Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-XSS-Protection
X-Frame-Options
Strict-Transport-Security
CF-RAY
Age
Expect-CT
X-Cache
P3P
Content-Language
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
Referrer-Policy
X-Varnish
X-Request-Id
X-Adblock-Key
X-Check
X-Generator
X-FRAME-OPTIONS
X-Drupal-Cache
X-Language
X-Template
X-Buckets
X-Type
WPE-Backend
Alt-Svc
X-Cache-Group
X-Pass-Why
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-Cache-Hits
X-Ac
X-Hacker
X-AspNetMvc-Version
Host-Header
X-ShopId
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Shopify-Stage
X-Sorting-Hat-Section
X-Sorting-Hat-PodId
X-ShardId
X-Dc
X-Alternate-Cache-Key
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Served-By
X-Powered-By-Plesk
X-Runtime
X-Amz-Cf-Id
MS-Author-Via
X-Via
Access-Control-Allow-Headers
X-Powered-CMS
X-IPLB-Instance
X-Xss-Protection
Access-Control-Allow-Methods
Content-Location
X-Timer
X-Contextid
X-UA-Device
Cartoon
Status
CF-Cache-Status
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-ServedBy
X-PC-AppVer
X-PC-Hit
X-PC-Key
X-PC-Date
X-PC-Host
Access-Control-Allow-Credentials
X-Iinfo
P3p
X-Cache-Status
Powered-By
X-Backend
X-Wix-Request-Id
X-Seen-By
Content-Encoding
X-Rid
X-Mod-Pagespeed
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-WPE-Loopback-Upstream-Addr
X-CST
X-Cache-Enabled
X-Tumblr-Pixel-1
X-Endurance-Cache-Level
X-Logged-In
X-Cache-Hit
X-Server
X-Port
X-Drupal-Dynamic-Cache
X-Tumblr-Pixel-2
X-CDN
X-Server-Powered-By
Keep-Alive
X-DIS-Request-ID
X-Host
X-Ua-Compatible
X-Nginx-Cache-Status
X-Robots-Tag
X-Accel-Version
X-Turbo-Charged-By
X-LiteSpeed-Cache
X-Proxy-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Tumblr-Pixel-3
X-Page-Speed
Content-Security-Policy-Report-Only
X-Content-Digest
X-Request-ID
Allow
X-Content-Powered-By
X-AH-Environment
Request-Context
X-GitHub-Request-Id
X-Rack-Cache
X-FW-Hash
X-FW-Server
X-Varnish-Cache
X-FW-Serve
X-FW-Type
X-FW-Static
X-Pad
Access-Control-Expose-Headers
X-Request-Country
X-XRDS-Location
X-Node
Edge-Control
SPRequestGuid
X-Hits
X-SharePointHealthScore
X-MS-InvokeApp
X-Content-Security-Policy
X-Newrelic-App-Data
X-Trace
Cf-Railgun
MicrosoftSharePointTeamServices
X-BC-Stapler
X-Webcom-Cache-Status
X-Amz-Request-Id
X-Died
X-Amz-Id-2
Edge-Cache-Tag
WP-Super-Cache
X-HS-Cache-Config
X-CF-Powered-By
Timing-Allow-Origin
X-HS-Content-Id
Charset
X-PHP-Backend
X-Cache-Lookup
Request-Id
X-Tumblr-Pixel-4
X-Backend-Server
X-HOST
Access-Control-Max-Age
X-FullPageCaching
X-INKT-URI
X-INKT-SITE
