Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Set-Cookie
Server
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
P3P
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
X-Xss-Protection
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Adblock-Key
X-Varnish
Referrer-Policy
X-Request-Id
X-Check
X-Generator
X-Language
X-Template
X-Buckets
X-Type
X-Cache-Group
X-Pass-Why
X-Drupal-Cache
WPE-Backend
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Alt-Svc
X-Ac
X-Hacker
X-Cache-Hits
Host-Header
X-Sorting-Hat-Section
X-Dc
X-Alternate-Cache-Key
X-AspNetMvc-Version
X-ShopId
X-ShardId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-ShopId
X-Sorting-Hat-FeatureSet
P3p
X-Via
X-Runtime
X-Powered-By-Plesk
X-Served-By
X-Contextid
X-PC-Key
X-PC-Hit
X-ServedBy
X-Amz-Cf-Id
X-UA-Device
X-PC-AppVer
MS-Author-Via
Content-Location
X-PC-Host
X-PC-Date
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-IPLB-Instance
X-Timer
X-Wix-Request-Id
X-Seen-By
Status
X-Rid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
CF-Cache-Status
Cartoon
X-Tumblr-Pixel-1
X-Iinfo
Access-Control-Allow-Credentials
X-Tumblr-Pixel-2
X-Backend
X-WPE-Loopback-Upstream-Addr
X-Host
X-Cache-Status
X-CST
X-Ua-Compatible
Content-Encoding
Powered-By
X-NewRelic-App-Data
X-Endurance-Cache-Level
X-Mod-Pagespeed
X-FRAME-OPTIONS
X-Cache-Hit
X-Cache-Enabled
X-Port
X-CDN
X-Tumblr-Pixel-3
X-Newrelic-App-Data
X-Logged-In
Keep-Alive
X-Server-Powered-By
X-DIS-Request-ID
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server
X-Robots-Tag
X-Request-ID
X-Accel-Version
X-Proxy-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Turbo-Charged-By
X-Page-Speed
X-Content-Powered-By
X-GitHub-Request-Id
X-Content-Digest
Content-Security-Policy-Report-Only
X-LiteSpeed-Cache
X-Rack-Cache
X-Tumblr-Pixel-4
X-AH-Environment
X-FW-Hash
X-FW-Server
X-Pad
X-FW-Serve
X-FW-Type
X-FW-Static
Request-Context
X-ASPNET-VERSION
X-Varnish-Cache
Edge-Control
X-XRDS-Location
X-Hits
X-Webcom-Cache-Status
X-Request-Country
X-Trace
SPRequestGuid
X-BC-Stapler
X-Node
X-SharePointHealthScore
X-MS-InvokeApp
Access-Control-Expose-Headers
Edge-Cache-Tag
WP-Super-Cache
X-HS-Cache-Config
MicrosoftSharePointTeamServices
Cf-Railgun
X-HS-Content-Id
X-HS-Combine-CSS
X-Amz-Request-Id
X-Amz-Id-2
X-CF-Powered-By
Timing-Allow-Origin
Charset
X-SERVER
X-FullPageCaching
X-Died
X-Content-Security-Policy
X-Webserver
X-Cache-Lookup
Server-Timing
X-INKT-URI
X-INKT-SITE
X-PHP-Backend
X-Fastly-Request-ID
X-Cnection
X-PhApp
Request-Id
Access-Control-Max-Age
X-Backend-Server
SPIisLatency
SPRequestDuration
X-Edge-Cache-Key
X-Edge-Cache
MicrosoftOfficeWebServer
EagleId
CONTENT-SECURITY-POLICY
Composed-By
X-Swift-SaveTime
X-Swift-CacheTime
X-SS-Conf
X-CDN-Pop
X-CDN-Pop-IP
X-SS-Location
Grace
Rating
X-Tumblr-Pixel-5
X-Safe-Firewall
X-Server-Name
X-Spip-Cache
