Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
X-AspNet-Version
Age
P3P
Content-Language
X-Pingback
Via
X-UA-Compatible
Upgrade
Expect-CT
Access-Control-Allow-Origin
X-Adblock-Key
Content-Security-Policy
X-Cacheable
X-Check
X-Template
X-Language
X-Varnish
Alt-Svc
X-Generator
X-Buckets
X-Drupal-Cache
P3p
X-Request-Id
X-Xss-Protection
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
Referrer-Policy
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Host-Header
Content-Location
MS-Author-Via
X-ShopId
X-Runtime
X-Sorting-Hat-ShopId
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId-Cached
X-Dc
X-Sorting-Hat-PodId
X-Sorting-Hat-PrivacyLevel
X-ShardId
X-Sorting-Hat-PodId-Cached
X-Alternate-Cache-Key
X-UA-Device
X-Powered-CMS
X-IPLB-Instance
X-Served-By
X-Sorting-Hat-FeatureSet
Cartoon
Access-Control-Allow-Methods
Access-Control-Allow-Headers
X-Amz-Cf-Id
X-Cache-Status
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
Status
X-Via
X-Request-ID
X-Iinfo
X-Wix-Server-Artifact-Id
X-Timer
X-TEC-API-VERSION
X-Accel-Buffering
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-ServedBy
X-Ua-Compatible
X-Contextid
CF-Cache-Status
X-PC-Key
X-PC-Hit
X-PC-Date
X-PC-AppVer
X-PC-Host
Powered-By
X-Mod-Pagespeed
X-Backend
X-CST
Content-Encoding
X-Host
X-WPE-Loopback-Upstream-Addr
X-Logged-In
X-Server
X-CDN
X-DIS-Request-ID
Keep-Alive
X-Rid
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Cache-Hit
X-Port
X-Cache-Enabled
X-Endurance-Cache-Level
X-Server-Powered-By
X-Tumblr-Pixel-1
X-Original-Date
X-Accel-Version
X-Nginx-Cache-Status
X-Robots-Tag
X-NewRelic-App-Data
X-Drupal-Dynamic-Cache
X-Page-Speed
X-Tumblr-Pixel-2
X-Wix-Request-Id
X-Seen-By
X-Turbo-Charged-By
X-Wix-Punisher
X-Content-Powered-By
X-Proxy-Cache
X-Forwarded-For
X-Content-Digest
X-AH-Environment
X-Forwarded-Proto
X-Pad
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Varnish-Cache
X-Rack-Cache
WP-Super-Cache
X-LiteSpeed-Cache
Content-Security-Policy-Report-Only
X-Tumblr-Pixel-3
X-GitHub-Request-Id
X-Request-Country
SPRequestGuid
Edge-Control
X-MS-InvokeApp
X-XRDS-Location
X-SharePointHealthScore
MicrosoftSharePointTeamServices
X-Cache-Lookup
Timing-Allow-Origin
X-Cnection
X-Node
X-Content-Security-Policy
X-FW-Hash
X-Amz-Request-Id
X-FullPageCaching
X-Amz-Id-2
Cf-Railgun
Charset
X-FW-Serve
X-FW-Type
X-FW-Static
X-Trace
Request-Id
X-Webcom-Cache-Status
X-Died
X-PhApp
Edge-Cache-Tag
Request-Context
X-BC-Stapler
X-HS-Cache-Config
X-Hits
X-HS-Content-Id
X-CF-Powered-By
SPIisLatency
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