X-Fastly-Request-ID
SPIisLatency
SPRequestDuration
X-Cnection
X-HS-Combine-CSS
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
Composed-By
X-SS-Location
X-SS-Conf
X-Edge-Cache
X-CDN-Pop
X-Edge-Cache-Key
X-CDN-Pop-IP
MicrosoftOfficeWebServer
EagleId
Grace
X-Device
X-Spip-Cache
Served-By
X-Servedby
X-Safe-Firewall
X-Hyper-Cache
X-NF-Request-ID
X-Dw-Request-Base-Id
X-DDC-Arch-Trace
Liferay-Portal
X-Server-Name
Front-End-Https
Rating
X-Cloud-Trace-Context
X-VCache
Feature-Policy
Surrogate-Control
X-LiteSpeed-Cache-Control
X-RateLimit-Reset
X-Firenze-Processing-Times
X-OneAgent-JS-Injection
X-DNS-Prefetch-Control
X-Jimdo-Wid
X-Vtex-Processado-Em
X-Original-Date
X-RateLimit-Remaining
X-RateLimit-Limit
X-Jimdo-Instance
X-TNCMS
X-Loop
X-Middleton-Display
Display
X-FB-Debug
X-Sol
X-Kinsta-Cache
Content-Style-Type
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-HeyJason
X-Clacks-Overhead
X-SERVER
X-Cluster-Node
X-Tumblr-Pixel-5
X-Pc-Appver
Content-Script-Type
X-Pc-Key
X-Tumblr-Content-Rating
X-Pc-Hit
Public-Key-Pins
P-LB
P-WS
X-Middleton-Response
X-Debug-Info
Response
X-WebKit-CSP
X-Pc-Host
X-Pc-Date
Xkey
X-StackifyID
X-Acc-Exp
X-Frame-Option
X-Magento-Tags
X-ServerName
X-Ruxit-JS-Agent
X-Age
X-Amz-Version-Id
Fpc-Cache-Id
X-Edge-Location
Refresh
X-Goog-Hash
X-Px
X-XN-Trace-Token
X-DynaTrace-JS-Agent
X-XN-XNHTML
X-N-OperationId
X-User-Agent
X-Hostname
X-ARC
X-Url
X-Cached
X-Zen-Fury
X-Cache-Config
X-Generated-By
X-LW-Cache
WPX
X-Handled-By
Retry-After
PageSpeed
X-B-Cache
X-MiniProfiler-Ids
X-Loopia-Node
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Topify-Platform
Powered
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Rt-Fastcgi-Cache
X-Webserver
X-Source
TCN
X-Outils-CS
X-Cdn
X-Tumblr-Pixel-6
X-CMS-Version
X-FORWARDED-FOR
Pagespeed
No
X-CacheServer
X-Powered-By-VTEX-Janus-ApiCache
Access-Control-Request-Method
X-Vtex-Processed-At
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Remote-Cache
X-VTEX-Janus-Router-Backend-App
X-Cached-By
X-Request-Time
X-Platform-Server
X-Magento-Cache-Debug
Fastcgi-Cache
ServedBy
X-ET-API-ROOT
Imagetoolbar
Fhost
X-Signature
X-ET-API-VERSION
X-ET-API-ORIGIN
X-Location-Id
X-Version
X-Application-Context
X-From
X-Response-Time
X-Accel-Expires
X-Platform-Processor
Cache-Provider
X-Platform-Cluster
X-Upstream
X-Platform-Router
X-LBLID
X-PhApp
X-Cache-Key
X-EdgeConnect-Origin-MEX-Latency
X-SRCache-Fetch-Status
X-Engine
X-URLSCHEME
X-SRCache-Store-Status
X-Actual-URL
Dmn
Host
X-Fastcgi-Cache
X-F-Cache
X-URL
X-DynaTrace
Alternate-Protocol
