix-Renderer-Server
X-Wix-Request-Id
X-Page-Speed
X-Turbo-Charged-By
X-Wix-PunisherID
X-Content-Powered-By
X-Drupal-Dynamic-Cache
X-Tumblr-Pixel-3
X-Varnish-Cache
X-Content-Digest
X-Rack-Cache
X-AH-Environment
X-Forwarded-For
Content-Security-Policy-Report-Only
X-Forwarded-Proto
SPRequestGuid
X-Proxy-Cache
X-SharePointHealthScore
Surrogate-Key-Raw
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
MicrosoftSharePointTeamServices
X-MS-InvokeApp
X-Request-Country
X-GitHub-Request-Id
X-Cnection
X-XRDS-Location
X-Cache-Lookup
X-LiteSpeed-Cache
X-Original-Date
Edge-Control
Cf-Railgun
X-Safe-Firewall
X-FullPageCaching
Timing-Allow-Origin
MicrosoftOfficeWebServer
Request-Id
X-Amz-Request-Id
X-Amz-Id-2
X-Webserver
Charset
X-PhApp
X-Died
X-FW-Hash
X-Node
X-FW-Type
X-FW-Static
X-FW-Serve
SPIisLatency
SPRequestDuration
X-INKT-SITE
X-INKT-URI
X-Content-Security-Policy
Edge-Cache-Tag
X-Hits
Composed-By
X-HS-Cache-Config
X-HS-Content-Id
Access-Control-Max-Age
X-CF-Powered-By
X-Tumblr-Pixel-4
Liferay-Portal
X-Swift-SaveTime
X-Swift-CacheTime
Grace
Served-By
EagleId
Access-Control-Expose-Headers
X-Hyper-Cache
X-Spip-Cache
Content-MD5
X-CDN-Pop
X-CDN-Pop-IP
X-BC-Stapler
X-Firenze-Processing-Times
X-Device
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
Request-Context
X-Server-Name
X-Backend-Server
Rating
X-Newrelic-App-Data
X-Microcachable
X-Fastly-Request-ID
X-Dw-Request-Base-Id
X-Microcache
X-VCache
X-Tumblr-Content-Rating
X-RateLimit-Remaining
X-RateLimit-Limit
Refresh
X-FB-Debug
Content-Style-Type
X-RateLimit-Reset
X-ServerName
X-Clacks-Overhead
Content-Script-Type
X-User-Agent
X-Jimdo-Wid
X-Jimdo-Instance
X-Cloud-Trace-Context
X-TNCMS
X-Loop
Real-Hostname
Public-Key-Pins
Xkey
X-Cache-Config
X-XN-XNHTML
X-XN-Trace-Token
Surrogate-Control
X-SERVER
X-Acc-Exp
Front-End-Https
X-Hostname
X-DDC-Arch-Trace
X-Age
Fpc-Cache-Id
X-Aspnetmvc-Version
X-Generated-By
X-N-OperationId
X-Px
PageSpeed
X-Tumblr-Pixel-5
X-Cached
X-LiteSpeed-Cache-Control
X-StackifyID
X-Topify-Platform
X-Middleton-Response
Response
Display
X-Middleton-Display
X-Sol
X-SS-Location
X-SS-Conf
X-MiniProfiler-Ids
X-WebKit-CSP
X-DNS-Prefetch-Control
X-FORWARDED-FOR
X-Cached-By
X-Url
Surrogate-Key
X-Zen-Fury
X-CMS-Version
X-Outils-CS
TCN
X-Content-Options
X-Request-Time
X-URL
X-Pantheon-Environment
X-Pantheon-Phpreq
X-Pantheon-Site
Rt-Fastcgi-Cache
X-Cdn
X-HOST
X-Whom
X-OneAgent-JS-Injection
X-Varnish-TTL
X-PERF
X-ApacheServer
X-Umbraco-Version
Edge-Control-Message
X-Amz-Version-Id
