Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
P3P
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
X-Xss-Protection
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Adblock-Key
X-Varnish
Referrer-Policy
X-Request-Id
X-Check
X-Generator
X-Language
X-Template
X-Buckets
X-Type
X-Cache-Group
X-Pass-Why
X-Drupal-Cache
WPE-Backend
X-Permitted-Cross-Domain-Policies
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Alt-Svc
X-Download-Options
X-Ac
X-Hacker
X-Cache-Hits
Host-Header
X-AspNetMvc-Version
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-FeatureSet
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PrivacyLevel
X-Via
X-Powered-By-Plesk
X-Runtime
X-Served-By
P3p
X-Contextid
X-PC-Key
X-PC-Hit
X-UA-Device
X-Amz-Cf-Id
X-PC-AppVer
MS-Author-Via
X-ServedBy
Content-Location
X-PC-Date
X-PC-Host
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-Timer
X-IPLB-Instance
X-Seen-By
X-Wix-Request-Id
Status
X-TEC-API-VERSION
X-Rid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Ua-Compatible
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
CF-Cache-Status
Cartoon
X-Tumblr-Pixel-1
X-Iinfo
Access-Control-Allow-Credentials
X-Backend
X-Tumblr-Pixel-2
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
X-Host
Content-Encoding
X-CST
X-Endurance-Cache-Level
Powered-By
X-Mod-Pagespeed
X-Cache-Hit
X-Port
X-Cache-Enabled
X-FRAME-OPTIONS
X-NewRelic-App-Data
X-CDN
X-Tumblr-Pixel-3
X-Logged-In
X-Newrelic-App-Data
X-DIS-Request-ID
Keep-Alive
X-Server-Powered-By
X-Drupal-Dynamic-Cache
X-Server
X-Nginx-Cache-Status
X-Robots-Tag
X-Accel-Version
X-Request-ID
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Turbo-Charged-By
X-Proxy-Cache
X-Page-Speed
X-Content-Powered-By
X-LiteSpeed-Cache
X-GitHub-Request-Id
Content-Security-Policy-Report-Only
X-Content-Digest
X-FW-Hash
X-AH-Environment
X-FW-Server
X-Rack-Cache
X-FW-Static
X-FW-Type
X-FW-Serve
X-Tumblr-Pixel-4
X-Pad
Request-Context
X-Varnish-Cache
X-Hits
Edge-Control
X-Request-Country
X-Webcom-Cache-Status
X-XRDS-Location
X-Trace
SPRequestGuid
Access-Control-Expose-Headers
X-SharePointHealthScore
X-MS-InvokeApp
X-BC-Stapler
X-Node
MicrosoftSharePointTeamServices
Edge-Cache-Tag
Cf-Railgun
X-HS-Cache-Config
WP-Super-Cache
X-HS-Content-Id
X-Amz-Id-2
X-Amz-Request-Id
X-HS-Combine-CSS
Timing-Allow-Origin
X-CF-Powered-By
X-SERVER
Charset
X-Content-Security-Policy
X-Died
X-Webserver
X-Cache-Lookup
X-FullPageCaching
X-INKT-SITE
X-INKT-URI
X-PHP-Backend
Request-Id
X-PhApp
X-Cnection
X-Fastly-Request-ID
Access-Control-Max-Age
SPIisLatency
SPRequestDuration
X-Backend-Server
MicrosoftOfficeWebServer
X-Edge-Cache-Key
X-Edge-Cache
EagleId
CONTENT-SECURITY-POLICY
X-Swift-SaveTime
X-Swift-CacheTime
Composed-By
X-SS-Conf
X-SS-Location
Rating
X-CDN-Pop-IP
X-CDN-Pop
X-Servedby
X-Server-Name
X-Device
Grace
X-Tumblr-Pixel-5
Liferay-Portal
Served-By
X-DDC-Arch-Trace