X-Dns-Prefetch-Control
X-Returned-From-BeforeDispatch
X-AspNetWebPages-Version
X-Returned-From
X-Returned-From-DLL
Public-Key-Pins-Report-Only
X-Varnish-Beresp-Ttl
X-Passed-To-DLL
X-Varnish-Beresp-Status
X-Passed-To-PostProcessResponse
X-Cache-Age
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-RESOURCE
X-Varnish-Beresp-Grace
X-Original-Request
X-EdgeConnect-MidMile-RTT
X-Passed-To
Warning
X-Stale
X-Developer
X-Forwarded-For
X-Content-Options
X-Msg-2-Log
X-Cache-Info
X-Acquia-Application-UUID
Arr-Disable-Session-Affinity
X-Acquia-Application-Trace
X-Umbraco-Version
X-Ezoic-Cdn
X-Defender
X-Shop-Id
Cache-Key
Last-Published
Product
X-Dispatcher
X-Microcachable
X-Varnish-Cache-Hits
X-Platform
Generator
X-GUploader-UploadID
X-Dealeron-Original-Url
X-Varnish-HitMiss
X-Cache-Rule
X-Whom
X-Varnish-Count
X-NWS-LOG-UUID
X-DealerOn
X-Dealeron-Backend
X-Server-ID
X-Correlation-ID
X-Hosted-By
X-Platform-Cache
X-Device-Type
X-Cache-Namespace
X-S
X-HS-Content-Campaign-Id
X-Cache-TTL
Origin
X-Varnish-Host
X-Lambda-Id
X-Cache-Tags
X-Magento-Cache-Control
X-Art-Request-Id
X-Micro-Cache
Content-Hash
X-Varnish-TTL
X-PERF
X-BS
X-SO
X-Rnd
X-ApacheServer
X-I-Sp
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
Akamai-IP
DynaTrace
Surrogate-Key
X-Duration
X-Sapient
X-Microcache-Status
X-Translation
X-Gateway-Cache-Key
X-Akam-SW-Version
X-Powered-By-360WZB
Powered-By-ChinaCache
X-Track
X-Environment
X-Vcap-Request-Id
X-Supported-By
X-Director
X-Cache-Debug
Version
SSPAppContext
X-Via-JSL
Server-Timing
X-Nginx-Cache
RTSS
WZWS-RAY
X-VARITI-CCR
X-NetCat-Version
X-Cache-Lifetime
X-Abgroup
X-Route-Server
X-Gamma-Serve
X-Powered-By-VelaWeb
X-Client-IP
Content-Disposition
S-Cnection
X-Varnish-RemainingTTL
X-TransIP-Balancer
X-TransIP-Backend
X-Instart-Request-ID
X-Hypernode
X-Varnish-ObjectSource
X-Varnish-Seen-By
X-Varnish-GracePeriod
X-Varnish-RemainingLife
X-Page-Cache
X-I
X-Guploader-Uploadid
X-App-Status
X-Expires-Orig
X-Esi
MIME-Version
X-Powered-By-VTEX-Janus-Edge
USPLoggingUUID
X-Sucuri-ID
X-Debug
X-Amz-Meta-S3cmd-Attrs
X-Drupal-Cache-Tags
CF-Worker-Version
X-Server-Upstream
X-Revision
X-App-Hosting
X-Rocket-Nginx-Serving-Static
X-Front
X-Cache-Type
X-SSL-Protocol
X-CSRF-Protection
X-SSL-Cipher
X-Sucuri-Cache
X-Cache-2
X-Geo-Country
X-Matrix-Proxy
X-Helper-Autoassign-All
X-Matrix-Server
X-Edge-IP
X-Flow-Powered
SN
X-Cache-Control-Orig
X-Drupal-Cache-Contexts
Contao-Page-Layout
Cneonction
X-ORACLE-DMS-ECID
X-Cache-IO
Srv
X-Rocket-Nginx-Bypass
X-Dispatch
Strikingly-Cache-Region
Nodo
X-IsCacheURL