SPRequestDuration
MicrosoftOfficeWebServer
X-Webserver
Access-Control-Expose-Headers
Access-Control-Max-Age
Composed-By
X-Newrelic-App-Data
X-Safe-Firewall
Grace
EagleId
X-Swift-SaveTime
X-Swift-CacheTime
Served-By
X-Spip-Cache
X-CDN-Pop
X-CDN-Pop-IP
X-Fastly-Request-ID
X-Firenze-Processing-Times
X-Hyper-Cache
X-VCache
Liferay-Portal
X-Backend-Server
X-Tumblr-Pixel-4
X-Dw-Request-Base-Id
X-Server-Name
X-Device
X-SERVER
X-FB-Debug
X-Microcache
X-StackifyID
Surrogate-Control
X-LiteSpeed-Cache-Control
Refresh
X-SS-Conf
X-SS-Location
Front-End-Https
X-Cloud-Trace-Context
X-RateLimit-Remaining
X-TNCMS
X-Loop
X-Clacks-Overhead
X-RateLimit-Limit
Xkey
X-RateLimit-Reset
Content-Style-Type
Rating
X-DNS-Prefetch-Control
Public-Key-Pins
X-Jimdo-Instance
X-Jimdo-Wid
Content-Script-Type
X-Acc-Exp
X-XN-Trace-Token
X-XN-XNHTML
X-HS-Combine-CSS
X-DDC-Arch-Trace
X-User-Agent
X-WebKit-CSP
X-Cache-Config
X-Age
X-Vtex-Processado-Em
Fpc-Cache-Id
X-Dscp-Value
X-ServerName
X-Hostname
X-Middleton-Display
Display
X-Middleton-Response
X-Sol
Response
X-Px
X-N-OperationId
X-Generated-By
X-Topify-Platform
X-Cached
X-Tumblr-Content-Rating
X-Tumblr-Pixel-5
X-Correlation-Id
X-Url
X-MiniProfiler-Ids
X-Zen-Fury
X-Request-Time
X-Magento-Tags
P-LB
P-WS
X-Kinsta-Cache
X-Handled-By
TCN
X-OneAgent-JS-Injection
X-Outils-CS
X-CMS-Version
X-Whom
X-Amz-Version-Id
X-Loopia-Node
Edge-Control-Message
X-B-Cache
X-DynaTrace
PageSpeed
X-Debug-Info
Rt-Fastcgi-Cache
X-Content-Options
ServedBy
Dmn
Access-Control-Request-Method
X-URL
X-Cached-By
X-Edge-Location
X-DynaTrace-JS-Agent
X-From
X-Msg-2-Log
X-Varnish-TTL
X-LBLID
X-Ruxit-JS-Agent
Public-Key-Pins-Report-Only
Imagetoolbar
Product
X-Upstream
Host
X-Location-Id
X-Goog-Hash
X-Varnish-Cache-Hits
Surrogate-Key
Fhost
X-FORWARDED-FOR
X-Cluster-Node
X-AspNetWebPages-Version
X-Cache-Rule
Powered
Retry-After
X-Engine
X-Signature
X-Shard
DynaTrace
X-F-Cache
X-CacheServer
X-Via-JSL
X-Fastcgi-Cache
X-Accel-Expires
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Platform-Router
X-Platform-Processor
X-Actual-URL
X-Original-Request
X-Returned-From
X-Passed-To-DLL
X-Returned-From-DLL
X-Passed-To
Alternate-Protocol
X-Platform
X-Platform-Cluster
X-NWS-LOG-UUID
No
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processed-At
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Passed-To-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Micro-Cache
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Umbraco-Version
X-LW-Cache
X-Stale
X-Recruiting
X-Art-Request-Id
Arr-Disable-Session-Affinity
X-Magento-Cache-Debug
