Threat Level: green Handler on Duty: Pasquale Stirparo

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Set-Cookie
Server
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
P3P
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
X-Xss-Protection
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Varnish
Referrer-Policy
X-Request-Id
X-Adblock-Key
X-Check
X-Generator
X-Language
X-Template
X-Type
X-Cache-Group
X-Pass-Why
X-Buckets
X-Drupal-Cache
WPE-Backend
X-Permitted-Cross-Domain-Policies
Alt-Svc
X-Download-Options
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Ac
X-Hacker
Host-Header
X-Cache-Hits
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-AspNetMvc-Version
X-ShopId
X-Sorting-Hat-FeatureSet
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId-Cached
X-Via
X-Runtime
X-Powered-By-Plesk
X-Served-By
X-Contextid
P3p
X-PC-Key
X-PC-Hit
X-Amz-Cf-Id
X-UA-Device
X-PC-AppVer
MS-Author-Via
X-ServedBy
Content-Location
X-PC-Host
X-PC-Date
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-IPLB-Instance
X-Timer
X-Wix-Request-Id
X-Seen-By
Status
X-Rid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Ua-Compatible
CF-Cache-Status
X-Tumblr-Pixel-1
Cartoon
X-Iinfo
Access-Control-Allow-Credentials
X-Tumblr-Pixel-2
X-Backend
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
Content-Encoding
X-CST
Powered-By
X-Host
X-Endurance-Cache-Level
X-Mod-Pagespeed
X-Cache-Enabled
X-Cache-Hit
X-Port
X-FRAME-OPTIONS
X-NewRelic-App-Data
X-CDN
X-Tumblr-Pixel-3
X-Logged-In
X-Newrelic-App-Data
Keep-Alive
X-Server-Powered-By
X-DIS-Request-ID
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server
X-Robots-Tag
X-Accel-Version
X-Request-ID
X-Turbo-Charged-By
X-Proxy-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Page-Speed
X-Content-Powered-By
X-LiteSpeed-Cache
X-GitHub-Request-Id
X-Content-Digest
Content-Security-Policy-Report-Only
X-Rack-Cache
X-AH-Environment
X-FW-Hash
X-Tumblr-Pixel-4
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Type
X-Pad
Request-Context
X-Varnish-Cache
X-Hits
Edge-Control
X-Webcom-Cache-Status
X-Request-Country
X-XRDS-Location
X-Trace
SPRequestGuid
Access-Control-Expose-Headers
X-MS-InvokeApp
X-SharePointHealthScore
X-BC-Stapler
X-Node
WP-Super-Cache
Cf-Railgun
MicrosoftSharePointTeamServices
Edge-Cache-Tag
X-HS-Cache-Config
X-HS-Content-Id
X-Amz-Request-Id
X-Amz-Id-2
X-CF-Powered-By
Charset
X-HS-Combine-CSS
Timing-Allow-Origin
X-SERVER
X-Died
X-Content-Security-Policy
X-FullPageCaching
X-Webserver
X-Cache-Lookup
X-Fastly-Request-ID
X-PHP-Backend
X-INKT-SITE
X-INKT-URI
X-PhApp
X-Cnection