X-Firenze-Processing-Time
Service-Worker-Allowed
X-Recruiting
Pool
X-Vhost
Wsr-Cache
Cache-Tags
X-Cache-Server
X-V
Strikingly-Cached
X-Cache-Engine
X-ATG-Version
Strikingly-Cached-Version
X-Storage
X-SV-Nginx-Duration
Content-Encoding-Handler
Lsrequestid
Node
X-Varnish-Age
X-SV-CreatedAt
X-Ttl
X-Url-Base
X-SV-Edge
X-SV-Duration
X-SV-FromDBCache
X-SV-Pid
X-Hostinger-Node
ServerName
X-LB
X-Hostinger-Datacenter
X-Content-Type-Option
X-Cache-Only-Varnish
X-Daa-Tunnel
X-Cache-Operation
X-Correlation-Id
FAI-W-FLOW
If-Modified-Since
X-HW
X-ORACLE-DMS-RID
NnCoection
X-Cache-PageType
X-FTR-Request-ID
X-Nf-Srv-Version
Section-Io-Id
X-Varnish-Cacheable
X-Generated
X-Now-Id
X-Cache-Fix
Server-Name
Edge-Control-Message
Https
Lb
X-Cache-Device-Type
Page-Completion-Status
X-Orig-Vary
X-TTL
X-NoCache
X-SDS
X-ID
X-Last-Modified
Author
X-Cache-Level
Src-Update
X-Server-Id
X-TransIP-Reserved
X-Pressidium-NinukisWP-Ver
X-N
X-Grace
Update-Time
Proxy-Connection
X-SV-CacheTags
Location
X-SV-Expires
X-Forwarded-Proto
X-SV-Cacheable
X-SRV
X-Env
X-Cache-Expires
Backend
X-SRCache-Key
X-Country-Code
S
X-Rq
PICS-Label
X-Discourse-Route
X-Varnish-IP
Accept-Encoding
AMF-Ver
X-Time
X-Nginx-Dummy
X-Real-Server
X-GeoIP-Country-Code
Smug-CDN
X-SmugMug-Hiring
X-SmugMug-Values
X-TTFB
Dtk-Cache-Check-0
X-Speed-Cache-Key
X-Trace-Id
X-Middleware-Start
X-TTFB-L
X-Speed-Cache
X-Locale
X-Varnish-Url
X-CJ-Soft
Frame-Options
X-Ratelimit-Limit
X-Id
X-Ratelimit-Remaining
X-FW
Content-MD5
MJ12bot
SEOMOZ
X-Content-Security-Policy-Report-Only
X-SSLProxy
X-Cache-Control
X-SSLUpstream
Accept-Charset
X-LB-Server
X-Config-Blacklist-Version
X-Transaction
X-Empowered-By
X-Frontend
AC-ELC
X-Amz-Rid
W
Cache
X-Dynamic-Cache
X-Twitter-Response-Tags
HCVer
X-PwB-Node
X-Connection-Hash
Content-Transfer-Encoding
Pv
HAVer
Qs-Cache
NetMindSessionID
X-WPL-DATA
X-Akamai-Device-Model
X-Akamai-Device-Characteristics
Local-Info
X-Service-Id
Content_type
Edit
Server-Info
Pf.Web.Request.Id
X-Disney-Akamai-Rule
X-ACMCache
Ohc-File-Size
X-Content-Age
X-CACHE-TTL
X-Cache-TTL-Remaining
X-BKSrc
X-CacheFROM
Backend-Timing
X-Stage
X-UPSTREAM
Req-Id
X-FIRSTBase
X-RequestId
ServerID
X-Processing-Time
X-Cookie-Domain
X-High-Performance
X-GeoIP-Country-Name
X-Varnish-Retries
X-CF-Passed-Proto
X-PF-Uncompressing
Accept-CH
X-Pagename
X-Adobe-Content
X-CB-Server
X-Adobe-Loc
X-Hiawatha-Cache
X-Hit-Cache
X-TB-M
X-JG-Page-Cache
X-Balanceador
Ufe-Result
Pics-Label
X-Symfony-Cache
X-Session-ID
X-ARRServer
X-Analytics
X-Origin-Date
X-Litespeed-Cache-Control
X-Proxy