X-Application-Context
X-Version
X-Varnish-Host
X-Cache-Info
X-Source
X-Developer
X-Hosted-By
X-Device-Type
X-Rnd
Ohc-File-Size
X-Response-Time
X-UD-Method
X-HS-Content-Campaign-Id
Fastcgi-Cache
X-URLSCHEME
X-Rocket-Nginx-Bypass
X-S
X-Matrix-Proxy
X-Microcachable
X-Supported-By
Cache-Provider
X-PERF
Pagespeed
X-ApacheServer
Origin
X-Matrix-Server
Generator
X-Powered-By-360WZB
WZWS-RAY
X-Instart-Request-ID
Akamai-IP
X-Defender
X-EdgeConnect-Origin-MEX-Latency
X-Cdn
X-Shop-Id
X-TransIP-Balancer
X-App-Status
X-I-Sp
X-Frame-Option
X-BS
X-Gamma-Serve
Last-Published
X-Tumblr-Pixel-6
X-TransIP-Backend
X-Server-ID
X-Microcache-Status
X-Platform-Server
X-Translation
X-RESOURCE
X-HOST
X-Cache-TTL
X-Storage
Version
X-Platform-Cache
X-Varnish-Count
X-Cache-Namespace
X-Varnish-HitMiss
Content-Hash
X-Flow-Powered
X-Hypernode
X-Daa-Tunnel
X-App-Hosting
X-Track
X-Cache-Age
HTTPS
X-Front
X-Cache-Key
X-Sapient
X-Powered-By-VelaWeb
X-NetCat-Version
X-Drupal-Cache-Tags
USPLoggingUUID
X-Route-Server
X-ATG-Version
RTSS
Powered-By-ChinaCache
Surrogate-Key-Raw
X-Pantheon-Phpreq
X-Pantheon-Environment
X-Pantheon-Site
Pool
X-EdgeConnect-MidMile-RTT
X-Expires-Orig
X-WebServer
ServerID
X-Varnish-RemainingLife
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-Dispatcher
X-Varnish-RemainingTTL
X-Varnish-Seen-By
X-ORACLE-DMS-ECID
X-Firenze-Processing-Time
X-Powered-By-VTEX-Janus-Edge
Allow
X-Cache-Tags
Cache-Key
X-Duration
X-SV-Nginx-Duration
X-SV-FromDBCache
X-SV-Pid
Lsrequestid
X-I
X-SV-Edge
MIME-Version
X-SV-Duration
X-SV-CreatedAt
X-Last-Modified
X-Cache-Operation
X-Vcache
X-Director
X-Content-Encoded-By
Content-Disposition
X-CSRF-Protection
X-Page-Cache
X-Ezoic-Cdn
X-SV-CacheTags
X-Cache-Debug
X-SV-Expires
X-SV-Cacheable
Cneonction
X-SDS
X-Drupal-Cache-Contexts
X-SSL-Cipher
SSPAppContext
X-Ttl
X-Server-Upstream
X-Vcap-Request-Id
S-Cnection
X-SSL-Protocol
X-Varnish-Age
X-Generated
X-Grace
X-Environment
NnCoection
X-Litespeed-Cache
AMF-Ver
X-Client-IP
Pv
SN
X-Magento-Cache-Control
X-Time
Accept-Encoding
X-Cache-Control-Orig
X-Cache-Server
X-Lambda-Id
X-Abgroup
X-CJ-Soft
X-IsCacheURL
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
FAI-W-FLOW
Section-Io-Id
X-Debug
X-Server-Id
X-Revision
X-Edge-IP
X-NoCache
IBM-Web2-Location
Wsr-Cache
X-Gateway-Cache-Key
X-Varnish-Cacheable
X-Varnish-Ttl
X-Varnish-Url
X-Hiawatha-Cache
X-ARC
X-Origin
Node
X-LB-Node
ServerName
Server-Timing
X-Amz-Meta-S3cmd-Attrs
Req-Id
X-PwB-Node
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Srv
Fw-Via
X-Cache-Expires
X-N
X-TTL
Page-Completion-Status
X-UPSTREAM