X-NF-Request-ID
X-Safe-Firewall
X-Spip-Cache
X-Dw-Request-Base-Id
Ali-Swift-Global-Savetime
X-Tumblr-Content-Rating
Front-End-Https
X-Cloud-Trace-Context
X-VCache
X-Hyper-Cache
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-HeyJason
X-Original-Date
Surrogate-Control
X-Microcache
P-WS
P-LB
X-Cluster-Node
X-LiteSpeed-Cache-Control
X-TNCMS
X-Loop
X-RateLimit-Remaining
X-RateLimit-Limit
X-FB-Debug
X-Middleton-Display
X-Sol
Display
X-Clacks-Overhead
X-StackifyID
Content-Style-Type
X-Middleton-Response
Response
X-OneAgent-JS-Injection
X-Acc-Exp
X-Jimdo-Instance
X-RateLimit-Reset
X-Jimdo-Wid
X-Kinsta-Cache
Content-Script-Type
X-Vtex-Processado-Em
X-Wix-Punisher
X-DNS-Prefetch-Control
Public-Key-Pins
X-Debug-Info
X-Age
X-Shopid
X-Sorting-Hat-Featureset
X-Shardid
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Podid-Cached
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Shopid-Cached
X-Amz-Version-Id
X-DynaTrace-JS-Agent
X-HOST
X-Magento-Tags
X-Tumblr-Pixel-6
X-Zen-Fury
X-XN-XNHTML
X-XN-Trace-Token
X-Px
X-Firenze-Processing-Times
X-Cached
X-Ruxit-JS-Agent
X-Goog-Hash
Fpc-Cache-Id
X-User-Agent
X-LW-Cache
X-N-OperationId
PageSpeed
X-Url
X-WebKit-CSP
Xkey
X-Cache-Config
Wpe-Backend
X-Version
Retry-After
X-Hostname
Refresh
X-Topify-Platform
X-Generated-By
X-FORWARDED-FOR
X-Upstream
Feature-Policy
X-Handled-By
X-Frame-Option
X-Edge-Location
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
Allow
Rt-Fastcgi-Cache
TCN
X-Whom
Access-Control-Request-Method
X-Source
X-B-Cache
X-From
Fastcgi-Cache
X-Request-Time
X-Loopia-Node
Powered
X-MiniProfiler-Ids
X-Outils-CS
X-Cached-By
X-ET-API-VERSION
X-ET-API-ROOT
X-ET-API-ORIGIN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-EdgeConnect-Origin-MEX-Latency
X-Content-Options
ServedBy
X-AspNetWebPages-Version
X-URLSCHEME
Product
X-Fastcgi-Cache
X-Platform-Cluster
X-EdgeConnect-MidMile-RTT
X-Platform-Processor
Last-Published
X-Platform-Router
X-Vtex-Remote-Cache
X-Vtex-Processed-At
No
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Cache-Status-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-RESOURCE
X-CacheServer
X-DynaTrace
X-Magento-Cache-Debug
X-CMS-Version
X-Guploader-Uploadid
X-Accel-Expires
X-Varnish-HitMiss
X-Varnish-Count
X-Varnish-Cache-Hits
Warning
Imagetoolbar
X-Signature
X-Tec-Api-Origin
X-Response-Time
X-Tec-Api-Version
X-Tec-Api-Root
X-Varnish-Host
X-LBLID
X-Engine
X-Platform-Server
X-Application-Context
X-Passed-To
X-Returned-From-DLL
X-Returned-From
X-Original-Request
X-Passed-To-DLL
X-Msg-2-Log
X-Actual-URL
X-Microcachable
X-Location-Id
X-ApacheServer
Generator
X-NWS-LOG-UUID
X-PERF
X-Device-Type
X-Umbraco-Version
X-Cache-Info
X-Developer
Dmn
X-S
Public-Key-Pins-Report-Only
X-Varnish-Beresp-Grace
X-UD-Method
X-Varnish-Beresp-Ttl
Host
X-Varnish-Beresp-Status
X-Passed-To-BeforeDispatch
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Cache-Key