Request-Id
Access-Control-Max-Age
X-Backend-Server
SPIisLatency
SPRequestDuration
X-Edge-Cache
X-Edge-Cache-Key
MicrosoftOfficeWebServer
CONTENT-SECURITY-POLICY
EagleId
X-Servedby
X-CDN-Pop-IP
X-CDN-Pop
X-Swift-SaveTime
X-Swift-CacheTime
Rating
Composed-By
X-SS-Location
X-SS-Conf
X-Tumblr-Pixel-5
X-Server-Name
Grace
X-Device
X-Tumblr-Content-Rating
Liferay-Portal
X-NF-Request-ID
X-DDC-Arch-Trace
Ali-Swift-Global-Savetime
Served-By
X-Safe-Firewall
X-Dw-Request-Base-Id
X-Spip-Cache
X-Hyper-Cache
X-Cloud-Trace-Context
Front-End-Https
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-HeyJason
X-VCache
X-Microcache
P-WS
P-LB
X-Original-Date
Surrogate-Control
X-Firenze-Processing-Times
X-LiteSpeed-Cache-Control
X-Cluster-Node
X-RateLimit-Remaining
X-RateLimit-Limit
X-OneAgent-JS-Injection
X-Loop
X-TNCMS
X-Clacks-Overhead
X-StackifyID
X-RateLimit-Reset
X-Acc-Exp
X-Jimdo-Wid
X-Jimdo-Instance
X-Kinsta-Cache
X-HOST
X-FB-Debug
Content-Style-Type
Display
X-Middleton-Display
X-Sol
Content-Script-Type
Response
X-Middleton-Response
X-Wix-Punisher
Public-Key-Pins
X-Debug-Info
X-Vtex-Processado-Em
X-DNS-Prefetch-Control
X-Age
X-Tumblr-Pixel-6
X-Shopid
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Podid
X-Sorting-Hat-Featureset
X-Shardid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid-Cached
X-Amz-Version-Id
X-User-Agent
X-Magento-Tags
X-Ruxit-JS-Agent
X-DynaTrace-JS-Agent
X-XN-Trace-Token
X-XN-XNHTML
Fpc-Cache-Id
X-Url
X-Zen-Fury
X-Px
X-LW-Cache
X-Cache-Config
X-Cached
X-Goog-Hash
X-WebKit-CSP
X-N-OperationId
X-Hostname
Wpe-Backend
PageSpeed
X-Version
Feature-Policy
Retry-After
Xkey
X-Generated-By
X-Topify-Platform
X-Upstream
Refresh
X-Frame-Option
X-Edge-Location
Rt-Fastcgi-Cache
X-Handled-By
X-FORWARDED-FOR
X-Loopia-Node
X-Goog-Generation
TCN
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Allow
Access-Control-Request-Method
X-Source
X-MiniProfiler-Ids
Fastcgi-Cache
X-Request-Time
X-Whom
X-B-Cache
X-SRCache-Store-Status
X-Cached-By
X-SRCache-Fetch-Status
X-EdgeConnect-Origin-MEX-Latency
Product
X-CMS-Version
X-ET-API-VERSION
X-ET-API-ROOT
X-ET-API-ORIGIN
X-URLSCHEME
X-Platform-Router
X-Accel-Expires
X-Platform-Cluster
X-Platform-Processor
X-Fastcgi-Cache
X-EdgeConnect-MidMile-RTT
Powered
X-From
X-RESOURCE
ServedBy
X-Varnish-Host
X-Content-Options
X-AspNetWebPages-Version
Last-Published
X-Outils-CS
Public-Key-Pins-Report-Only
X-Varnish-HitMiss
X-Varnish-Count
X-DynaTrace
X-Magento-Cache-Debug
X-Guploader-Uploadid
X-Engine
X-Tec-Api-Origin
X-Platform-Server
X-Application-Context
X-Tec-Api-Root
X-Varnish-Cache-Hits