X-DynaTrace
Product
X-Handled-By
X-Varnish-Cache-Hits
Imagetoolbar
X-Ruxit-JS-Agent
Access-Control-Request-Method
X-AspNetWebPages-Version
X-DynaTrace-JS-Agent
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Alternate-Protocol
Host
X-From
X-Correlation-Id
X-Msg-2-Log
X-Engine
ServedBy
DynaTrace
Dmn
X-Kinsta-Cache
X-Magento-Tags
Powered
X-Micro-Cache
X-NWS-LOG-UUID
Fhost
X-Hosted-By
X-Servedby
P-LB
P-WS
Generator
X-Cache-Rule
X-LBLID
X-Location-Id
WZWS-RAY
X-Powered-By-360WZB
X-Track
X-CacheServer
X-B-Cache
X-Edge-Location
X-Actual-URL
X-Recruiting
X-Goog-Hash
X-Passed-To-DLL
X-Passed-To
X-Returned-From
X-Returned-From-DLL
X-Powered-By-VTEX-Janus-ApiCache
X-Original-Request
X-VTEX-Cache-Status-Janus-ApiCache
X-RESOURCE
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Vtex-Processed-At
No
X-Developer
X-Instart-Request-ID
Arr-Disable-Session-Affinity
Origin
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Matrix-Server
X-Tumblr-Pixel-6
X-Fastcgi-Cache
X-Varnish-Beresp-Ttl
X-Passed-To-BeforeDispatch
X-Matrix-Proxy
X-Varnish-Beresp-Status
Fastcgi-Cache
X-Varnish-Beresp-Grace
X-Powered-By-VTEX-Janus-Edge
X-Varnish-Host
X-URLSCHEME
X-App-Hosting
X-Stale
X-I-Sp
X-BS
X-Response-Time
X-Defender
X-Shop-Id
X-Cache-Age
X-Accel-Expires
X-Source
X-LB
X-TransIP-Balancer
X-Internal-ReqID
X-Cache-Info
X-Art-Request-Id
X-Application-Context
X-Cache-TTL
Akamai-IP
X-UD-Method
X-VARNISH-Cache
X-Akamai-Transformed
X-HS-Content-Campaign-Id
X-Varnish-RemainingTTL
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Varnish-GracePeriod
X-Varnish-Seen-By
X-Upstream
X-Varnish-HitMiss
X-Gamma-Serve
X-Storage
X-Varnish-Count
X-NetCat-Version
X-TransIP-Backend
USPLoggingUUID
X-Platform-Cluster
X-Device-Type
X-Platform-Processor
X-Platform-Router
X-Version
Powered-By-ChinaCache
X-S
Ohc-File-Size
X-Varnish-Cacheable
Content-Hash
X-Expires-Orig
Content-Disposition
X-Cache-Debug
X-Route-Server
X-Rocket-Nginx-Bypass
Pool
X-Cache-Tags
X-I
Version
X-Origin
IBM-Web2-Location
X-Supported-By
X-Front
X-Content-Encoded-By
X-Cache-Operation
X-Powered-By-VelaWeb
Srv
X-UPSTREAM
X-Platform
Public-Key-Pins-Report-Only
X-VTEX-Cache-Status-Janus-Edge
X-Translation
X-Revision
X-Microcache-Status
X-Cache-Key
X-Dispatcher
Last-Published
Node
X-Signature
MIME-Version
X-Debug-Info
HTTPS
X-EdgeConnect-Origin-MEX-Latency
X-NoCache
X-Daa-Tunnel
X-Firenze-Processing-Time
X-Server-Upstream
X-ATG-Version
X-Varnish-Age
ServerName
X-NewRelic-App-Data
X-SV-Nginx-Duration
X-SV-Duration
X-SV-Expires