X-Passed-To-PostProcessResponse
X-ARC
X-HS-Content-Campaign-Id
X-Stale
Cache-Key
X-F-Cache
X-Platform
Fhost
Cache-Provider
X-Recruiting
DynaTrace
X-Micro-Cache
Pagespeed
X-Defender
X-Shop-Id
X-Hosted-By
X-Akam-SW-Version
X-Ezoic-Cdn
Alternate-Protocol
X-Gateway-Cache-Key
X-Track
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
Origin
Surrogate-Key
X-Powered-By-360WZB
X-Microcache-Status
Content-Hash
Arr-Disable-Session-Affinity
X-Translation
X-Dispatcher
X-Instart-Request-ID
X-Cache-Rule
X-Lambda-Id
X-SSLUpstream
X-SSLProxy
X-Dns-Prefetch-Control
Version
X-Platform-Cache
X-Acquia-Application-UUID
X-Powered-By-VTEX-Janus-Edge
WZWS-RAY
X-Cache-Age
X-Magento-Cache-Control
MIME-Version
X-URL
X-Via-JSL
Server-Timing
X-Cache-Tags
X-Supported-By
X-Duration
Content-Disposition
S-Cnection
X-Svr-Proxy
X-Sapient
X-SVR-IIS
X-Director
USPLoggingUUID
X-Forwarded-For
X-Rnd
RTSS
X-BS
X-App-Status
X-SO
X-I-Sp
Akamai-IP
SSPAppContext
X-I
X-Abgroup
X-CSRF-Protection
X-Correlation-Id
X-Powered-By-VelaWeb
X-Environment
X-Dealeron-Backend
X-Dealeron-Original-Url
X-Cache-Namespace
X-Server-Id
X-DealerOn
X-Art-Request-Id
X-Server-Upstream
X-NetCat-Version
X-TransIP-Balancer
X-Rocket-Nginx-Bypass
Node
X-SSL-Cipher
X-SSL-Protocol
X-Cache-TTL
X-Matrix-Server
X-ORACLE-DMS-ECID
X-Matrix-Proxy
X-App-Hosting
Pool
Wsr-Cache
X-Edge-IP
X-Generated
X-Daa-Tunnel
X-Page-Cache
X-TransIP-Backend
X-Varnish-Seen-By
X-LB-Node
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-Varnish-ObjectSource
X-Debug
X-Varnish-GracePeriod
X-Hypernode
X-Revision
X-Gamma-Serve
X-Drupal-Cache-Tags
X-Client-IP
X-Correlation-ID
X-Varnish-TTL
FAI-W-FLOW
X-ServerName
SN
X-Vcap-Request-Id
X-Expires-Orig
X-Url-Base
X-NoCache
Contao-Page-Layout
X-Front
X-Route-Server
X-Varnish-Cacheable
Edge-Control-Message
Req-Id
X-Storage
X-Cache-Handler
X-Rocket-Nginx-Serving-Static
X-Now-Id
X-Vhost
X-Cache-Debug
X-Cache-Lifetime
X-Acquia-Application-Trace
X-Discourse-Route
X-Hiawatha-Cache
X-Cache-Control-Orig
X-Amz-Meta-S3cmd-Attrs
X-ATG-Version
Accept-Encoding
Src-Update
Update-Time
SiteSpeed
X-Server-ID
Powered-By-ChinaCache
X-SV-Expires
X-SV-Edge
X-SV-CreatedAt
X-SV-CacheTags
X-SV-Duration
X-Cache-Level
X-LB-Server
X-GeoIP-Country-Code
X-SV-Pid
X-SV-Nginx-Duration
X-SV-FromDBCache
X-SV-Cacheable
X-VARITI-CCR
ServerID
Content-Encoding-Handler
X-Geo-Country
X-Grace
X-Pressidium-NinukisWP-Ver
X-SRV
X-CJ-Soft
X-TransIP-Reserved
Cneonction
Cache
X-Sucuri-ID
X-Dispatch
X-Forwarded-Proto
X-Varnish-Age
If-Modified-Since
Backend
X-Last-Modified
X-Esi
X-Drupal-Cache-Contexts
X-Litespeed-Cache-Control
X-Trace-Id
X-Ttl
X-Locale
X-Cache-Server
X-Country-Code
X-Sucuri-Cache
X-Cache-Only-Varnish
X-Akamai-Device-Model
X-Akamai-Device-Characteristics
X-Connection-Hash
X-Transaction
Cache-Tags
MJ12bot
X-Twitter-Response-Tags
X-Varnish-IP
X-Varnish-Url
Service-Worker-Allowed
SEOMOZ