X-DDC-Arch-Trace
X-NF-Request-ID
X-Device
Served-By
X-Tumblr-Content-Rating
Liferay-Portal
X-Dw-Request-Base-Id
X-Hyper-Cache
X-VCache
Front-End-Https
X-Cloud-Trace-Context
X-HeyJason
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
Surrogate-Control
Ali-Swift-Global-Savetime
X-Microcache
P-LB
P-WS
X-Cluster-Node
X-Loop
X-TNCMS
X-Original-Date
X-Firenze-Processing-Times
X-LiteSpeed-Cache-Control
X-Servedby
X-Wix-Punisher
X-StackifyID
X-Clacks-Overhead
X-Acc-Exp
X-Middleton-Display
X-OneAgent-JS-Injection
Display
X-Sol
Response
X-Middleton-Response
X-FB-Debug
X-RateLimit-Remaining
X-RateLimit-Limit
X-Kinsta-Cache
Content-Style-Type
Public-Key-Pins
X-Jimdo-Wid
X-RateLimit-Reset
X-Jimdo-Instance
Content-Script-Type
X-Debug-Info
X-Age
X-Shopid
X-Sorting-Hat-Featureset
X-Sorting-Hat-Podid-Cached
X-Shardid
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Shopid-Cached
X-Amz-Version-Id
X-Magento-Tags
Refresh
X-DNS-Prefetch-Control
X-XN-XNHTML
X-XN-Trace-Token
X-HOST
X-Tumblr-Pixel-6
X-Vtex-Processado-Em
PageSpeed
Fpc-Cache-Id
X-Goog-Hash
X-DynaTrace-JS-Agent
X-Hostname
X-N-OperationId
X-Px
X-Zen-Fury
X-Cached
X-User-Agent
X-Ruxit-JS-Agent
X-WebKit-CSP
Xkey
X-Url
X-Cache-Config
X-LW-Cache
Retry-After
Wpe-Backend
Feature-Policy
X-Version
X-Generated-By
X-Topify-Platform
X-Upstream
X-Frame-Option
X-Handled-By
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
Access-Control-Request-Method
X-Edge-Location
TCN
Rt-Fastcgi-Cache
X-MiniProfiler-Ids
X-Whom
Allow
X-FORWARDED-FOR
X-Source
X-Loopia-Node
X-CMS-Version
X-Request-Time
X-B-Cache
X-Cached-By
X-ET-API-ORIGIN
Product
X-ET-API-ROOT
X-ET-API-VERSION
X-Content-Options
Fastcgi-Cache
X-EdgeConnect-Origin-MEX-Latency
X-SRCache-Store-Status
ServedBy
X-URLSCHEME
X-SRCache-Fetch-Status
X-RESOURCE
Warning
X-Fastcgi-Cache
X-Outils-CS
X-Guploader-Uploadid
Last-Published
X-Platform-Processor
X-EdgeConnect-MidMile-RTT
X-Platform-Cluster
X-Platform-Router
X-AspNetWebPages-Version
Fhost
X-Magento-Cache-Debug
X-Tec-Api-Origin
X-Accel-Expires
X-Tec-Api-Version
X-Tec-Api-Root
X-From
X-Engine
X-Cache-Key
X-Cache-Info
Generator
X-Varnish-Host
X-DynaTrace
Powered
X-Signature
Public-Key-Pins-Report-Only
X-Application-Context
X-Dns-Prefetch-Control
X-Location-Id
X-Varnish-Count
X-Platform-Server
X-Varnish-HitMiss
X-Developer
X-LBLID
X-Micro-Cache
X-URL
Dmn
X-NWS-LOG-UUID
X-Varnish-Cache-Hits
X-Passed-To
X-Returned-From
X-Returned-From-DLL
X-Original-Request
X-Passed-To-DLL
X-Umbraco-Version
X-Response-Time
X-Varnish-Beresp-Status
X-Actual-URL
Cache-Key
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-F-Cache
X-PERF
X-Device-Type
X-Stale
X-ApacheServer
X-UD-Method
X-Powered-By-VTEX-Janus-ApiCache
X-CacheServer
No
X-VTEX-Cache-Status-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-S
X-Vtex-Remote-Cache
X-Vtex-Processed-At
X-HS-Content-Campaign-Id