X-SSL-Cipher
X-SV-FromDBCache
X-SSL-Protocol
X-SV-Pid
X-SV-CreatedAt
X-SV-CacheTags
X-SV-Edge
X-SV-Cacheable
X-Hypernode
X-Server-ID
X-Flow-Powered
X-EdgeConnect-MidMile-RTT
SSPAppContext
X-Duration
X-Varnish-Backend
X-AOL-HN
X-Sapient
X-Platform-Server
X-Platform-Cache
X-Cache-Lifetime
X-Dns-Prefetch-Control
X-Abgroup
X-Vcap-Request-Id
X-Server-Id
X-LB-Node
X-Page-Cache
SN
X-Last-Modified
X-TTL
X-Cache-Control-Orig
FAI-W-FLOW
X-Dispatch
ServerID
Cache-Key
X-PwB-Node
X-Country-Code
Cache-Tag
X-SDS
Page-Completion-Status
X-F-Cache
Lsrequestid
X-Geo-Country
X-CJ-Soft
X-Abuse
X-Client-IP
Edge-Content-Tag
X-Cache-Only-Varnish
X-Magento-Cache-Debug
X-Director
Cneonction
X-Cookie-Domain
WSR-Cache
X-Url-Base
X-Edge-IP
Accept-Encoding
X-LW-Cache
Proxy-Connection
X-Debug
X-Grace
Req-Id
IM-Version
Allow
X-GeoIP-Country-Code
X-Speed-Cache-Key
X-ServerID
X-Speed-Cache
X-Cache-Expires
NnCoection
X-ORACLE-DMS-ECID
X-BackendServer
X-Cache-CFC
X-GeoIP-Country-Name
Pv
Location
PICS-Label
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-ARC
X-Amz-Meta-S3cmd-Attrs
Author
X-Cache-Server
X-Processing-Time
X-Ttl
X-Akamai-Device-Model
X-Nbs
X-Time
X-Akamai-Device-Characteristics
If-Modified-Since
X-Frontend
X-Purge-URL
X-Content-Age
X-RequestId
Content-Encoding-Handler
Backend
Cache-Provider
X-IsCacheURL
X-Discourse-Route
X-Yadis-Location
Cteonnt-Length
X-NB-Cached-Page
X-SERVER-NAME
X-Middleware-Start
A-Powered-By
X-FW
Section-Io-Id
Cached
S-Cnection
X-Goog-Generation
X-Loopia-Node
X-Goog-Metageneration
AMF-Ver
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Nginx-Cache
Fw-Via
X-SE-Debug
X-Id
X-Sucuri-ID
X-Cache-Engine
Server-Info
MJ12bot
SEOMOZ
X-Proxy
X-Browser
Use-Proxy
X-PF-Uncompressing
X-Purge-Host
X-Worker
Accept-Charset
X-Cache-Level
X-Processed-By
X-BKSrc
X-Varnish-Url
X-Sucuri-Cache
X-N
S
X-Shield-Request-Id
X-Pressidium-NinukisWP-Ver
X-Generated
X-Lambda-Id
X-Cache-Handler
Access-Control-Allow-Header
X-Varnish-IP
Nitro-Cache
Cache
Identity
Qs-Cache
Frame-Options
Content-Transfer-Encoding
X-DealerOn
X-Trace
X-Hiawatha-Cache
X-ID
X-Config-Blacklist-Version
Xc-Version
X-Empowered-By
X-Vhost
X-Content-Type-Option
X-Always-Cache
X-Mobilized-By
Nodo
X-Cache-Type
X-Real-Server
X-CDN-Forward
X-Cache-Fix
CacheControlHeader
X-SO
RTSS
X-Cache-TTL-Remaining
Tracecode
X-WR-Flags
MC
Local-Info
X-Cache-PageType
X-Healthy
Eomportal-Instance
X-Varnish-Server
X-Framework
X-Cache-Control
NetMindSessionID
X-Cf-Powered-By
X-Amz-Storage-Class
HitType