X-Flow-Powered
X-Varnish-Backend
X-Content-Type-Option
X-Content-Encoded-By
X-Cache-Engine
X-GUploader-UploadID
Lsrequestid
X-GeoIP-Country-Name
X-Cache-Operation
X-Speed-Cache-Key
X-Cache-Expires
X-ORACLE-DMS-RID
X-Speed-Cache
X-Env
X-Webkit-CSP
Strikingly-Cached-Version
X-Nginx-Cache
X-Unbounce-PageId
X-Unbounce-VisitorID
Strikingly-Cache-Region
X-Server-Instance
X-Unbounce-Variant
Strikingly-Cached
W
X-Litespeed-Cache
X-Amz-Rid
X-Middleware-Start
X-TTL
X-SmugMug-Values
X-Cache-Control
X-TTFB
X-CF-Passed-Proto
Section-Io-Id
X-TTFB-L
PICS-Label
X-Time
X-FIRSTBase
X-Varnish-Retries
X-N
X-SmugMug-Hiring
Smug-CDN
Proxy-Connection
X-PwB-Node
X-High-Performance
X-Cookie-Domain
X-Firenze-Processing-Time
Server-Name
ServerName
X-Always-Cache
Page-Completion-Status
Custom-Header
Location
Content-MD5
X-SRCache-Key
X-BackendServer
Nodo
Author
X-Service-Id
X-IsCacheURL
FindLaw
Swift-Performance
X-Cache-Type
Srv
From-Origin
X-SDS
X-WR-MODIFICATION
X-ServerID
X-Now-Cache
X-ID
S
Qs-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
AMF-Ver
MC
X-Magnolia-Registration
X-BKSrc
X-Key
X-Varnish-Server
Pv
X-Storage-Cache-Expires
X-Srv
X-FTR-Request-ID
X-Empowered-By
X-Storage-Cache-Date
X-Processing-Time
X-Origin
Use-Proxy
X-Storage-Cache
X-LB
NetMindSessionID
NnCoection
X-Content-Security-Policy-Report-Only
X-FW
X-Xrds-Location
X-Cache-Device-Type
X-Yadis-Location
X-Content-Age
Surrogate-Key-Raw
X-Pantheon-Environment
X-Pantheon-Site
X-Pool
X-CDN-Forward
X-Pantheon-Phpreq
Local-Info
Edit
Tracecode
X-Symfony-Cache
Https
X-Analytics
X-Dynamic-Cache
CacheControlHeader
X-Real-Server
Backend-Timing
Fw-Via
X-AEM
X-FireWall-Port
X-Amz-Storage-Class
X-Nitro-Cache
X-Amz-Meta-Content-Md5
Cm-Server
Prama
X-ACMCache
X-VC-Enabled
AsisCache
X-Cache-Fix
X-Cache-PageType
X-Nbs
X-A
Content_type
X-Vip
X-UPSTREAM
X-Sedo-Request-Id
X-Config-Blacklist-Version
X-Cache-Miss-From
X-Browser
X-Worker
X-HW
X-Shield-Request-Id
Drupal-Pagecache-Memcache
X-Id
X-NginX-Cache
X-Frontend
X-Varnish-Hits
Pics-Label
Access-Control-Allow-Method
X-Varnish-Ttl
X-Shard
Hummingbird-Cache
X-Distributor
IM-Version
X-4ormat-Cacheable
X-SP-UniqueName
X-Orig-Vary
Xc-Version
X-Disney-Akamai-Rule
Ramp
X-Remote-Addr
X-Runtime-Rack
X-LW-Web-Server
X-E
Ram
Noq
Content-Transfer-Encoding
X-SP-Farm
HCVer
Ohc-File-Size
X-WR-Flags
X-Location
HAVer
Accept-CH
X-Varnish-ID
X-V
X-CacheFROM
X-Yottaa-Optimizations
X-Stage
IBM-Web2-Location
X-Yottaa-Metrics
RequestId
X-TB-M
X-WPL-DATA
Cteonnt-Length
X-Hit-Cache
X-Hstore
X-Cache-CFC
Server-Info
X-Hrouter
X-Akamai-Edgescape
X-RequestId
X-Adobe-Loc
X-AVG-Country-Code
SRV
X-Avg-Cookie-Expires
X-RealServer
X-Real-IP
X-Redman-Backend
Cached
X-SERVER-NAME
X-Drectory-Script
X-Adobe-Content
Lb
X-PF-Uncompressing
X-Resource
A-Powered-By
X-Unique-ID
X-Pagename
X-Redman-Final-Url
X-JSESSIONID
X-Sys-Req-ID
X-App
X-Runtime-Affili
X-Proxy-Backend