X-Defender
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
Imagetoolbar
X-Returned-From-BeforeDispatch
X-Shop-Id
Surrogate-Key
X-Microcachable
Origin
X-Forwarded-For
Host
X-Platform
Arr-Disable-Session-Affinity
X-Hosted-By
X-Ezoic-Cdn
Cache-Provider
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-ARC
Alternate-Protocol
X-Recruiting
Version
X-Msg-2-Log
DynaTrace
X-Sapient
Edge-Control-Message
X-Lambda-Id
X-Via-JSL
X-SSLProxy
X-SSLUpstream
X-Supported-By
X-Rnd
X-Translation
X-Instart-Request-ID
X-Microcache-Status
X-Platform-Cache
Akamai-IP
MIME-Version
X-Cache-Age
X-Cache-Namespace
X-Akam-SW-Version
X-I-Sp
X-SO
SSPAppContext
X-Cache-TTL
X-Cache-Rule
X-BS
X-App-Status
X-SVR-IIS
X-Svr-Proxy
Content-Hash
X-TransIP-Balancer
X-Powered-By-360WZB
X-Art-Request-Id
X-TransIP-Backend
X-Environment
S-Cnection
X-Director
X-Duration
X-Correlation-Id
X-Dealeron-Original-Url
X-DealerOn
X-Dealeron-Backend
WZWS-RAY
USPLoggingUUID
Pagespeed
Node
X-Server-Upstream
X-Magento-Cache-Control
X-SSL-Cipher
X-NetCat-Version
X-SSL-Protocol
RTSS
Pool
X-Matrix-Server
X-Matrix-Proxy
X-Acquia-Application-UUID
Content-Disposition
X-Track
X-Cache-Tags
X-Powered-By-VelaWeb
X-Hypernode
X-Rocket-Nginx-Bypass
X-CSRF-Protection
X-Edge-IP
X-Expires-Orig
X-Server-Id
X-LB-Node
Accept-Encoding
X-App-Hosting
X-Generated
X-Daa-Tunnel
X-Abgroup
SN
X-ServerName
X-Cache-Debug
X-Cache-Control-Orig
X-Powered-By-VTEX-Janus-Edge
X-NoCache
X-Debug
X-Hiawatha-Cache
X-Page-Cache
X-Drupal-Cache-Tags
X-Last-Modified
X-Server-ID
X-Storage
Wsr-Cache
SiteSpeed
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-Varnish-Cacheable
X-Varnish-RemainingLife
X-Varnish-ObjectSource
X-Dispatcher
X-Grace
X-Cache-Lifetime
Contao-Page-Layout
X-Ttl
X-Cache-Handler
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Powered-By-ChinaCache
X-SV-Nginx-Duration
X-SV-Cacheable
X-SV-Expires
X-SV-FromDBCache
X-SV-Pid
X-Route-Server
X-VARITI-CCR
X-SV-Duration
X-SV-CreatedAt
X-SV-CacheTags
X-SV-Edge
Req-Id
FAI-W-FLOW
Content-Encoding-Handler
X-Gamma-Serve
X-GeoIP-Country-Code
Cache
Src-Update
Update-Time
X-Client-IP
X-Firenze-Processing-Time
X-Front
X-Now-Id
X-Rocket-Nginx-Serving-Static
X-TransIP-Reserved
X-Cache-Level
X-CJ-Soft
X-Sucuri-ID
X-Flow-Powered
X-I
X-Forwarded-Proto
X-Revision
X-Env
Lsrequestid
X-Amz-Meta-S3cmd-Attrs
X-Content-Type-Option
X-Pressidium-NinukisWP-Ver
X-Drupal-Cache-Contexts
X-Cache-Engine
X-Discourse-Route
X-SRV
X-ATG-Version
X-Varnish-TTL
X-Litespeed-Cache-Control
X-Correlation-ID
X-Cache-Server
X-Cache-Expires
X-Time
X-Sucuri-Cache
If-Modified-Since
X-SDS
X-SmugMug-Hiring
X-SmugMug-Values
X-TTFB
X-TTFB-L
Smug-CDN
X-GeoIP-Country-Name
X-Trace-Id
X-Geo-Country
X-Locale
X-Content-Encoded-By
X-LB-Server
ServerID
Backend
PICS-Label
X-Country-Code
X-GUploader-UploadID
X-Varnish-IP
Cache-Tags
X-Unbounce-VisitorID