X-Bb-Deploy-Id
X-Akamai-Device-Characteristics
X-Magnolia-Registration
X-ORACLE-DMS-RID
X-Cache-Lifetime
Content-MD5
Backend
Location
X-LB
Server-Name
X-ID
X-Yadis-Location
X-Oneagent-Js-Injection
Server-Info
X-Runtime-Rack
X-WEBSERVER
X-Cache-Type
X-Esi
X-Amz-Storage-Class
Content-Encoding-Handler
X-App-Server
X-Cache-Engine
X-Content-Age
Content-Transfer-Encoding
X-Dispatch
X-SO
X-Geo-Country
IM-Version
X-Real-Server
X-GeoIP-Country-Code
X-Redman-Backend
X-Discourse-Route
X-Cache-Only-Varnish
Fastly-Debug-Digest
X-Redman-Final-Url
Front
X-AVG-Country-Code
X-Frontend
X-Vhost
Proxy-Connection
X-Avg-Cookie-Expires
X-Akamai-Device-Model
X-Akamai-Edgescape
X-AOL-HN
X-Varnish-Backend
X-BackendServer
X-RequestId
If-Modified-Since
X-Config-Blacklist-Version
X-ServerID
X-FTR-Request-ID
X-Varnish-IP
X-Country-Code
PICS-Label
S
Nodo
X-Middleware-Start
X-Content-Security-Policy-Report-Only
Accept-Charset
X-Cache-Level
X-Varnish-Retries
X-Always-Cache
Nitro-Cache
W
Pf.Web.Request.Id
X-High-Performance
X-Pressidium-NinukisWP-Ver
X-Processing-Time
Frame-Options
X-Speed-Cache-Key
X-Speed-Cache
X-CF-Passed-Proto
X-Cache-Handler
X-Cache-Device-Type
HCVer
HAVer
Qs-Cache
Author
X-Url-Base
X-Sucuri-ID
X-Cache-Fix
X-VARITI-CCR
Cache
X-Worker
X-Nbs
X-HTML-Minification-Powered-By
Eomportal-Instance
X-Cache-PageType
X-SRV
Use-Proxy
X-PF-Uncompressing
SRV
Cached
X-BKSrc
X-Purge-URL
X-DealerOn
WWW-Authenticate
X-Empowered-By
X-Dealeron-Backend
X-Purge-Host
X-Dealeron-Original-Url
X-GeoIP-Country-Name
X-Cookie-Domain
CacheControlHeader
X-Location
Environment
X-Rocket-Nginx-Serving-Static
Cache-Tags
X-Nginx-Cache
X-Proxy
X-Stage
X-Rq
X-Browser
X-Server-Instance
X-FW
X-AF-Userserver
X-SRCache-Key
X-Content-Type-Option
Xc-Version
X-Env
VANITY-HOST
BALANCEDTO
Thanks
X-Cache-CFC
X-Resource
MC
X-Airee-Node
X-Dynatrace-Js-Agent
Adm-Server
X-Unbounce-PageId
X-Unbounce-Variant
X-Unbounce-VisitorID
X-Client-Vid
X-EPiphany-Vid
X-Client-Image-Vid
X-Garden-Version
Contao-Page-Layout
Cache-Tag
X-Correlation-ID
X-Ruxit-Js-Agent
X-Shield-Request-Id
X-Litespeed-Cache-Control
Pics-Label
Local-Info
X-Varnish-Server
X-Symfony-Cache
X-Sucuri-Cache
X-WPL-DATA
Custom-Header
Tracecode
Cm-Server
X-HW
X-Id
X-Source-ID
X-Remote-Addr
Smug-CDN
X-Srv
From-Origin
X-CB-Server
X-SmugMug-Values
X-TTFB
X-SmugMug-Hiring
X-TTFB-L
X-Akamai-3PM-SW-Version
X-WR-Flags
X-Akam-SW-Version
X-CDN-Forward
X-CAPServer
X-WebKit-CSP-Report-Only
IISExport
NtCoent-Length
X-Varnish-Hostname
X-Server-IP
X-Hit-Cache
X-Pagename
X-Akamai-Transformed
X-Framework
X-Cache-Control
X-Session-Reinit