X-App-Runtime
Accept-Language
X-Framework
X-Webstats-RespID
X-SDE-Name
X-Role
X-Proxy
X-Runtime-Memory
X-Span
Server-ID
Accept-Charset
X-Hosting-Env
Web-App-Origin-Name
Lookup-Cache-Hit
X-Cache-2
X-ClientSide-Caching
X-GoCache-CacheStatus
X-VC-TTL
SHInfo
X-Generated-Timestamp
X-Backend-Status
Front
Disablevcache
X-Akamai-Transformed
X-Balanceador
WWW-Authenticate
X-NginX-Server
X-AF-Userserver
X-Fedora-School-Id
Dtk-Cache-Check-0
X-Rq
Nginx-Cache
X-ServerIndex
X-Dw-Trace-Id
X-Atraveo-Param-Rm
X-Force
X-PRAM
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
X-Vcache
IISExport
Pf.Web.Request.Id
X-ARRServer
Identity
X-Appmachine-Environment
X-Atraveo-TTL
X-Request-Uri
X-Atraveo-Expires
X-Cacheable-TTL
X-Atraveo-ETag
X-CLOUD-TRACE-CONTEXT
X-Atraveo-Cache-Control
X-Atraveo-From-Varnish-Cache
X-Path-Route
X-Culture
X-Source-ID
X-Atraveo-Set-Cookie
Beyond-Iis
Environment
X-CacheDebug
X-Jphone-Copyright
X-Debug-Token
Access-Control-Request-Headers
X-LP
X-CB-Server
XDomainRequestAllowed
X-Pantheon-Az
X-Distil-CS
Copyright
X-IIJ-Cache
X-Session-ID
X-Varnish-Debug-TTL
Request-Country
Request-EU
X-NWS-UUID-VERIFY
X-Ratelimit-Reset
X-Ratelimit-Remaining
X-Varnish-Debug-Age
VServer
X-Ratelimit-Limit
Upgrade-Insecure-Requests
X-Cache-Ttl
X-App-Server
X-Server-IP
Firespring-Website-Id
X-Frames-Options
X-RiS-UFDI
X-Varnish-Hostname
Url
ScoreTracker
X-ESI
X-SE-Debug
X-Nginx-Host
X-VCS-Ttl
SVR
X-VCS-Cacheable
X-Processed-By
X-Dev
X-Cms-Mode
WP-FROM-CACHE
X-Domain-Checked
Worker
X-Provisioner-Version
CS-SERVER
X-Client-Vid
X-EPiphany-Vid
Cmsid
X-Detected-Device
X-Proxy-Skip
X-Purge-URL
X-Compress-Hint
Cmstype
X-Purge-Host
Frame-Options
X-Req-Head-Response
X-Ms-Request-Id
Pramga
X-Map-Context
X-Via-NSCOPI
CLMOB
Referer
X-GeoIP
X-JG-Page-Cache
X-Client-Image-Vid
X-SV
X-HeBS-Cache-Status
Eomportal-Instance
X-Consent-Required
X-Upgrade-Enabled
X-Geo
X-Agent
X-Rack-Cors
AETN-Latitude
X-AOL-HN
X-Session-Reinit
X-Rule
Num
X-Rebelmouse-Cache-Control
AETN-Postal-Code
X-Info
X-Proxy-Cache-Control
X-Soro
X-Upstream-Backend
AETN-Longitude
X-Cache-Dispatcherpragma
X-CRA-DC
X-HA-Backend
X-HTML-Minification-Powered-By
X-PBY
X-Application
AETN-DEVICE
X-Cache-Dispatchercachecontrol
X-Resty-Request-Id
X-Upstream-Status
X-WebNode
AETN-EU
Access-Control
X-Varnish-Action
X-HA-Frontend
X-Via-S
X-HashTwo
AR-ATIME
AR-CACHE
X-Data-Request
X-GSL-Server
X-Actindo-Thread-Id
X-Actindo-Rs
X-Oferteo-Domain
AR-PoweredBy
Myheader
VANITY-HOST
*
Paypal-Debug-Id
X-Actindo-Request-Id
AR-SID
X-TKP-SRV-ID
X-7d-Trace-Id
AKA-DEVICE
X-Amz-Id-1
Resin-Trace
Machine
AETN-State-Code
X-Header
X-Amcomm-Site
Dispatcher
X-Cocoon-Version
WP-AdvCache-MemCached
X-Adnet
Max-Age
X-Cache-Doesi
X-Resolver-IP
X-Cache-On
AETN-Continent-Code
X-Plat
X-Forwarded-Host
X-Aramark-SID
Cleartype
Thanks
AMP-Redirect-To
X-SilverStripe-Cache
Play-Detected-Device
Play-Detected-UserAgent