X-Unbounce-Variant
X-IsCacheURL
W
X-Amz-Rid
X-Unbounce-PageId
X-Server-Instance
ServerName
Service-Worker-Allowed
Cneonction
Author
X-Litespeed-Cache
SEOMOZ
X-Middleware-Start
X-Speed-Cache
X-Varnish-Age
MJ12bot
X-Speed-Cache-Key
X-PwB-Node
Strikingly-Cached-Version
X-Cache-Operation
Strikingly-Cache-Region
Strikingly-Cached
X-Connection-Hash
X-Esi
Location
X-Vhost
X-Transaction
X-Dispatch
X-Varnish-Url
X-Cookie-Domain
X-Twitter-Response-Tags
X-LB
X-Cache-Only-Varnish
X-Cache-Type
X-Varnish-Backend
Pv
X-N
X-Acquia-Application-Trace
AMF-Ver
Server-Name
X-Service-Id
X-Always-Cache
X-BackendServer
X-Akamai-Device-Model
Https
X-Akamai-Device-Characteristics
X-FIRSTBase
X-Url-Base
X-FTR-Request-ID
Use-Proxy
Custom-Header
X-Real-Server
MC
S
X-HW
Fw-Via
Section-Io-Id
Ohc-File-Size
X-Content-Age
X-Cache-PageType
X-ServerID
Content-MD5
NnCoection
X-Cache-Device-Type
Nodo
X-Cache-Fix
X-Config-Blacklist-Version
X-Varnish-Server
X-Storage-Cache-Date
X-Storage-Cache
X-Webkit-CSP
X-Frontend
X-Storage-Cache-Expires
X-ORACLE-DMS-RID
X-High-Performance
X-Varnish-Retries
X-CF-Passed-Proto
X-Yadis-Location
X-Amz-Storage-Class
X-Worker
X-Dynamic-Cache
X-Cache-Control
X-Amz-Meta-Content-Md5
NetMindSessionID
FindLaw
Srv
Page-Completion-Status
X-Xrds-Location
X-Wikidot-Backend
X-ID
X-Wikidot-Static-Cache
Proxy-Connection
X-CDN-Forward
X-Pool
X-Key
Local-Info
Surrogate-Key-Raw
X-Varnish-Ttl
X-Pantheon-Phpreq
X-Symfony-Cache
X-Origin
X-Empowered-By
X-Processing-Time
X-Pantheon-Environment
Qs-Cache
X-Now-Cache
Xc-Version
X-CacheFROM
X-Pantheon-Site
X-TTL
X-Id
From-Origin
Content-Transfer-Encoding
X-SRCache-Key
Prama
X-Browser
X-Magnolia-Registration
X-Vip
X-Runtime-Affili
X-App-Runtime
X-Nginx-Cache
X-Location
X-RequestId
X-Nitro-Cache
X-Shield-Request-Id
X-Srv
Edit
X-UPSTREAM
X-NginX-Cache
IM-Version
Cm-Server
Hummingbird-Cache
X-Unique-ID
X-Varnish-Hits
Swift-Performance
X-Content-Security-Policy-Report-Only
X-Nbs
Drupal-Pagecache-Memcache
X-Cache-2
SRV
X-SP-Farm
X-SP-UniqueName
X-Orig-Vary
X-VC-Enabled
X-BKSrc
X-Runtime-Rack
Tracecode
X-Ratelimit-Remaining
X-Sys-Req-ID
X-Runtime-Memory
X-Ratelimit-Limit
X-FW
Noq
X-Real-IP
X-AF-Userserver
Ram
Ramp
X-Rq
Dtk-Cache-Check-0
X-WPL-DATA
X-Analytics
IBM-Web2-Location
X-TB-M
X-Sedo-Request-Id
X-Cache-Miss-From
RequestId
Access-Control-Allow-Method
X-Shard
X-Varnish-ID
HCVer
HAVer
X-Stage
X-RealServer
X-Cache-CFC
Cached
X-LP
X-Pagename
Front
Adm-Server
X-4ormat-Cacheable
X-JSESSIONID
X-Culture
Backend-Timing
X-Proxy
X-NginX-Server
X-Distributor
X-Redman-Final-Url
X-Hit-Cache
X-Avg-Cookie-Expires
CacheControlHeader
X-Role
X-AVG-Country-Code
X-SE-Debug
X-Redman-Backend
X-Akamai-Edgescape
X-CB-Server
X-ClientSide-Caching
Web-App-Origin-Name
Content_type
X-IIJ-Cache
X-GoCache-CacheStatus
AsisCache
Accept-Language
X-Span
X-Proxy-Backend
X-Yottaa-Metrics