BALANCEDTO
EagleEye-TraceId
X-ClientSide-Caching
HCVer
HAVer
X-Symfony-Cache
Cm-Server
X-Powered-By-Server
Retry-After
SVR
Thanks
X-Pagename
X-SRCache-Key
X-Hit-Cache
X-Yottaa-Optimizations
X-Connection-Hash
X-HP-Trace-Project
WWW-Authenticate
X-App-Server
X-Drupal-Cache-Tags
Buuteeq-Source
X-Transaction
X-Twitter-Response-Tags
X-Yottaa-Metrics
X-Environment
X-AF-Userserver
X-JG-Page-Cache
X-HP-Trace-ID
X-VC-TTL
X-CDN-Cache-Status
Disablevcache
X-TB-M
X-CB-Server
X-ACMCache
X-Magnolia-Registration
X-CDN-Node
X-LB-Server
X-Orig-Vary
RATING
X-Content-Security-Policy-Report-Only
X-Client-Vid
X-Varnish-Ttl
SRV
X-Client-Image-Vid
Front
X-EPiphany-Vid
X-Magento-Cache-Control
X-Site-Name
X-Directory-Script
X-Remote-Addr
Keywords
X-Unique-ID
X-Session-Reinit
IISExport
X-Varnish-ID
X-LW-Web-Server
X-Cache-Device-Type
X-Server-IP
X-Varnish-Hits
Magicmarker
Ufe-Result
X-Srv
X-OPNET-Transaction-Trace
From-Origin
X-Route-To
X-Traffic
X-Location
X-Cocoon-Version
X-Generated-Time
Machine
NODE
X-Varnish-Hostname
X-Resty-Request-Id
X-DataDome
X-Source-ID
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
X-Fedora-School-Id
X-ORACLE-DMS-RID
X-CAPServer
X-Runtime-Memory
Fastly-Backend-Name
Pics-Label
X-FORWARDED-PROTO
X-Sys-Req-ID
X-Cache-Doesi
Description
X-FireWall-Port
AC-ELC
Content_type
Server-Name
X-VARITI-CCR
X-LP
VANITY-HOST
X-Webcelerate
X-SmugMug-Hiring
Max-Age
X-SmugMug-Values
X-TTFB
X-NginX-Server
X-HydroSheep
X-Resolver-IP
X-Adobe-Loc
X-Adobe-Content
X-Varnish-Retries
X-NginX-Cache
X-CF-Passed-Proto
X-High-Performance
X-TTFB-L
ServerSignature
X-HW
Smug-CDN
X-Nginx-Host
X-Key
ServerTokens
Provider
X-Page
X-Smartcache-Keys
X-Smartcache-Timeout
Ctx
X-WP
X-Proto
X-VC-Enabled
RN-Server
X-WHOIS-Cached
X-UA
CLMOB
X-Dynatrace-Js-Agent
X-Mobile-URL
X-Amz-Meta-Cb-Modifiedtime
NtCoent-Length
X-Cache-Detail
From
X-Runtime-Rack
X-GeoIP
X-Cache-Provider
X-Cache-Source
X-Captured
Bios
X-Backend-Status
X-Debug-Token
X-IIJ-Cache
NLCacheNote
W
X-Blog
Cmsid
X-Unbounce-Variant
X-Unbounce-PageId
X-Render-Time
X-Server-Instance
X-Unbounce-VisitorID
X-Served-Server
X-OpenCart-Lightning
Cmstype
MW-Webserver
Home
X-Frame-Option
AsisCache
X-Garden-Version
Id
X-Drectory-Script
WN
X-Env
X-WN-ClientGroup
X-WR-MODIFICATION
X-Correlation-ID
X-AEM
X-ServerIndex
X-Balanceador
ScoreTracker
X-Author
X-ARRServer
X-App
Strikingly-Cached-Version
Strikingly-Cached
Strikingly-Cache-Region
X-Session-ID
Yoncu-Errno
Web-App-Origin-Name
X-Cache-Node
X-Esi
X-ETag
SBGI-9
SBGI-Device
X-Adnet