AETN-Country-Code
X-B2f-Not-Route
X-Batcache
X-Domino-CacheValidationWithETagResult
X-DSMX-Render-MS
X-DSMX-Rewrite-MS
X-Varnish-Cache-Local
X-Domino-CacheValidationWithETagReason
CF-Worker-Script
AETN-City
X-MAT-GEO
AETN-Area-Code
X-Desc
Il-Cl
Proxy-Cache
Traffic-Origin
Load-Balancer
AETN-Country-Name
X-Confluence-Request-Time
X-Lb
X-M-Reqid
Home
X-7d-Instance-Id
X-M-Log
X-Qnm-Cache
IES-Server
X-HostName
ServerSignature
X-Sid
ServerTokens
Proxy-Agent
Dynatrace
Bios
X-DataDome
NtCoent-Length
X-OpenCart-Lightning
X-Now-Trace
Now
Web
X-Dynatrace
X-Varnish-URL
X-Cdn-Forward
COMMERCE-SERVER-SOFTWARE
X-Highwire-Smart-Code
X-Highwire-Sitecode
Adm-Server
X-HydroSheep
X-CACHE-TTL
PServer
X-Garden-Version
X-Test
X-CacheID
X-HS-Status
X-Secret
X-Varnish-Id
X-Gyrobase-Publication
X-Protected-By
X-Cache-Action
X-Served-Server
X-Cache-Detail
X-Cache-Extended
X-ASAP-Cache
FRONT-END-SECUREBROWSER
X-Box
X-Flex-Community
X-Phpwcms-Release
X-Phpwcms-Page-Processed-In
X-Flex-Tags
X-Flex-Tag
X-Flex-Lastmod
X-Skip-Cache
Yoncu-Errno
Ibf5scheme
N365rili
Content
X-Timestamp
X-UA-Bot
X-Flex-Lang
Ttl
X-DN-Cache-Control
X-Geo-IP
Fastly-Backend-Name
Edgecast
X-Cf-Powered-By
X-Response
X-Beatles
X-Flex-Evstart
VAR-Cache
X-Flex-Evend
X-Autoru-Host
X-AutoRu-App-Id
X-WebKit-CSP-Report-Only
X-UnsetCookies
X-Requestid
Viewport
X-Nx-All
X-ENV
MageStack-Web-Node
Pragrma
Ufe-Result
X-SAPP
X-Nx
X-Generated-Time
X-LBPoolMember
X-Cache-Time
Provider
X-Server-Addr
X-Middleton-PageSpeed
MageStack-Tag
Id
MageStack-Cache-Hits
MageStack-Debug
MageStack-Cache-Lifetime
MageStack-Config
MageStack-Cache-Status
MageStack-Cacheable
MageStack-Loadbalancer
MageStack-Cache
EagleEye-TraceId
ServerNode
X-Beget-Proxy
MageStack-Area
MageStack-Magento-Version
MageStack-PageSpeed
X-RiS-PX
Dis-Env
X-CAPServer
Aurora-Node
X-Clara-ASAP
X-Blog
HitType
Magicmarker
X-Custom-Name
DNNOutputCache
X-Fastly-Request-Id
X-WEBMGR-CACHE
X-MCB-Server
Prot
X-Depends
From
X-Ghost-Cache-Status
X-Directory-Script
X-SH-Cache-Status
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
Fastly-Debug-Digest
CommercePlatform-Version
VSID
X-APIVERSION
X-FORWARDED-PROTO
X-Deity
X-DB-Content-Length
X-Gateway-Rate-Limit-Delayed
X-WP
X-Appid
X-Serv
Device
X-Smartcache-Keys
NLCacheNote
BackendServer
X-IP
X-RAMCache
Report-To
Serverid
X-Smartcache-Timeout
X-Varnish-Ip
ViewMode
X-Unique-Id
X-TLS-Version
X-ROUTING
X-Reflector-Cache
X-ENDPOINT
X-Pj-Cache-Status
X-Served
X-APIAUTH-VAL
X-ORIKEY
X-Appversion
NODE
X-Reflector
X-Vary-Options
CommunityServer
X-Cache-Me-Harder
X-FastCGI-Cache-Status
X-Varnish-Debug-Hits
X-Access-Control-Allow-Origin
X-Tag-Playlist
X-Webcelerate
Nitro-Cache
X-MainProfileCategory
SINA-TS
X-DynamicCache
X-Instance-Id
SINA-LB
X-Cache-FS-Status
HSTS
X-PBS-Appsvrip
X-NewsFlow-Sitename
X-PBS-Appsvrname
X-PBS-Fwsrvname
X-Status
X-MyName
X-MainProfileURL
Session-Id
Provided-Host
X-MainProfileID