A-Powered-By
X-JG-Page-Cache
Accept-Charset
X-Yottaa-Optimizations
X-ACMCache
X-WP
X-Atraveo-TTL
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
X-Fedora-School-Id
X-Atraveo-Varnish-Server-Id
X-Atraveo-Zone
X-Hstore
X-Generated-Timestamp
X-ServerIndex
Identity
X-FireWall-Port
Pics-Label
X-Request-Uri
X-Hrouter
X-Atraveo-From-Varnish-Cache
X-PRAM
X-Force
X-Atraveo-Cache-Control
X-Remote-Addr
X-Varnish-Hostname
X-Path-Route
X-Source-ID
X-Rule
Server-Info
X-PF-Uncompressing
X-Appmachine-Environment
X-App-Server
X-LW-Web-Server
X-Backend-Status
X-WR-Flags
X-CAPServer
X-Dw-Trace-Id
X-Atraveo-ETag
Lb
X-App
X-CLOUD-TRACE-CONTEXT
Frame-Options
X-Vcache
X-Atraveo-Expires
X-GeoIP
X-Agent
Proxy-Agent
Lookup-Cache-Hit
Accept-CH
X-A
X-Purge-URL
X-Ratelimit-Reset
XDomainRequestAllowed
X-Purge-Host
CLMOB
X-HydroSheep
X-Session-ID
X-Varnish-Debug-Age
X-Pantheon-Az
X-Jphone-Copyright
X-Consent-Required
X-HeBS-Cache-Status
Environment
X-NWS-UUID-VERIFY
X-Resource
X-Varnish-Debug-TTL
Beyond-Iis
X-Debug-Token
Request-EU
X-CacheDebug
Request-Country
AR-PoweredBy
Pf.Web.Request.Id
X-E
X-Processed-By
Disablevcache
X-Smartcache-Timeout
X-Framework
X-Domain-Checked
X-Smartcache-Keys
SVR
X-ESI
X-Plat
X-VC-TTL
WP-FROM-CACHE
Upgrade-Insecure-Requests
AR-SID
X-WR-MODIFICATION
X-VCS-Ttl
X-VCS-Cacheable
X-Cache-Ttl
X-Provisioner-Version
X-Webstats-RespID
X-Frames-Options
X-Batcache
CS-SERVER
Thanks
Dispatcher
AR-ATIME
X-Detected-Device
Firespring-Website-Id
AR-CACHE
X-AOL-HN
SHInfo
Cmstype
X-EPiphany-Vid
Cmsid
X-Client-Vid
NtCoent-Length
VServer
X-Distil-CS
X-Client-Image-Vid
ServerSignature
MageStack-Config
MageStack-Cacheable
MageStack-Debug
MageStack-Loadbalancer
MageStack-Tag
MageStack-PageSpeed
MageStack-Cache-Status
MageStack-Cache-Lifetime
X-OpenCart-Lightning
Copyright
MageStack-Area
MageStack-Cache
MageStack-Cache-Hits
MageStack-Web-Node
MageStack-Magento-Version
Eomportal-Instance
From
ServerTokens
X-Map-Context
X-Req-Head-Response
X-V
Nginx-Cache
X-Rebelmouse-Cache-Control
X-Bip
Ufe-Result
N365rili
Ibf5scheme
WP-AdvCache-MemCached
X-Ghost-Cache-Status
EagleEye-TraceId
X-ARRServer
Server-ID
X-Block-RuleID
X-Cache-Dispatcherpragma
X-CRA-DC
X-Cache-On
Filters
X-CacheLoc
BALANCEDTO
X-Cache-Dispatchercachecontrol
X-Block-Rule
X-Disney-Akamai-Rule
Arrnode
X-Actindo-Rs
X-Soro
X-Server-IP
X-HA-Backend
X-Via-S
Access-Control
X-HA-Frontend
X-Proxy-Cache-Control
*
X-HashTwo
X-Data-Request
Num
X-Cocoon-Version
Traffic-Origin
X-Varnish-Cache-Local
Play-Detected-Device
X-B2f-Not-Route
Play-Detected-UserAgent
Proxy-Cache
X-Aramark-SID
Il-Cl
Home
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
X-Domino-CacheValidationWithETagResult
X-Domino-CacheValidationWithETagReason
X-Header
X-Upstream-Status
VANITY-HOST
Myheader
X-Actindo-Request-Id
X-Actindo-Thread-Id
X-Adnet
X-Generated-Time
X-Cache-Doesi