X-Clara-ASAP
SBGI-7
X-Grid-Server
X-ASAP-Cache
SBGI-RealPath
X-DTC
X-HP-Redirect
X-A
X-Middleton-PageSpeed
X-Info
X-Disney-Akamai-Rule
X-RiS-UFDI
NCache
Og
X-Cache-Keep
SBGI-RenderTime
SG
X-Cache-On
X-FRUIT
Sophnep-Edge-FX
X-RealServer
X-Config-By
X-Proxy-Cache-Key
SBGI-10
Response-Time
X-RDP
SBGI-5
DNNOutputCache
X-Machine-Name
X-Desc
X-Actindo-RS
X-ProcessESI
X-Rebelmouse-Cache-Control
X-Time-Microsecs
X-RemovedCookies
X-Rebelmouse-Surrogate-Control
SBGI-1
X-Distil-CS
X-App-Status
X-Force
X-Atraveo-Set-Cookie
X-Atraveo-TTL
X-PRAM
Dispatcher
X-Atraveo-Varnish-Server-Id
X-Atraveo-Zone
X-Atraveo-Param-Rm
X-Atraveo-ETag
X-Atraveo-Expires
X-Atraveo-Cache-Control
X-Atraveo-From-Varnish-Cache
X-Distributor
X-AutoRu-App-Id
X-PM-ID
X-Dw-Trace-Id
X-Analytics
Backend-Timing
X-App-Runtime
X-Cdn-Forward
X-Ser
X-Culture
X-Runtime-Affili
X-Drupal-Cache-Contexts
X-Rq
X-Goog-Meta-Replace
X-Autoru-Host
X-Jphone-Copyright
Xc
X-Req-Head-Response
X-Map-Context
X-Goog-Meta-Policy
VServer
X-CacheResult
X-Autoru-LB
X-Cluster-Node
CommunityServer
Cluster-ID
X-Trace-Id
X-BackEnd
X-Static
Content-Server
Hname
Web
Server-ID
X-MAT-GEO
Ibf5scheme
Paypal-Debug-Id
X-Batcache
N365rili
X-Highwire-RequestId
Access-Control-Request-Headers
X-Avvio-Cms-Cacheload
X-Frames-Options
X-Cache-TTL-Current
Beyond-Iis
X-Cache-TTL-Age
X-Machine
X-ReqId
X-E
X-HTML-Minification-Powered-By
X-Rocket-Nginx-Serving-Static
X-Varnish-Debug-TTL
Dis-Env
X-Varnish-Debug-Age
X-Application
TC-S-Cache-M
X-Highwire-SessionId
X-MSEdge-Ref
X-Airee-Node
X-Viator-Tapersistentcookie
X-Webkit-CSP
X-Response
X-Plat
X-SmartBan-Host
TC-Cache-U
TC-S-Cache
TC-Cache-IC
TC-Cache
X-SmartBan-URL
X-CRA-DC
X-Cached-Status
X-Provisioner-Version
X-Src-Webcache
X-Domain-Checked
X-Wikidot-Static-Cache
X-SV
X-Site
XDomainRequestAllowed
X-Wikidot-Backend
NZSpeedy
X-Optimization
X-Oracle-DMS-ECID
X-ENV
Url
X-Nginx
X-APP
X-PageType
X-Varnish-Info
X-EC2-Instance-Id
X-Lb
X-Batcache-Reason
X-Artvisual-Server
X-This-Proto
Ttl
X-Hosting-Env
X-Varnish-Action
X-Rack-Cors
X-Rack-CORS
X-We-Are-Hiring
X-Stage
X-SDE-Name
Device
X-ACCELERATE
X-Zendesk-Origin-Server
X-Old-Content-Length
X-PBY
X-GSL-Server
X-Obj.Ttl
X-Cache-Via
X-Depends
X-Powered-By-Home.Pl
Edgecast
X-Detected-Device
X-Zendesk-User-Id
Worker
Warning
X-KoobooCMS-Version
SS
Gzip
ServerIP
F5-IpCliente
X-Cache-Warmer
ClientIP
Myheader
X-Upstream-Backend
X-Rewrite
X-Server-Addr
X-4ormat-Cacheable
X-Secret
X-Webapp
Session-From
X-Magento-Action
X-SH-Cache-Status