X-Cache-Info
X-Tec-Api-Version
X-CacheServer
No
X-Vtex-Remote-Cache
Warning
X-Powered-By-VTEX-Janus-ApiCache
X-Vtex-Processed-At
X-VTEX-Cache-Status-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
Imagetoolbar
X-Location-Id
X-Signature
Fhost
X-UD-Method
X-Device-Type
Generator
X-NWS-LOG-UUID
X-Response-Time
X-S
X-Developer
Host
X-Microcachable
X-Umbraco-Version
Dmn
Cache-Provider
X-PERF
X-ApacheServer
X-Platform
X-Cache-Key
X-HS-Content-Campaign-Id
Alternate-Protocol
X-Returned-From
X-Returned-From-DLL
X-Passed-To-DLL
Pagespeed
X-Passed-To
X-Original-Request
X-Actual-URL
X-Shop-Id
X-Defender
Cache-Key
X-F-Cache
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Msg-2-Log
X-ARC
X-Varnish-Beresp-Grace
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Passed-To-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Recruiting
Origin
X-Stale
X-Cache-Rule
X-Micro-Cache
X-LBLID
X-Ezoic-Cdn
DynaTrace
X-Hosted-By
X-Dns-Prefetch-Control
X-Translation
X-Microcache-Status
Version
X-Platform-Cache
Surrogate-Key
Content-Hash
X-Lambda-Id
Akamai-IP
X-Rnd
MIME-Version
X-I-Sp
X-SSLProxy
X-SO
X-BS
X-SSLUpstream
X-Cache-Tags
X-Via-JSL
X-Cache-Age
X-Akam-SW-Version
X-Powered-By-360WZB
X-Track
X-Instart-Request-ID
X-Acquia-Application-UUID
Arr-Disable-Session-Affinity
S-Cnection
X-Correlation-Id
X-Forwarded-For
X-Sapient
X-Svr-Proxy
X-SVR-IIS
X-Environment
X-Dispatcher
X-Cache-TTL
X-Cache-Namespace
X-Duration
Content-Disposition
X-Powered-By-VTEX-Janus-Edge
USPLoggingUUID
WZWS-RAY
RTSS
X-Supported-By
X-TransIP-Balancer
X-Magento-Cache-Control
X-URL
SSPAppContext
X-Director
X-Abgroup
X-NetCat-Version
X-Powered-By-VelaWeb
X-App-Status
X-Dealeron-Backend
Pool
X-Matrix-Server
X-Dealeron-Original-Url
X-TransIP-Backend
Node
X-Matrix-Proxy
X-DealerOn
X-Page-Cache
X-Art-Request-Id
Wsr-Cache
X-Expires-Orig
X-Vcap-Request-Id
X-ORACLE-DMS-ECID
X-Hypernode
X-Server-Upstream
X-Rocket-Nginx-Bypass
X-Server-Id
X-Edge-IP
X-Cache-Control-Orig
X-SSL-Cipher
X-CSRF-Protection
X-App-Hosting
X-LB-Node
X-SSL-Protocol
X-Debug
X-I
X-Drupal-Cache-Tags
X-Daa-Tunnel
X-Server-ID
X-Generated
X-Correlation-ID
X-Client-IP
X-Revision
X-ATG-Version
X-Cache-Debug
X-Route-Server
X-Cache-Lifetime
X-Geo-Country
FAI-W-FLOW
SN
X-Varnish-GracePeriod
X-Hiawatha-Cache
X-Varnish-Seen-By
X-Varnish-RemainingLife
X-Varnish-ObjectSource
X-Storage
X-Varnish-Cacheable
X-Gamma-Serve
X-Varnish-RemainingTTL
ServerID
X-Front
X-Now-Id
X-ServerName
Cache
Accept-Encoding
Update-Time
Src-Update
X-VARITI-CCR
Contao-Page-Layout
X-CJ-Soft
X-Cache-Level
X-Cache-Handler
X-SV-Nginx-Duration
X-SV-FromDBCache