X-Resolver-IP
X-Info
Cleartype
Machine
Resin-Trace
X-Amz-Id-1
X-Amcomm-Site
X-TKP-SRV-ID
IISExport
X-Resty-Request-Id
X-Oferteo-Domain
X-Upstream-Backend
X-PBY
Max-Age
ScoreTracker
WWW-Authenticate
X-HTML-Minification-Powered-By
X-Nginx-Host
X-SAPP
X-Refresh
IES-Server
X-Cms-Mode
X-Dev
X-Rack-Cors
X-Hosting-Env
Device
Worker
Load-Balancer
X-SDE-Name
X-Cacheable-TTL
Access-Control-Allow-Header
X-SERVER-NAME
Url
X-Adobe-Content
X-Adobe-Loc
X-Balanceador
Access-Control-Request-Headers
X-AEM
Referer
X-Varnish-URL
X-Upgrade-Enabled
COMMERCE-SERVER-SOFTWARE
X-Garden-Version
Bios
Cteonnt-Length
X-Cache-Me-Harder
X-Access-Control-Allow-Origin
X-Highwire-Sitecode
X-Drectory-Script
X-Now-Trace
X-Forwarded-Host
MageStack-Cache-Warning
X-FastCGI-Cache-Status
X-Dynatrace
Now
X-Highwire-Smart-Code
Dynatrace
TC-Cache-U
Id
X-Goog-Meta-Replace
X-RiS-UFDI
X-Fastly-Request-Id
TC-Cache-IC
TC-S-Cache
Edgecast
Pragrma
X-Cache-Detail
X-Varnish-Grace
X-AutoRu-App-Id
Fastly-Backend-Name
TC-S-Cache-M
X-Autoru-Host
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Goog-Meta-Policy
X-Nx-All
NODE
X-Depends
Aurora-Node
X-UnsetCookies
MageStack-Last-Modified
X-MCB-Server
X-Custom-Name
X-Build-Id
Magicmarker
X-Middleton-PageSpeed
HitType
Fastly-Debug-Digest
X-Blog
X-Confluence-Request-Time
X-SH-Cache-Status
X-Page
X-Session-Reinit
X-Nx
Provider
X-WebKit-CSP-Report-Only
X-Directory-Script
TC-Cache
X-Secret
X-Protected-By
MageStack-Cache-Lifetime-Sent
X-Ms-Request-Id
X-Cache-Time
DNNOutputCache
Prot
X-Flex-Lang
X-Varnish-Action
Keywords
X-Response
X-ASAP-Cache
X-Cdn-Forward
XX
X-Gyrobase-Publication
X-LBPoolMember
X-Captured
X-Test
X-Served-Server
EN-User
X-WEBMGR-CACHE
X-Timestamp
X-7d-Instance-Id
X-7d-Trace-Id
AC-ELC
Ttl
AMP-Redirect-To
PServer
X-Cf-Powered-By
X-Beatles
X-DN-Cache-Control
X-Desc
X-Varnish-Id
X-Clara-ASAP
X-Application
RN-Server
X-Flex-Evstart
X-Requestid
X-Flex-Tags
ServerNode
X-Flex-Evend
X-Origin-Date
X-Flex-Lastmod
X-Highwire-RequestId
X-ETag
X-Envoy-Upstream-Service-Time
X-Flex-Tag
X-Varnish-Backend-Beresp-Backend
VAR-Cache
X-Server-Addr
X-WebNode
X-Flex-Community
X-PHP-Response-Code
X-Highwire-SessionId
X-Streams-Distribution
Viewport
X-Rack-CORS
X-UA-Bot
X-SmartBan-Host
X-SmartBan-URL
X-IP
X-Vary-Options
X-TLS-Version
X-Pj-Cache-Status
X-ORIKEY
X-Appversion
X-ENDPOINT
Web
X-APIAUTH-VAL
X-Varnish-Debug-Hits
X-Proxy-Skip
X-APIVERSION
X-ROUTING
X-Akamai-Transformed
NLCacheNote
X-Served
X-Tag-Playlist
Report-To
X-Appid
X-Gateway-Rate-Limit-Delayed
X-DB-Content-Length
X-Serv
Server-Ip
X-Varnish-Ip
X-Deity
Serverid
ViewMode
X-CACHE-TTL
VSID
X-SV
X-SilverStripe-Cache
X-Skip-Cache
X-Cache-Varnish
Yoncu-Errno
X-Svr
X-Reqid
X-Geo-IP
X-DataDome
HTTPS
X-CacheID
MS-CV
X-Shopware-Cache-Id
GranicusServer
X-Status
X-SSLTerm-Server
X-MAT-GEO
X-Origin-Cache
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Response-Time-X