X-SCM-Server-Number
MS-CV
Resin-Trace
X-Amz-Id-1
X-Varnish-Cache-Local
X-Amcomm-Site
X-7d-Trace-Id
X-Node-Name
X-HA-Backend
X-MidCOM-Meta-Cache
X-Refresh
X-Ezoic-Cdn
X-Forwarded-Host
X-7d-Instance-Id
Tempo
X-Pageid
ViewMode
X-Data-Request
X-HashTwo
Set-Cookie2
OriginServer
X-Environment-Context
X-AISO-Server
X-L-Path
X-CDN-COMPRESS
X-AISO-Cacheable
X-HA-Frontend
Il-Cl
Proxy-Cache
X-SilverStripe-Cache
AccessControlAllowOrigin
X-Cms-Mode
WP-AdvCache-MemCached
X-Dev
X-CDN-RULE
X-Sc-Cache
X-Hosting
X-Ghost-Cache-Status
X-AISO-Cache
X-HAProxy
Nginx-Cache
PagesDisplayed
StatusCode
Server-Ip
X-Header
SBMCLOUD
X-IP
X-CACHE-TTL
X-Redman-Backend
X-MCB-Server
X-Dynamic-Cache
X-Avg-Cookie-Expires
X-Hrouter
BackendServer
X-Hstore
X-DB-Content-Length
X-Redman-Final-Url
X-Akamai-Edgescape
X-AVG-Country-Code
X-EC-Security-Audit
X-Enhanced-By
Aurora-Node
X-RequesterIP
X-Server-Generated
Progma
X-Cache-Time
X-Nginx-Request-Processing-Time
Debug-Status
X-DSMX-Render-MS
X-V
NS-VaryByCustom-Key
COMMERCE-SERVER-SOFTWARE
X-Test
X-Search-Id
X-Cacheable-TTL
X-Flex-Lastmod
X-Flex-Tag
X-Flex-Tags
X-ACLR-Version
X-Apm-Telemetry-Syncmark
Access-Control-Allow-Method
FastCGI-Cache-Status
Traffic-Origin
X-Gyrobase-Publication
X-Compressed-By
X-B2f-Not-Route
X-CCM
X-DN-Cache-Control
X-Flex-Lang
X-Flex-Evstart
X-ManagedFusion-Rewriter-Version
X-Pubstack
X-Rewritten-By
X-Test-Debug
SHInfo
VAR-Cache
X-AMAZEEIO
X-AppVersion
X-DevSrv-CMS
X-WebKit-CSP-Report-Only
X-Who
X-DSMX-Rewrite-MS
X-Flex-Community
X-Flex-Evend
X-Wm-1
SiteSpeed
X-XHTML-Minification-Powered-By
Lb
RequestId
CDCHOST
X-Wm-VIP
X-NodeID
X-Proxy-Id
X-S-Misc
X-Server-FQDN
X-Session-Id
X-Unique-Id
X-AppServer-Cache-Rule
X-Country
X-D-Time
X-ELB
X-ServiceProvider
X-Time-Zone
X-Origin-Server
X-FPC
X-Bcwwwid
X-Built-With
Cache-Status
Accept-Language
X-Uncacheable
X-Varnish-Instance
X-VLoc
X-XHR-Current-Location
X-Amzn-Trace-Id
X-Amzn-RequestId
X-DEBUG
X-DeliveryServer
X-Dynamic
X-PHP-Response-Code
X-Cache-Extended
X-Brought-To-You-By
PServer
Ews
X-W3TC-Minify
X-Box
X-REDIRECTSERVER
X-HostName
SINA-LB
SINA-TS
UrlWatchModule-Time
Webserver
Rewriter
FindLaw
X-Sid
X-Upgrade-Enabled
Content-Cache
DbServerName
X-Cache-Varnish
X-Generation-Time
X-Gannett-Site-Version
X-M
X-Farm-Server
X-Catalyst
X-LOCATION
X-DS1D
Expiries
DrivedBy
X-Streams-Distribution
X-Pagely-Cache
X-Fstrz
X-Node-ID
X-Turpentine-Esi
X-Cache-HT
Swift-Performance
X-Pixelsilk-Server
Expect-Ct
X-Ocache
X-Nginx-Request-Time
X-LBPoolMember
X-Resource
Cleartype