X-SV-Expires
X-SV-Edge
X-SV-Duration
X-SV-Cacheable
X-SV-CreatedAt
X-Firenze-Processing-Time
X-Grace
Powered-By-ChinaCache
X-SV-Pid
X-NoCache
SiteSpeed
X-SV-CacheTags
X-Rocket-Nginx-Serving-Static
X-SRV
X-LB-Server
X-IsCacheURL
X-Acquia-Application-Trace
X-Varnish-Age
X-Env
Content-Encoding-Handler
X-Cache-Operation
X-Discourse-Route
X-Cache-Server
Req-Id
X-Url-Base
X-Flow-Powered
X-Varnish-Url
Edge-Control-Message
Cneonction
X-Pressidium-NinukisWP-Ver
X-Drupal-Cache-Contexts
X-Vhost
X-SmugMug-Hiring
Smug-CDN
X-Dispatch
X-Esi
X-Amz-Meta-S3cmd-Attrs
X-TTFB-L
X-SmugMug-Values
X-Varnish-TTL
X-TTFB
X-Litespeed-Cache-Control
X-Varnish-IP
X-GeoIP-Country-Code
X-Ttl
If-Modified-Since
X-Content-Encoded-By
X-TransIP-Reserved
X-Forwarded-Proto
X-Cache-Only-Varnish
X-Locale
X-PwB-Node
X-Time
X-Sucuri-ID
Cache-Tags
X-Varnish-Backend
Backend
X-Trace-Id
X-Unbounce-PageId
Location
X-Unbounce-VisitorID
Lsrequestid
X-Content-Type-Option
Author
X-Country-Code
X-Cache-Engine
X-Always-Cache
X-Server-Instance
X-Sucuri-Cache
Content-MD5
X-Unbounce-Variant
X-Cache-Expires
X-Middleware-Start
X-Connection-Hash
X-Transaction
X-Twitter-Response-Tags
X-Service-Id
Service-Worker-Allowed
MJ12bot
Strikingly-Cached
W
X-Cache-PageType
X-Amz-Rid
X-GUploader-UploadID
X-Litespeed-Cache
X-Last-Modified
Strikingly-Cache-Region
X-Cache-Fix
Strikingly-Cached-Version
SEOMOZ
X-Varnish-Retries
X-GeoIP-Country-Name
Section-Io-Id
X-Speed-Cache
X-Speed-Cache-Key
X-High-Performance
X-CF-Passed-Proto
Proxy-Connection
X-Magnolia-Registration
X-FIRSTBase
Custom-Header
X-Dynamic-Cache
X-LB
X-Akamai-Device-Characteristics
X-ORACLE-DMS-RID
Server-Name
X-Akamai-Device-Model
X-SRCache-Key
X-Webkit-CSP
X-Real-Server
Use-Proxy
X-Cache-Control
AMF-Ver
X-Cache-Type
PICS-Label
X-Cookie-Domain
X-TTL
X-Symfony-Cache
ServerName
Edit
X-Now-Cache
Page-Completion-Status
Pv
From-Origin
X-WR-MODIFICATION
Srv
X-Content-Security-Policy-Report-Only
X-BackendServer
X-ServerID
NnCoection
X-Wikidot-Backend
X-HW
X-N
X-Frontend
X-Wikidot-Static-Cache
MC
X-Nitro-Cache
Nodo
FindLaw
X-Origin
X-Srv
X-Empowered-By
X-Storage-Cache-Expires
X-CDN-Forward
X-Storage-Cache-Date
X-Nginx-Cache
X-Varnish-Server
X-Storage-Cache
Qs-Cache
NetMindSessionID
X-NginX-Cache
X-Cache-Device-Type
X-Yadis-Location
X-Xrds-Location
Drupal-Pagecache-Memcache
X-ID
X-Pool
X-Key
Https
Local-Info
X-FTR-Request-ID
Swift-Performance
Tracecode
X-Pantheon-Site
X-Pantheon-Environment
Ohc-File-Size
X-Processing-Time
Surrogate-Key-Raw
X-Pantheon-Phpreq
Content-Transfer-Encoding
X-SDS
X-Worker
X-Content-Age
S
X-Amz-Storage-Class
Fw-Via