NetMindSessionID
X-HydroSheep
MJ12bot
X-Cache-Dispatchercachecontrol
X-Cacheable-TTL
X-NginX-Cache
X-Atraveo-TTL
X-Omnis-SiteID
Machine
X-Abuse
SEOMOZ
X-Cache-Dispatcherpragma
X-Atraveo-Param-Rm
X-ClientSide-Caching
X-Real-IP
X-Runtime-Memory
X-Atraveo-Set-Cookie
Identity
X-Drectory-Script
X-ACMCache
X-Compress-Hint
X-WP
X-Atraveo-ETag
X-Atraveo-Cache-Control
X-JG-Page-Cache
Proxy-Agent
X-Atraveo-Varnish-Server-Id
X-Atraveo-Zone
X-Atraveo-From-Varnish-Cache
X-Page
X-Atraveo-Expires
Ufe-Result
X-Smartcache-Keys
X-Time-Microsecs
X-Smartcache-Timeout
Cmsid
Cmstype
X-IIJ-Cache
SVR
X-OpenCart-Lightning
X-Provisioner-Version
X-SmartBan-Host
X-FW-Server
X-SmartBan-URL
X-Highwire-SessionId
X-Info
Accept-CH
RN-Server
X-Trace-Id
X-App
X-Highwire-RequestId
X-LW-Web-Server
X-Adobe-Loc
X-LP
X-Directory-Script
X-Domain-Checked
Beyond-Iis
X-Adobe-Content
Access-Control-Allow-Method
Id
X-PRAM
X-Nginx-Host
X-WA-Info
X-Force
X-IP
NLCacheNote
Bios
X-Plat
Content_type
EagleEye-TraceId
X-RealServer
Ohc-Response-Time
X-ASAP-Cache
X-NodeID
X-CACHE-TTL
X-Mobilized-By
Accept-Language
Keywords
X-Secret
X-SERVER-NAME
X-Sites
X-Fedora-School-Id
X-Resty-Request-Id
Description
X-Resolver-IP
X-Adnet
X-WN-ClientGroup
X-Sys-Req-ID
ServerTokens
X-VC-Enabled
SERVER-ID
A-Powered-By
WN
X-Dns-Prefetch-Control
HitType
ServerSignature
X-Clara-ASAP
Hummingbird-Cache
Service-Worker-Allowed
X-Cache-Node
Backend-Timing
X-W3TC-Minify
X-Fstrz
X-Ser
X-Orig-Vary
X-FPC
X-Analytics
X-Request-Uri
X-Blog
X-RTag
X-DTC
X-Cache-Doesi
X-LB-Server
X-Locale
SS
X-Refresh
X-GeoIP
AC-ELC
X-Backend-Status
VServer
X-Session-ID
X-Yottaa-Metrics
Fastly-Backend-Name
X-Twitter-Response-Tags
From
X-Search-Id
X-Transaction
X-FORWARDED-PROTO
X-GoCache-CacheStatus
X-Cache-Varnish
X-Connection-Hash
X-Captured
Url
Yoncu-Errno
X-Cf-Powered-By
X-VC-TTL
X-Route-To
X-EC2-Instance-Id
X-Rewritten-By
X-ServerIndex
Web-App-Origin-Name
X-TB-M
X-Webstats-RespID
X-Unique-ID
X-Traffic
NODE
X-ACCELERATE
X-Yottaa-Optimizations
X-AEM
X-Server-Addr
X-ManagedFusion-Rewriter-Version
X-Batcache
X-MCB-Server
X-Autoru-LB
X-Layout
X-Map-Context
X-CRA-DC
X-Cache-On
X-Autoru-Host
SHInfo
X-Proxy-Cache-Key
X-RDP
X-Powered-By-Home.Pl
X-Protected-By
X-Response
X-Redirector
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-AutoRu-App-Id
X-4ormat-Cacheable
Max-Age
Hamster
X-DataDome
Swift-Performance
Access-Control-Allow-Header
X-Agent
Home
Ibf5scheme
SG
X-Key
X-Varnish-Debug-Age
N365rili
X-Varnish-Debug-TTL
X-Viator-Tapersistentcookie
TheAnswer
X-Debug-Token
X-Node-Name
X-Origin-Server
Play-Detected-UserAgent