X-ChromeLogger-Data
X-Cache-BE
X-Nocache
X-Tag-Playlist
X-RAMCache
X-Lima-Id
X-Reflector
SERVER-ID
X-Pixelsilk-Version
X-Reflector-Cache
X-Server-Instance-Name
X-WPL-DATA
M
X-Cms-Server
X-Layout
X-JSESSIONID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NewCloud-V-Cache
X-Cache-Bypass
X-PBS-Fwsrvname
X-CH-Device
X-9XB-Server
MageStack-Cache-Lifetime
MageStack-Cache-Hits
X-Config-Version
MageStack-Cache-Status
MageStack-Cacheable
MageStack-Cache
MageStack-Area
X-Served
X-Rocket-Nginx-Reason
AMP-Access-Control-Allow-Source-Origin
Server-Tuning
Brightspot-Id
No-Cache
MageStack-Config
PLCDN
Note
X-VC-Debug
X-App-Version
X-Backend-TTL
MageStack-Web-Node
Apple-Itunes-App
MageStack-Loadbalancer
MageStack-Debug
MageStack-Magento-Version
MageStack-PageSpeed
MageStack-Tag
X-Cache-Me-Harder
SB-Cache-Life
X-MainProfileCategory
X-MainProfileID
X-Pass-Through
X-UseReverse-Proxy
X-Ezpublish-Installationid
X-PROCESSED-BY
X-Tradeindia-SMgmt
X-RiS-PX
X-MainProfileName
X-Router
X-Router-Backend
X-Tradeindia-Request-GUID
X-CSRF-Token
X-HP-CAM-COLOR
X-Cache-FS-Status
X-CacheID
X-Agent
X-Ezpublish-Nodeid
TP-Cache
X-GoCache-CacheStatus
XDisk
X-Highwire-Smart-Code
X-Faeria
X-WebNode
X-Highwire-Sitecode
X-Webstats-RespID
X-MainProfileURL
X-ESI
X-FG-RequestId
SB-Cache-Remaining
SB-Site-Device
SB-Site-IE-VERSION
Session-Id
X-Aramark-SID
TP-L2-Cache
AMFplus-Ver
X-EBAY-C-REQUEST-ID
X-CM-FE
Provided-Host
RSL-Trace-ID
WFE
X-CACHE-KEY
X-Theme
Server-Id
WSCLoggingUUID
X-IP-Address
X-Provided-By
X-NewsFlow-Sitename
X-Not-Cacheable
X-Generated-Date
X-PBS-Appsvrname
X-Front-Cache
DB-Nickname
X-PBS-Appsvrip
X-Title
X-Amz-Meta-Content-Md5
X-Forwarded-By
X-WA-Info
X-AWS
X-Webkit-Csp
X-AG-MIPS
MwpReleaseVersion
X-Ss-Conf
Actual-Object-TTL
AGI-Request-ID
X-FIRSTBase
Cache-Tags
X-Phpwcms-Page-Processed-In
X-Phpwcms-Release
X-Real-IP
X-Svr
X-Origin-Cache
X-OCTOPOD
X-Backend-Name
X-Cjtype
X-NID
X-Meta-MSThemeCompatible
X-Meta-Imagetoolbar
X-SuperCache
X-UnsetCookies
D
Kanooh-Host
X-DDM-SERVER-UPDATED
X-DDM-SERVER
X-HASH
GP-Remote-Addr
GP-Version
Kp-EeAlive
X-Fpc
MSThemeCompatible
X-Backend-Host
Ibm-Web2-Location
MSSmartTagsPreventParsing
X-Varnish-Cached-TTL
X-MCF-ID
X-Ss-Location
X-Varnish-Cached
INFO
X-Meta-MSSmartTagsPreventParsing
X-UPSTREAM-Address
X-Cname-TryFiles
X-Deity
X-Cache-Id
X-Route
!~Request-OOB-Work
X-Header-Treatment
ENV
RSB-LINK
X-Custom-Header
X-Beatles
X-Debug-Message
X-Made-On
X-Varnish-URL
X-Webkit-CSP-Report-Only
X-C2M-Runtime
X-Ssl-Cipher
X-C2M-Server