X-Akamai-ERRuleID
Identity
X-Akamai-ERPolicy
X-WR-Flags
IM-Version
CDN-Cache
Front
X-NginX-Cache
EagleEye-TraceId
X-Framework
Cached
X-Amz-Storage-Class
Use-Proxy
Tracecode
X-Debug-Token
X-Now-Cache
X-Content-Encoded-By
X-Yottaa-Metrics
X-Webstats-RespID
X-Varnish-Backend
X-GoCache-CacheStatus
X-LP
X-Sys-Req-ID
X-LW-Web-Server
X-Magnolia-Registration
X-Avg-Cookie-Expires
Adm-Server
X-SERVER-NAME
Access-Control-Allow-Method
X-Backend-Status
X-Redman-Backend
X-Yottaa-Optimizations
X-Runtime-Memory
Web-App-Origin-Name
Url
SHInfo
Accept-Language
X-Worker
X-Remote-Addr
X-Srv
X-Redman-Final-Url
X-Akamai-Edgescape
X-AVG-Country-Code
X-BackendServer
X-Drectory-Script
MC
X-Nbs
Upgrade-Insecure-Requests
X-Atraveo-From-Varnish-Cache
X-Atraveo-Varnish-Server-Id
X-Atraveo-Param-Rm
X-Atraveo-Expires
X-Atraveo-Zone
X-HydroSheep
X-Atraveo-Cache-Control
X-Varnish-Debug-TTL
X-Varnish-Debug-Age
X-Atraveo-Set-Cookie
X-Atraveo-ETag
X-Atraveo-TTL
VServer
CDN-PullZone
CDN-CachedAt
,
X-Sedo-Request-Id
CDN-RequestId
WWW-Authenticate
Max-Age
From-Origin
CDN-Uid
X-Origin
X-Distributor
RequestId
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-ServerID
X-Streams-Distribution
X-Cache-Miss-From
Drupal-Pagecache-Memcache
CacheControlHeader
X-Browser
X-Forwarded-Host
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
X-FireWall-Port
X-Hstore
Eomportal-Instance
IBM-Web2-Location
X-PRAM
X-Request-Uri
X-HTML-Minification-Powered-By
X-Hrouter
X-FastCGI-Cache
Xc-Version
X-RealServer
X-CAPServer
X-Amz-Apigw-Id
X-Varnish-Hostname
X-SE-Debug
X-Amzn-Trace-Id
X-Amzn-RequestId
X-Force
X-Source-ID
X-Origin-Name
X-Unbounce-VisitorID
X-Resource
X-Unbounce-Variant
X-Unbounce-PageId
X-Cf-Powered-By
X-SVR-IIS
X-Server-Instance
X-A
Surrogate-Key-Raw
Nopic
X-Envoy-Upstream-Service-Time
X-Svr-Proxy
Noq
X-Culture
X-CacheDebug
Ramp
Ram
X-Cache-Handler
X-Proxy-Backend
Custom-Header
X-FORWARDED-PROTO
X-Consent-Required
X-Pantheon-Phpreq
X-AEM
SRV
X-Unique-ID
X-Pantheon-Environment
X-HeBS-Cache-Status
X-Pantheon-Az
X-Pantheon-Site
Copyright
RN-Server
X-Key
X-Middleton-Pagespeed
X-Span
X-Cache-Varnish
X-MCB-Server
XDomainRequestAllowed
X-SP-UniqueName
X-Yadis-Location
Dispatcher
X-Webkit-CSP
X-AOL-HN
AsisCache
X-UD-METHOD
SiteSpeed
X-Processed-By
X-Detected-Device
X-App-Server
Nitro-Cache
X-Plat
Request-Country
Request-EU
X-Unique-Id
X-Garden-Version
Report-To
AMP-Access-Control-Allow-Source-Origin
X-WP
X-Smartcache-Timeout
Serverid
DNNOutputCache
X-Smartcache-Keys
X-Role
X-CDN-Forward
X-Server-Addr
X-Directory-Script