X-MainProfileName
X-MrHost
CDN-CachedAt
TC-Cache-U
TC-Cache-IC
TC-Cache
TC-S-Cache
TC-S-Cache-M
Tk
Debug-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
Session-From
ServerIP
BALANCEDTO
Arrnode
X-Streams-Distribution
CDN-Cache
CDN-PullZone
CDN-Uid
CDN-RequestId
X-ACCELERATE
X-Client-Id
X-Nginx
X-Aramark-CSID
YF-ID
X-Page
X-We-Are-Hiring
X-Amz-Meta-S3b-Last-Modified
D
CF-Cache-Key
X-ZSITES-DNS
X-Title
X-Origin-Date
X-Obvious-Tid
X-Obvious-Info
X-Varnish-Grace
X-FPC
X-Static
X-Layout
X-Refresh
X-DevSrv-CMS
X-DDM-SERVER
X-Cache-Varnish
X-Bip
X-DDM-SERVER-UPDATED
X-Envoy-Upstream-Service-Time
X-PHP-Response-Code
X-Highwire-SessionId
X-Highwire-RequestId
X-Amzn-Trace-Id
X-Amzn-RequestId
X-Compressed-By
X-Cluster
TP-L2-Cache
X-Reqid
X-Svr
X-Amz-Apigw-Id
Access-Control-Allow-Header
X-Policy
X-SmartBan-Host
X-Beluga-Response-Time-X
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Status
X-Beluga-Trace
X-CacheLoc
X-Block-RuleID
X-Block-Rule
X-Beluga-Node
X-Beluga-Cache-Status
Description
X-SuperCache
X-SmartBan-URL
Filters
Keywords
Ohc-Response-Time
Og
TP-Cache
X-Goog-Meta-Replace
Purge-Cache-Tags
Hit-Count
Cf-Ipcountry
Response-Time
Ssl-Proxy-Server
X-Pass-Through
X-Max-Age
X-XHTML-Minification-Powered-By
X-W3TC-Minify
X-Powered-By-ADS
X-NodeID
X-Rewritten-By
X-SCM-Server-Number
X-Varnish-Cache-Ttl
X-Test-Debug
X-PM-ID
X-Search-Id
X-Vol-Correlation
X-Now-Instance
X-Vol-Mrp
X-Wodby-Node
NGX
Hosted-By
X-Global-Transaction-ID
X-FromPodPressCache
AMP-Access-Control-Allow-Source-Origin
X-Src-Webcache
PBS
REFRESH
X-Firefox-Spdy
X-Backside-Transport
X-Node-Id
X-ManagedFusion-Rewriter-Version
SB-Site-Device
SB-Site-IE-VERSION
X-ReqId
X-Who
SB-Cache-Remaining
CDCHOST
AC-ELC
X-RemovedCookies
X-Proxy-Server
X-Nginx-Request-Processing-Time
X-Ms-Version
X-Origin-Server
X-ProcessESI
X-AMAZEEIO
X-Proxy-Cache-Key
SB-Cache-Life
X-Server-Generated
X-BServer
X-BPool-Back
X-Cache-TTL-Age
DrivedBy
X-Gannett-Site-Version
X-Captured
X-Cache-TTL-Current
X-Lw-Cache
X-Cache-Warmer
X-Enhanced-By
Page-Template
NZSpeedy
X-Airee-Node
X-Proto
Server-Id
X-Mighty-Proxy
X-ETag
MageStack-Last-Modified
GranicusServer
X-Varnish-Backend-Beresp-Backend
WN
X-Build-Id
X-Shopware-Cache-Id
X-Say-Cacheable
X-MID-Host
X-Cache-LB
MageStack-Cache-Warning
X-Powered-By-Home.Pl
X-Rack-CORS
X-HA
X-M
X-Processed
X-This-Proto
X-Goog-Meta-Policy
MageStack-Cache-Lifetime-Sent
X-Cname-TryFiles
X-Say-TTL
X-ProBase-Server
X-Cache-Node
X-NoIndex
X-Origin-Cache
Amfplus-Ver
X-WN-ClientGroup
X-Instance
X-EC2-Instance-Id
MS-CV
Tempo
HTTPS
X-Custom-Header
X-V-Cache
X-CH-Device
X-SayCDN-TTL
X-Shopware-Allow-Nocache
X-Route
X-PROCESSED-BY
X-Mobilized-By
X-COUNTRY-CODE
X-Actual-Url
X-Oracle-Dms-Ecid
X-CACHE-KEY
X-Xml-Http-Blocked
SERVER-ID
X-Scheme
Server-Ip
X-DEBUG
X-RENDER-TIME
Gzip
X-Serverid
X-Catalyst
X-Appmachine-CreatedOn
X-Appmachine-Duration
X-Ruxit-Js-Agent