X-Beresp-Ttl
X-COUNTRY-CODE
Aoestatic
EQ-Cache
Be
Contao-Page-Layout
Generate-Time
Microcache
X-Varnish-Debug-Hits
X-Support
X-HEAD
X-Prerendered
X-Cache-ID
X-Magento-Lifetime
Upgrade-Insecure-Requests
WP-Cache
HostName
CpuTime
Language
Accept-CH
TheAnswer
X-Ants-Host
X-Ants-Machine-Id
X-SVR
0
Copyright
X-Obvious-Info
X-Obvious-Tid
X-Csrf-Token
X-BC
X-BPool
IsMobile
X-SCProxy
V-Age
X-Imforza-Hosted
X-Protected-By
X-NMT-Proxy
X-BPool-Back
X-BPool-Bx-Cache
X-BPool-Fx-Cache
X-BServer
X-Cluster
X-Serverid
CD4
X-PG
X-Varnish-VCL
Countrycode
X-Tt-Dbg
X-Skip-Cache
E-TAG
Lookup-Cache-Hit
X-Client-Ip
X-Geo-IP
Head
Serverid
X-ZSITES-DNS
Fastly-Restarts
Service-Worker-Allowed
X-PHP-Backend
X-Upstream-Status
X-Serv
X-CO-Host
X-Nginx-Page-Cache
Page-Template
RlogId
X-Stiffia-Cache
X-SRV
X-Processed
Fw-Cache-Status
X-Build-Id
X-Cachable
X-VNode
X-Vary-Options
User-Cache-Control
X-ASAP-Age
X-DynamicCache
X-UT-Cache
X-FreeTag-Count
X-Obj-Ttl
Resource
Session
X-Instance-Id
X-Netrix-ID
ReqUrl
FrontEnd
X-Pool-Info
X-Serendipity-InterfaceLang
X-Serendipity-InterfaceLangSource
X-Transaction-Name
Tesla.Performance
Tk
ServerNode
OutputRewritten
X-Enabled2
X-W-Cache
WebServer
Www.Aujourdhui.Com
X-Count
X-Cache-Served
X-Enabled1
X-Ar-Debug
X-W-Cache-Hits
X-UUID
X-Built-By
VC-NoCache
X-Archive-Orig-Server
X-Archive-Orig-ETag
X-Content-Parsed-By
X-Enabled3
X-Server-App
X-Request-Received
X-Request-Processing-Time
Ez
X-Debug-Out
X-Debug-Serve
X-Varnish-Store
X-Varnish-Set-Cookie
X-Varnish-Max-Age
X-Varnish-Esi-Method
Content-Legth
Yola-ID
ResourceTag
Public-Extension
X-Beatles-Hits
X-ZORequestID
X-Varnish-Esi-Access
X-Varnish-Currency
X-FCMS-Cache
X-Czt
X-Max-Age
X-Hash
X-Does-He-Have-Time
X-Cache-Action
X-Turpentine-Cache
X-Cache-Set
X-HS-Status
X-BeResp-Ttl
X-Container
X-Archive-Orig-Date
X-ServerAddr
X-UPServer
B-Rlogid
AR-SID
X-Script
AR-PoweredBy
X-Auto-Login
X-Instance-Name
X-Diazo-Applied
X-EC-Custom-Error
Rlogid
GranicusServer
X-Amz-Meta-Version-Id
X-Cache-LB
X-CPU-Time
X-B3-Traceid
X-Op-Benvironment
X-Sn-Servicetimems
Httpd-Identifier
Hosted-By
ProxiaInstanceId
Content-Generator
AR-CACHE
X-Pj-Cache-Status
X-TTL-Age
X-Vol-Mrp
X-Vol-Correlation
X-Would-Your-GrandPa-Wait
EXT-CACHEEXPIRE
Memento-Datetime
X-Archive-Orig-Content-Length
X-Archive-Orig-Connection
X-Archive-Guessed-Charset
Server-Node
X-Accel-Cache-Control
Debug-Expires
X-Restarts
Url-Hash
X-Jcms-Ajax-Id
AR-ATIME
CD1
X-Your-GrandPa-Would-Wait
Debug-Cache-Control
Container
Prototype-RootPath
X-B3-Spanid