X-Scheme
Swift-Performance
X-Distil-CS
X-GeoIP
Machine
X-SP-Farm
Srv-Name
X-Storage-Cache-Expires
X-RiS-UFDI
ClientIP
F5-IpCliente
Cm-Server
Nginx-Cache
Gzip
X-Amz-Id-1
X-Instance-Id
X-Proxy-Cache-Control
X-DataDome
VSID
X-Ms-Request-Id
ViewMode
SWS-Security
X-NginX-Upstream
X-Cache-Var
X-Cache-Var-Map
SVR
X-Storage-Cache-Date
AETN-Latitude
AETN-EU
X-Runtime-Affili
X-Server-IP
AETN-Longitude
*
AETN-Postal-Code
AETN-DEVICE
AETN-Country-Name
X-SSLTerm-Server
X-Varnish-Grace
AETN-Area-Code
AETN-City
AETN-Country-Code
AETN-Continent-Code
X-Page
AETN-State-Code
X-WebKit-CSP-Report-Only
X-Hit
Access-Control-Request-Headers
X-Storage-Cache
X-Soro
X-Dw-Trace-Id
X-GSL-Server
X-E
X-LB-Node
AKA-DEVICE
X-Instance
X-Cacheable-TTL
X-Depends
X-Generated-Time
X-Cache-Me-Harder
X-7d-Instance-Id
X-Nx
Fastly-Restarts
Fastly-Backend-Name
X-Client-Image-Vid
X-Client-Vid
X-Protected-By
X-Fstrz
X-EPiphany-Vid
X-Varnish-Ttl
X-NginX-Server
X-UA-Bot
X-SmartBan-URL
X-SmartBan-Host
X-Varnish-Action
XX
Prama
Ohc-Response-Time
Filters
X-IP
X-FPC
X-VCS-Cacheable
X-ACCELERATE
X-4ormat-Cacheable
A-Powered-By
X-AF-Userserver
X-Via-S
X-Resolver-IP
X-Client-Id
Resin-Trace
Locale
X-Actindo-Rs
X-SAPP
X-Actindo-Thread-Id
X-Actindo-Request-Id
IISExport
Environment
X-VCS-Ttl
X-Response
X-PHP-Response-Code
Server-ID
Disablevcache
X-Proxy-Skip
X-Adnet
X-7d-Trace-Id
X-Rebelmouse-Cache-Control
X-MSU-SOURCE
X-Clx-Request
X-Desc
X-Akamai-Transformed
X-Amzn-Remapped-Content-Length
Paypal-Debug-Id
Aurora-Node
AMP-Redirect-To
FRONT-END-SECUREBROWSER
HitType
HitInfo
Access-Control-Allow-Header
AR-ATIME
X-Cocoon-Version
X-Cache-On
X-Autoru-Host
X-CRA-DC
X-GeoIP-Country
X-IIJ-Cache
X-Highwire-SessionId
X-Highwire-RequestId
X-Autoru-App-Id
X-Nx-All
AR-SID
AR-PoweredBy
AR-CACHE
VANITY-HOST
From
N365rili
MW-Webserver
Edgecast
X-App-Runtime
X-Cache-Time
X-Access-Control-Allow-Origin
X-Amcomm-Site
X-ClientSide-Caching
Proxy-Agent
X-Flex-Evend
X-Flex-Community
X-ASAP-Age
X-ASAP-Cache
Traffic-Origin
Num
X-DynamicCache
X-Data-Request
X-Cache-Date
X-Clara-ASAP
X-Flex-Evstart
X-Flex-Lang
X-HA-Backend
X-Rack-CORS
X-Goog-Meta-Replace
X-Purge-URL
X-Purge-Host
X-HA-Frontend
X-Nginx-Host
X-Goog-Meta-Policy
X-Varnish-Backend-Beresp-Backend
COMMERCE-SERVER-SOFTWARE
X-Flex-Lastmod
X-Flex-Tag
X-Flex-Tags
X-Varnish-Hits
Dis-Env
X-HashTwo
X-Cache-CFC
X-Location
X-UnsetCookies
Section-Io-Origin-Time-Seconds
X-Amz-Meta-S3b-Last-Modified
X-Map-Context
X-TKP-SRV-ID
X-Microcache
X-NWS-UUID-VERIFY
X-Req-Head-Response
X-Oracle-Dms-Ecid
X-Shield-Request-Id