X-Custom-Header
X-Beluga-Response-Time
X-Client-Id
X-DevSrv-CMS
Tk
Debug-Status
Session-From
ServerIP
X-Beluga-Record
X-Beluga-Node
X-NoIndex
X-Obvious-Info
X-Route
X-Policy
X-Instance
Description
X-Beluga-Cache-Status
X-EC2-Instance-Id
Ohc-Response-Time
Og
X-Shopware-Allow-Nocache
X-Obvious-Tid
X-CH-Device
X-ACCELERATE
X-ZSITES-DNS
X-Title
X-Cache-Node
X-Transaction-Name
AETN-Area-Code
X-Processed
X-This-Proto
YF-ID
AETN-City
WN
X-Cachable
X-Say-Cacheable
X-MID-Host
X-Itkg-Cache-Tags
X-ProBase-Server
X-Say-TTL
X-SayCDN-TTL
Amfplus-Ver
X-Time-Spent
X-WN-ClientGroup
X-V-Cache
AETN-Continent-Code
X-Powered-By-Home.Pl
AKA-DEVICE
Tempo
X-Cache-LB
X-Cname-TryFiles
AETN-State-Code
Dis-Env
X-GSL-Server
X-TEST
X-Layout
Paypal-Debug-Id
X-MrHost
AETN-Postal-Code
AETN-Longitude
AETN-DEVICE
AETN-Country-Name
X-Aramark-CSID
AETN-Country-Code
X-M
AETN-EU
X-HA
AETN-Latitude
X-FPC
X-Accel-Cache-Control
X-Beget-Proxy
X-ProcessESI
X-BPool-Back
X-BServer
X-Gannett-Site-Version
X-ManagedFusion-Rewriter-Version
X-Airee-Node
X-B3-Sampled
X-Who
X-Node-App
X-Built-With
CDCHOST
X-Node-Id
X-NodeID
X-XHTML-Minification-Powered-By
X-Amzn-Trace-Id
Cf-Ipcountry
Hit-Count
X-W3TC-Minify
X-Varnish-Cache-Ttl
X-Powered-By-ADS
X-Rewritten-By
X-SCM-Server-Number
X-Test-Debug
X-WA-Info
StatusCode
X-Server-Generated
SB-Cache-Life
SB-Cache-Remaining
SB-Site-Device
X-Enhanced-By
X-Cache-Warmer
X-Proto
X-Cache-TTL-Current
NZSpeedy
Page-Template
SB-Site-IE-VERSION
X-AMAZEEIO
X-Proxy-Cache-Key
X-Proxy-Server
X-RemovedCookies
X-ReqId
DrivedBy
X-Origin-Server
X-Cache-TTL-Age
X-Ms-Version
X-Nginx-Request-Processing-Time
Purge-Cache-Tags
Xc
X-SuperCache
X-VG-WebCache
X-Proxy-Id
X-Firefox-Spdy
X-FromPodPressCache
X-Amzn-RequestId
X-Amz-Apigw-Id
REFRESH
X-Lw-Cache
SBSS
Backend-Powered-By
X-Backside-Transport
X-Global-Transaction-ID
X-M-Log
X-Wodby-Node
X-DDM-SERVER
X-Clx-Request
Hosted-By
NGX
X-Vol-Mrp
X-Vol-Correlation
X-Now-Instance
X-M-Reqid
X-MSU-SOURCE
X-Qnm-Cache
X-DDM-SERVER-UPDATED
X-HostName
PBS
X-Mighty-Proxy
X-Pass-Through
Response-Time
Content
X-Max-Age
Ssl-Proxy-Server
X-XHR-Current-Location
X-ServiceProvider
X-HAProxy
Requested-Host
X-PM-ID
Progma
X-Lb
Server-Id
X-Src-Webcache
X-Search-Id
AMP-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Ecid
X-COUNTRY-CODE
X-Xml-Http-Blocked
X-PROCESSED-BY
X-Mobilized-By
X-FORWARDED-PROTO
X-Scheme
X-Sid
X-RENDER-TIME
X-Geo
X-Compress-Hint
SERVER-ID
BackendServer
X-RAMCache
X-Actual-Url
X-DEBUG
X-Hit
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
X-Instance-Name
X-Fastly-Backend-Reqs
OracleCommerceCloud-Version
OracleCommerceCloud-Sandiego
X-I-V
X-Meta-MSThemeCompatible
Key
X-Firewall
MachineName
WebServer
Generate-Time
X-ASAP-Age
X-We-Are-Hiring
Prototype-RootPath
Returned-Status
X-UT-Cache
MSThemeCompatible
MwpReleaseVersion