VC-NoCache
ProxiaInstanceId
X-Bitrix-Composite
X-Avvio-Cms-Cacheload
Fastly-Restarts
X-Machine
MwpReleaseVersion
Returned-Status
WebServer
X-ASAP-Age
MachineName
X-Node-App
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
X-Nginx-Page-Cache
X-FG-RequestId
X-JoinUs
X-Ssl-Cipher
Language
X-Healthy
X-Middleton-Pagespeed
Actual-Object-TTL
F5-IpCliente
X-Old-Content-Length
SERVER-NAME
X-NMT-Proxy
LB
X-Pageid
X-CAMPUSSUITE-TENANT
X-No-Session
X-Front-Cache
X-CSRF-Token
X-Fastly-Backend-Reqs
X-CAMPUSSUITE-ENVIRONMENT
X-Tradeindia-Request-GUID
X-Tradeindia-SMgmt
PagesDisplayed
V-Cache-Ttl
X-CAMPUSSUITE-DEBUGGING
X-Meta-Imagetoolbar
X-Expires
X-Magento-Route
X-Beresp-Ttl
X-TEST
RSL-Trace-ID
X-Time-Spent
Fastly-Drupal-Html
X-UT-Cache
X-SSLTerm-Server
X-Itkg-Cache-Tags
X-Country
X-SG-Server
Generate-Time
Prototype-RootPath
X-Accel-Cache-Control
EQ-Cache
X-Enabled3
PB-PID
Origin-Vm
PB-RID
PROGMA
X-InDy-Memory
X-Grid-Server
Amp-Access-Control-Allow-Source-Origin
X-Varnish-TTL-Debug
X-From-Cache
X-Cache-HT
X-GZip
X-Optimization
X-Varnish-Age-Debug
X-InDy-Query
X-InDy-Time
X-Cache-Id
Servername
X-Enabled1
X-Enabled2
X-Vid
Ews
ClientIP
X-Origin-Upstream-Status
X-Mobile-Rewrite
X-ORIGN-SERVER
X-Router
X-Telligent-Evolution
X-Appmachine-Name
X-CGP
Webserver
Web-Server
X-CloudBurst-WordPress
X-CloudBurst-Frontend
X-CloudBurst-Backend
X-CloudBurst-Cache
Unique-Request-Id
SBSS
X-Qiniu-Zone
X-Oracle-Dms-Rid
X-Server-Ip
X-Pagely-Cache
Requested-Host
X-Clx-Request
Sl-Pgid
X-UType
SS
X-VG-WebCache
XX
BlockPHPCallEnd
Backend-Powered-By
X-Rocket-Nginx-Reason
X-Rocket-Nginx-File
X-PressLabs-Stats
X-MSU-SOURCE
X-PoweredBy
X-Proxy-Id
X-Requested-With
X-Batcache-Reason
X-Log
X-Debug-Message
X-Mobile-Device
X-Az
X-Amz-Meta-Version-Id
X-Activity-Id
X-D2id
X-Mobile-Device-Type
X-UPSTREAM-Address
X-Cachable
X-Transaction-Name
X-BeResp-Ttl
X-Content-Type
X-SCProxy
X-HP-CAM-COLOR
X-SSL
HitInfo
X-Varnish-Cache-Control
X-Served-From
X-FastCGI-Cache
X-BIT-Node
X-VHosting-Cache
ID
X-Navigation-Version
X-OPNET-Transaction-Trace
X-Olaf
X-Cache-ID
X-Boot
Content-Sn
DB-Nickname
X-Abuse
X-Sn-Servicetimems
X-UPServer
X-Varnish-Cached
X-XHR-Current-Location
X-Varnish-Cached-TTL
X-ServiceProvider
X-Ruby-Cluster-ID
X-Homeaway-Requestmarker
X-HAProxy
X-Jcms-Ajax-Id
X-MCF-ID
X-NginX-Upstream
Xc
FastCGI-Cache
X-RequesterIP
MSThemeCompatible
StatusCode
X-Firewall
X-Hit
X-Cache-Via
MSSmartTagsPreventParsing
Httpd-Identifier
X-Zendesk-User-Id
EN-User
X-Zendesk-Origin-Server
CmsfirstPublishTimestamp
X-WA-Info
X-Fpc
X-SEA-Instance-Name
HA-Servedtime
HA-Ipaddr
HA-Urlpath
Arrow-RequestId
ModuleCacheType
L5d-Success-Class
HA-Host
HA-Georegion
HA-Geocity
HA-Cloudapp
HA-Geocountry
HA-Geolat
HA-Geolon
NKBVHEADER
Progma
X-Built-With
X-Render-Time
X-Dck
X-Built-By
X-Cdn-Origin
X-Ser
X-Bcwwwid
RN-Server
Request-Time
TYPO3-Pid
TYPO3-Sitename
X-B3-Sampled
X-Instance-Name