ScoreTracker
X-Info
X-Webcelerate
Section-Io-Origin-Status
X-Serverid
X-Dynatrace-Js-Agent
Cleartype
X-LBPoolMember
X-ReqId
X-Mobilized-By
Provider
X-PROCESSED-BY
X-Proto
X-Oracle-DMS-ECID
X-Rack-Cors
X-Appversion
X-SDE-Name
TYPO3-Pid
PagesDisplayed
X-Cache-Detail
X-VTEX-Cache-Status-Janus-Edge
X-Reflector
X-Reflector-Cache
Cf-Ipcountry
X-OpenCart-Lightning
X-UUID
X-HostName
Cmstype
Cteonnt-Length
Cmsid
X-ServerIndex
X-RENDER-TIME
Server-Ip
X-WEBMGR-CACHE
TYPO3-Sitename
X-Hosting-Env
X-Cache-Ttl
X-Cdn-Forward
X-Via-NSCOPI
EQ-Cache
Content-Generator
Keywords
Ews
X-Instance-Name
Fastly-Debug-Digest
X-Nginx-Page-Cache
X-Route
X-TNCMS-Bot-Tier
Play-Detected-UserAgent
X-HTTPS-Protocol
IES-Server
GD-Server
X-HTTPS-Cipher
X-Ghost-Cache-Status
Httpd-Identifier
X-MCF-ID
X-Jcms-Ajax-Id
X-Fpc
X-EC2-Instance-Id
NS-VaryByCustom-Key
ModuleCacheType
X-Refresh
Load-Balancer
X-Nitro-Cache
X-DevSrv-CMS
X-Cms
X-Batcache
Og
X-B3-Sampled
Request-Time
X-Batcache-Reason
X-Bcwwwid
X-Cdn-Origin
X-Captured
X-Built-With
X-Sn-Servicetimems
X-VC-Cache
ServerSignature
NtCoent-Length
Id
Play-Detected-Device
ServerTokens
StatusCode
X-Cache-TTL-Age
X-Amz-Meta-Content-Md5
Verto-Server
Home
Hosted-By
X-Varnish-Cached-TTL
X-Varnish-Cached
X-UPServer
Il-Cl
Arrnode
ID
DrivedBy
Debug-Status
X-Cache-TTL-Current
X-Machine
X-Ms-Version
X-Highwire-Smart-Code
X-Highwire-Sitecode
X-Built-By
X-Origin-Server
X-PBY
X-Ssl-Cipher
X-SCM-Server-Number
X-Proxy-Cache-Key
X-Beluga-Trace
X-Beluga-Status
X-Archive-Orig-Server
X-Archive-Orig-Last-Modified
X-Archive-Orig-Date
X-Beluga-Cache-Status
X-Beluga-Node
X-Beluga-Response-Time-X
X-Beluga-Response-Time
X-Beluga-Record
X-VC-Enabled
X-VC-TTL
NEL
Beyond-Iis
X-Varnish-Cache-Ttl
X-PM-ID
X-PressLabs-Stats
X-Src-Webcache
X-Search-Id
X-Rule
X-Upstream-Status
X-Upstream-Backend
X-Airee-Node
X-Who
X-VHOST
X-Gannett-Site-Version
X-Layout
X-Title
X-Secret
X-Ruxit-Js-Agent
X-Archive-Orig-Content-Type
X-Archive-Orig-Connection
X-Cache-Via
X-Cache-Doesi
SB-Site-IE-VERSION
SB-Site-Device
X-Debounce
X-LAKANA-AB
X-NodeID
X-Nginx-Request-Processing-Time
Proxy-Cache
SB-Cache-Remaining
SB-Cache-Life
MachineName
CD5
Actual-Object-TTL
NZSpeedy
Origin-Cache-Control
Returned-Status
Page-Template
Origin-Edge-Control
X-Page-Cacheable
X-ProcessESI
Disp
DeleGate-Ver
Bios
Magicmarker
Memento-Datetime
X-Archive-Guessed-Charset
X-AMAZEEIO
NLCacheNote
X-Zendesk-User-Id
X-Zendesk-Origin-Server
X-Serv
X-RemovedCookies
X-Redir-Url
X-Server-Generated
X-Status
X-User-Agent-Tier
X-Timestamp
X-Svr
Yoncu-Errno
X-M-Reqid