X-Nginx-Page-Cache
Httpd-Identifier
X-Mw-Workerstats
X-NginX-Upstream
X-Ruby-Cluster-ID
X-Sn-Servicetimems
X-M-V
X-MCF-ID
X-Jcms-Ajax-Id
X-Fpc
X-S-V
X-Homeaway-Requestmarker
X-S-C
X-Q-S
X-UPServer
X-Varnish-Cached
CDN-Uid
X-M-P
CmsfirstPublishTimestamp
CommercePlatform-Version
X-SG-Server
CDN-RequestId
CDN-PullZone
X-Varnish-Cached-TTL
CDN-Cache
X-M-T
CDN-CachedAt
MSSmartTagsPreventParsing
X-FG-RequestId
X-Enabled3
PB-PID
PB-RID
X-Enabled2
PROGMA
LB
Amp-Access-Control-Allow-Source-Origin
X-GZip
X-Optimization
X-Varnish-Age-Debug
X-Varnish-TTL-Debug
X-Enabled1
X-Grid-Server
Ews
Servername
X-ORIGN-SERVER
X-Router
X-Telligent-Evolution
X-Origin-Upstream-Status
X-Mobile-Rewrite
X-InDy-Memory
X-Cache-Id
X-InDy-Query
X-InDy-Time
X-From-Cache
X-Cache-HT
X-CAMPUSSUITE-ENVIRONMENT
X-CAMPUSSUITE-TENANT
X-CAMPUSSUITE-DEBUGGING
V-Cache-Ttl
PagesDisplayed
X-Old-Content-Length
X-CSRF-Token
X-Nginx
X-Machine
X-Magento-Route
X-Expires
X-Ssl-Cipher
Language
Fastly-Restarts
X-Appmachine-CreatedOn
X-Appmachine-Duration
X-Appmachine-Name
X-ENV
X-Static
EQ-Cache
X-NMT-Proxy
X-Ruxit-Js-Agent
X-Serverid
X-JoinUs
X-Phpwcms-Release
Provided-Host
Pramga
Session-Id
X-BeResp-Ttl
X-UPSTREAM-Address
X-Content-Type
CommunityServer
X-Cache-Via
FastCGI-Cache
X-Abuse
X-Zendesk-User-Id
X-Zendesk-Origin-Server
X-SEA-Instance-Name
X-RequesterIP
X-Via-NSCOPI
X-Webcelerate
X-MainProfileCategory
X-Instance-Id
X-MainProfileID
X-MainProfileName
X-MyName
X-MainProfileURL
X-HS-Status
X-HP-CAM-COLOR
SINA-LB
Nitro-Cache
SINA-TS
X-Cache-FS-Status
X-DynamicCache
X-D2id
X-Built-By
X-Dck
Sl-Pgid
X-CloudBurst-Backend
X-Varnish-Cache-Control
X-VHosting-Cache
X-Boot
ID
X-CloudBurst-Cache
X-Served-From
X-BIT-Node
X-Batcache-Reason
X-Server-Ip
X-Pagely-Cache
X-CloudBurst-Frontend
X-CloudBurst-WordPress
X-Cache-ID
X-OPNET-Transaction-Trace
X-Mobile-Device
Arrow-RequestId
X-Mobile-Device-Type
X-Ser
X-Render-Time
X-SCProxy
X-Debug-Message
X-Az
X-SSL
X-PressLabs-Stats
SS
X-Activity-Id
X-Amz-Meta-Version-Id
X-Navigation-Version
X-NewsFlow-Sitename
HA-Geolat
HA-Geocountry
HA-Geolon
HA-Georegion
HA-Ipaddr
HA-Host
HA-Geocity
HA-Cloudapp
X-Rocket-Nginx-Reason
X-Rocket-Nginx-File
X-UType
BlockPHPCallEnd
DB-Nickname
Content-Sn
HA-Servedtime
HA-Urlpath
X-Newrelic-Synthetics
X-Bcwwwid
X-MidCOM-Meta-Cache
X-GEO
X-Cdn-Origin
X-Distributed-By
TYPO3-Sitename
TYPO3-Pid
ModuleCacheType
L5d-Success-Class
NKBVHEADER
X-SID
Request-Time
X-Requested-With
X-PoweredBy
HSTS
HitInfo
TP-Cache
TP-L2-Cache
X-Cache-Action
X-Box
FRONT-END-SECUREBROWSER
Cache-Status
X-PBS-Appsvrip
X-Olaf
X-PBS-Appsvrname
X-PBS-Fwsrvname
X-Reflector-Cache
X-Reflector
X-Cache-Extended
X-Cluster
Unique-Request-Id
X-D-Time
Web-Server
Webserver
End-User-Country
X-Phpwcms-Page-Processed-In
X-Generation-Time
X-S-Misc
X-FastCGI-Cache
X-Compressed-By
X-Log
X-Oracle-Dms-Rid
X-Qiniu-Zone
X-CGP