Play-Detected-Device
X-Title
X-Req-Head-Response
X-BPool
X-BPool-Back
X-Cache-Via
X-Distil-CS
X-RiS-UFDI
X-Cocoon-Version
X-Varnish-Id
SBGI-Device
SBGI-9
Xc
SBGI-RealPath
SBGI-RenderTime
SBGI-7
SBGI-5
X-Culture
X-Cache-TTL-Current
X-Webkit-CSP
SBGI-1
SBGI-10
ScoreTracker
X-BPool-Bx-Cache
X-Depends
Report-To
RequestId
Gzip
Disablevcache
F5-IpCliente
ClientIP
X-Cache-TTL-Age
X-Webcelerate
Myheader
X-Machine
X-Gannett-Site-Version
Edit
X-Disney-Akamai-Rule
X-BServer
Resin-Trace
X-BPool-Fx-Cache
X-CacheID
X-FireWall-Port
X-PROCESSED-BY
X-Src-Webcache
EN-User
Og
X-ARRServer
X-NginX-Server
Magicmarker
X-Grid-Server
AMP-Access-Control-Allow-Source-Origin
Ram
Noq
X-Batcache-Reason
Ramp
SiteSpeed
X-Middleton-Pagespeed
X-Jphone-Copyright
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Highwire-Smart-Code
X-Highwire-Sitecode
Dis-Env
X-Cdn-Forward
X-DEBUG
X-Detected-Device
X-Varnish-ID
X-Serv
X-Pagely-Cache
Device
X-Amz-Meta-Cb-Modifiedtime
X-SDE-Name
X-Role
X-Rack-Cors
X-Forwarded-Host
Ctx
X-V
Lb
NZSpeedy
X-A
X-Hosting-Env
X-Distributor
XDomainRequestAllowed
Web
X-Balanceador
Server-ID
DrivedBy
Hostname
Language
Www.Aujourdhui.Com
X-Node-Id
CLMOB
X-Amz-Meta-Content-Md5
X-Varnish-Cache-Ttl
X-Cjtype
X-XHTML-Minification-Powered-By
X-Old-Content-Length
X-JSESSIONID
X-Confluence-Request-Time
OracleCommerceCloud-Version
OracleCommerceCloud-Sandiego
X-E
X-Ghost-Cache-Status
X-Rewrite
X-Origin-Id
X-GSL-Server
CommercePlatform-Version
BackendServer
X-Runtime-Affili
X-Hosting
X-Header
X-Wikidot-Backend
X-Wikidot-Static-Cache
Backend-Name
Backend-IP-Port
X-Zendesk-Origin-Server
X-Zendesk-User-Id
X-Skip-Cache
X-Proxy-Skip
X-MAT-GEO
Warning
X-MidCOM-Meta-Cache
Prama
X-Varnish-Action
X-Geo-IP
X-Desc
SINA-TS
SINA-LB
Apachenode
X-Dw-Trace-Id
X-SH-Cache-Status
Paypal-Debug-Id
Edgecast
X-DynamicCache
X-Compressed-By
X-Gyrobase-Publication
X-Generated-Time
X-Frames-Options
X-Svr
X-Varnish-Cache-Local
ID
Content-Generator
X-Varnish-Hits
X-DN-Cache-Control
X-DB-Content-Length
Proxy-Cache
MW-Webserver
Il-Cl
TZ-Server
X-Aramark-SID
X-Cluster
X-B2f-Not-Route
NS-VaryByCustom-Key
OriginServer
X-Amcomm-Site
MS-CV
X-Rack-CORS
X-Amz-Id-1
X-App-Runtime
X-CacheDebug
X-Cache-Me-Harder
X-OPNET-Transaction-Trace
X-HashTwo
Upgrade-Insecure-Requests
Traffic-Origin
PagesDisplayed
X-Cache-Time
X-Data-Request
X-Goog-Meta-Replace
X-Goog-Meta-Policy
COMMERCE-SERVER-SOFTWARE
X-FG-RequestId
X-Varnish-Cached
X-Varnish-Cached-TTL
X-Mobile-URL
X-Bip
X-Config-By
X-ServerAddr
X-UPServer
Nginx-Cache
MSSmartTagsPreventParsing
X-Acquia-Debug-Password
Cteonnt-Length