VC-NoCache
MS-CV
Session-Id
ProxiaInstanceId
X-Avvio-Cms-Cacheload
X-Blog
MageStack-PageSpeed
MageStack-Tag
X-Cache-FS-Status
MageStack-Web-Node
Pramga
NODE
WN
Worker
X-Activity-Id
X-Amz-Meta-Version-Id
Viewport
Tesla.Performance
NB-Cache
Hummingbird-Cache
Tempo
X-CacheID
X-Catalyst
MageStack-Cache-Hits
X-Provisioner-Version
X-PBS-Fwsrvname
X-PBS-Appsvrname
MageStack-Cache
MageStack-Area
X-UPSTREAM-Address
X-Static
HTTPS
X-PBS-Appsvrip
MageStack-Cache-Lifetime
MageStack-Loadbalancer
X-Domain-Checked
X-Dispatcher-Number
MageStack-Magento-Version
MageStack-Debug
MageStack-Config
MageStack-Cache-Status
X-MyName
MageStack-Cacheable
X-App
X-XHR-Current-Location
X-Processed
X-SH-Cache-Status
X-Resty-Request-Id
X-Middleton-PageSpeed
X-Test
X-Time-Spent
X-Jphone-Copyright
X-JSESSIONID
X-Oferteo-Domain
X-Pj-Cache-Status
X-Served
X-Itkg-Cache-Tags
X-UA
X-UT-Cache
X-V-Cache
Device
X-Cache-Node
X-CH-Device
X-Geoip-Country-Name
X-This-Proto
X-Confluence-Request-Time
X-Hosting
X-HA
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-Cache-LB
X-Cms-Mode
X-Cname-TryFiles
X-Az
X-RAMCache
X-Ser
X-RiS-PX
X-Req-Counter
X-Debug-Message
X-CACHE-KEY
Amfplus-Ver
X-FastCGI-Cache-Status
X-Fedora-School-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
CommunityServer
X-Dev
X-Deity
Provided-Host
Origin-Vm
X-WebNode
Cache-Cookie-Set-From
X-Bip
X-DB-Content-Length
X-DN-Cache-Control
X-AppServer-Status
X-CSRF-Token
X-Cache-ID
X-B2f-Not-Route
X-Beatles
X-DDM-SERVER-UPDATED
X-DDM-SERVER
X-AppServer-Cache-Rule
X-AppServer-Cache-Exception
SBSS
Requested-Host
Nd
X-DSMX-Rewrite-MS
SS
Thanks
Webserver
UrlWatchModule-Time
X-DSMX-Render-MS
X-Artvisual-Server
X-Aramark-SID
Server-Id
X-Time-Microsecs
X-SuperCache
Ttl
X-VG-WebCache
Xc
DB-Nickname
Content-Sn
Backend-Powered-By
X-SID
X-Session-Reinit
X-Policy
X-Aramark-CSID
X-WN-ClientGroup
X-M-Log
X-Proxy-Id
X-Qnm-Cache
X-Rocket-Nginx-Reason
X-Rocket-Nginx-File
X-Application
X-ESI
X-ETag
TP-Cache
SERVER-NAME
X-RunCloud-Cache
X-Tag-Playlist
TP-L2-Cache
WP-AdvCache-MemCached
X-Geo-IP
X-Compressed-By
X-Cluster
X-Agent
X-TLS-Version
X-UD-Method
X-Xml-Http-Blocked
Generate-Time
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Web-Server
X-We-Are-Hiring
X-VC-Cacheable
X-Container
X-Varnish-Cache-Local
X-Nginx
X-MAT-GEO
X-SilverStripe-Cache
X-Sid
X-Lb
X-Geo
Cache-Ctrol
Content
Firespring-Website-Id
FindLaw
X-Expires
X-ENV
X-Compress-Hint
D
X-Upgrade-Enabled
X-Skip-Cache
X-HEAD
X-Gyrobase-Publication
X-Box
X-Frames-Options
X-Cache-Extended
X-Cache-Action
Description