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
Progma
X-HP-Trace-Project
MSThemeCompatible
Server-Ip
X-Script
X-VNode
X-Processed-By
X-S-Misc
X-Proxy-Id
Cleartype
Dispatcher
X-ServiceProvider
X-Streams-Distribution
XX
X-PHP-Response-Code
X-Bcwwwid
X-Built-With
X-MCF-ID
X-D-Time
X-Generation-Time
X-Nitro-Cache
X-HAProxy
Kanooh-Host
X-Application
X-ReqId
X-SilverStripe-Cache
X-SCM-Server-Number
X-Enhanced-By
X-Nginx-Request-Processing-Time
X-DS1D
X-Render-Time
X-Meta-MSThemeCompatible
X-Actindo-Rs
X-Actindo-Thread-Id
X-AMAZEEIO
X-Actindo-Request-Id
Provider
X-ASAP-Age
SB-Site-IE-VERSION
AsisCache
X-Artvisual-Server
X-ESI
X-Who
X-Proto
X-ZSITES-DNS
X-Varnish-Grace
Page-Template
Actual-Object-TTL
SB-Site-Device
SB-Cache-Remaining
SB-Cache-Life
X-UnsetCookies
X-HP-Trace-ID
MyHeader
Worker
X-Cache-Detail
X-HS-Status
X-Cms-Mode
X-AISO-Server
X-Sid
TP-L2-Cache
X-Upgrade-Enabled
X-Client-Ip
X-Lb
TP-Cache
X-AISO-Cache
VC-NoCache
X-LBPoolMember
X-AISO-Cacheable
X-Reflector
X-Reflector-Cache
X-Dev
X-Magento-Action
Strikingly-Cache-Region
Strikingly-Cached
Strikingly-Cached-Version
Ttl
Ews
X-PM-ID
X-CacheResult
PServer
X-NID
X-Origin-Cache
X-Author
Aoestatic
Viewport
X-Tag-Playlist
X-Magento-Lifetime
X-WebNode
X-Via-NSCOPI
X-PoweredBy
X-Qnm-Cache
Fastly-Restarts
X-MSU-SOURCE
X-Qiniu-Zone
X-Phpwcms-Page-Processed-In
FRONT-END-SECUREBROWSER
X-SE-Debug
X-Phpwcms-Release
X-Uncacheable
X-REDIRECTSERVER
X-VG-WebCache
BlockPHPCallEnd
DB-Nickname
X-SSLProxy
X-SSLUpstream
X-UType
X-UPSTREAM-Address
X-Svr-Proxy
X-SuperCache
X-Backend-Host
X-M-Reqid
X-Cache-Extended
Requested-Host
X-7d-Instance-Id
Unique-Request-Id
X-M-Log
X-Log
X-KoobooCMS-Version
X-Hstore
X-Hrouter
X-7d-Trace-Id
X-CACHE-KEY
X-Distributed-By
X-Hash
X-VTEX-Cache-Status-Janus-Edge
HA-Cloudapp
X-Box
X-DDM-SERVER-UPDATED
X-Clx-Request
X-DDM-SERVER
X-Reqid
X-Avvio-Cms-Cacheload
X-Sn-Servicetimems
X-RequesterIP
X-RemovedCookies
X-ProcessESI
X-Original-IP
X-SATserver
X-TA-CDN-Provider
X-Cache-Ttl
X-Ants-Machine-Id
X-Ants-Host
CDCHOST
X-Obvious-Tid
X-Obvious-Info
Request-Country
Dtk-Cache-Check-0
X-SV
X-Server-Generated
Request-EU
Tk
X-Instance
X-Feed
WSCLoggingUUID
X-COUNTRY-CODE
X-Custom-Name
X-Global-Transaction-ID
X-Flex-Tags
X-Flex-Tag
X-Flex-Lastmod
X-Max-Age
X-Nginx
X-We-Are-Hiring
X-Profiler
X-PressLabs-Stats
X-Pool
X-Flex-Lang
X-Flex-Evstart
V-TTL
HSTS
X-Test-Debug
X-Pubstack
X-Backside-Transport
X-CD
X-Flex-Evend
X-Flex-Community
X-Device-Item
X-Dynamic-Cache
WP-FROM-CACHE
X-B3-Traceid
X-B3-Spanid
X-AWS
NKBVHEADER
X-CGP
X-Fpc
X-Member
X-Jcms-Ajax-Id
X-Homeaway-Requestmarker
X-FreeTag-Count
Load-Balancer
L5d-Success-Class
HA-Georegion
HA-Geolon
HA-Geolat
HA-Geocountry
HA-Host
HA-Ipaddr
IES-Server
HA-Urlpath
HA-Servedtime
X-OCTOPOD
X-OpenUrlRewriter-Debug
X-Unique-Id
X-Node-App
X-Hit
X-CO-Host
CS-SERVER
Debug-Status
Session-From
ServerIP
Expiries
X-Cache-Bypass
TC-S-Cache-M
Xcache
X-XHR-Current-Location
X-PBS-Fwsrvname
X-PG
Response-Time
TC-Cache
TC-S-Cache
TC-Cache-U
TC-Cache-IC
HA-Geocity
Provided-Host
HostName
GranicusServer
EQ-Cache
X-Sentry-ID
RSB-LINK
X-Cache-ID
X-Beatles
X-Apm-Telemetry-Syncmark
X-Server-Hostname
Be
X-Shopware-Allow-Nocache
X-Served-Server
X-Route
X-Shopware-Cache-Id
X-WHOIS-Cached
X-VCS-Ttl
X-VCS-Cacheable
X-Cname-TryFiles
X-CSRF-Token
X-Made-On
X-M
X-Header-Treatment
Rewriter
X-Pj-Cache-Status
No-Cache
X-Sorting-Hat-Expire-Cache
X-Served
X-HEAD
UrlWatchModule-Time
X-ETag
X-Deity
X-Debug-Token-Link
X-Gateway-Rate-Limit-Conn
X-Gateway-Rate-Limit-Delayed
Webserver
X-AppServer-Cache-Rule
X-Pixelsilk-Version
X-Pixelsilk-Server
X-VC-Cache
X-Static
Container
X-VC-Cacheable
X-VC-Debug
StatusCode
X-Instance-Name
X-VC-Hash
MachineName
MwpReleaseVersion
X-PBY
X-Site
X-Ssl-Cipher
X-Pass-Through
X-Timestamp
X-NMT-Proxy
X-Status
Cacheid
CpuTime
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
X-Custom-Header
X-BackendProxy
X-Full-Url
Amp-Access-Control-Allow-Source-Origin
Cache-Status
X-ClusterID
X-Cache-Original-TTL
User-Agent
Server-Id
Httpd-Identifier
V-Age
X-Ab-Selection
X-Cache-Id
X-ACLR-Version
X-Varnish-Debug-Hits
1A-CountryCode
X-CH-Device
X-Beresp-Ttl
RSL-Trace-ID
X-Country
X-FIRSTBase
X-IP-Address
X-Instart-Cache-Id
X-Front-Cache
Referer
DeleGate-Ver
X-UT-Cache
X-UA
X-T
Amfplus-Ver
CommunityServer
HA-Front
Copyright
X-Litespeed-Tag
X-Pageid
X-HP-CAM-COLOR
X-Healthy
X-Container
X-Instance-Id
X-MyName
X-PBS-Appsvrip
X-Nginx-Request-Time
X-NewsFlow-Sitename
X-Catalyst
X-Cache-FS-Status
X-Transaction-Name
X-RAMCache
X-Pool-Info
XDisk
ProxiaInstanceId
Session-Id
ReqUrl
X-Serverid
X-SayCDN-TTL
MageStack-Magento-Version
MageStack-Loadbalancer
MageStack-Debug
MageStack-PageSpeed
MageStack-Tag
Content-Cache
DbServerName
MageStack-Web-Node
MageStack-Config
MageStack-Cacheable
MageStack-Area
IsMobile
Generate-Time
MageStack-Cache
MageStack-Cache-Hits
MageStack-Cache-Status
MageStack-Cache-Lifetime
Request-Filtered-By
CD4
X-NewCloud-V-Cache
X-HA
X-FastCGI-Cache-Status
X-Ocache
X-ProBase-Server
X-Say-TTL
X-Say-Cacheable
X-Debug-Message
X-BP-NSA-REQID
X-Amz-Meta-Version-Id
X-Activity-Id
Tesla.Performance
X-AppVersion
X-Az
X-Backend-TTL
X-B
X-PBS-Appsvrname