X-Amz-Meta-Content-Md5
X-Nbs
X-BKSrc
IBM-Web2-Location
X-Vip
X-FW
Content_type
X-LP
X-ACMCache
Access-Control-Allow-Method
X-FireWall-Port
IM-Version
X-TB-M
X-Varnish-Ttl
X-Cache-Miss-From
X-Varnish-Hits
X-Sedo-Request-Id
Hummingbird-Cache
X-Shield-Request-Id
Pics-Label
Accept-Language
X-Shard
CacheControlHeader
X-Id
X-Distributor
X-Analytics
X-Browser
X-VC-Enabled
Backend-Timing
X-A
Accept-Charset
X-Varnish-Hostname
X-NginX-Server
X-Location
Ramp
X-Orig-Vary
X-SP-UniqueName
X-Disney-Akamai-Rule
X-UPSTREAM
Prama
Noq
Xc-Version
X-4ormat-Cacheable
Server-Timing
Ram
X-WR-Flags
X-SP-Farm
HAVer
HCVer
X-Yottaa-Optimizations
X-Config-Blacklist-Version
X-Cache-2
X-WPL-DATA
X-Yottaa-Metrics
X-Role
X-Varnish-ID
X-CB-Server
RequestId
X-HydroSheep
X-Drectory-Script
X-AEM
X-App
X-PF-Uncompressing
X-Hstore
X-Real-IP
Dtk-Cache-Check-0
X-JG-Page-Cache
X-Rq
Server-Info
X-Adobe-Content
X-AVG-Country-Code
X-Redman-Backend
X-Avg-Cookie-Expires
X-Akamai-Edgescape
SRV
Adm-Server
X-Redman-Final-Url
X-Pagename
X-Forwarded-Host
X-Cache-CFC
X-Adobe-Loc
X-Unique-ID
X-Hrouter
X-Hit-Cache
X-Resource
X-E
X-Runtime-Rack
X-RequestId
X-LW-Web-Server
X-JSESSIONID
X-Remote-Addr
X-Sys-Req-ID
AsisCache
X-SERVER-NAME
Cached
Cm-Server
X-Proxy-Backend
Eomportal-Instance
Cteonnt-Length
X-ClientSide-Caching
X-Runtime-Affili
X-Runtime-Memory
Web-App-Origin-Name
Lookup-Cache-Hit
X-Span
X-Agent
X-App-Runtime
X-GoCache-CacheStatus
X-Proxy
X-GeoIP
X-Dw-Trace-Id
X-Balanceador
X-Vcache
X-ServerIndex
X-ARRServer
X-Source-ID
A-Powered-By
X-Atraveo-ETag
X-Rule
X-Atraveo-TTL
X-Atraveo-From-Varnish-Cache
Lb
Nginx-Cache
X-Atraveo-Expires
X-RealServer
Accept-CH
X-CLOUD-TRACE-CONTEXT
X-Atraveo-Set-Cookie
X-Atraveo-Param-Rm
X-Generated-Timestamp
X-Atraveo-Cache-Control
X-Atraveo-Varnish-Server-Id
Server-ID
X-Fedora-School-Id
X-Stage
X-Appmachine-Environment
SHInfo
X-Request-Uri
X-PRAM
X-App-Server
X-Batcache
X-Force
X-Plat
X-Culture
X-Atraveo-Zone
X-VC-TTL
X-Path-Route
WWW-Authenticate
X-V
XDomainRequestAllowed
X-Varnish-Debug-Age
Access-Control-Request-Headers
Pf.Web.Request.Id
X-Debug-Token
X-Jphone-Copyright
X-Session-ID
Beyond-Iis
X-Pantheon-Az
X-CacheDebug
X-Distil-CS
X-Ratelimit-Reset
X-Varnish-Debug-TTL
Request-Country
X-NWS-UUID-VERIFY
Request-EU
X-Ratelimit-Remaining
X-Purge-Host
X-Purge-URL
X-Webstats-RespID
X-IIJ-Cache
X-Ratelimit-Limit
Identity
X-Domain-Checked
X-CacheFROM
X-Akamai-Transformed
X-Frames-Options
Front
Disablevcache
X-SE-Debug
WP-FROM-CACHE
X-Session-Reinit
Load-Balancer
X-Processed-By
X-Cache-Ttl
Firespring-Website-Id
CS-SERVER
IES-Server
Upgrade-Insecure-Requests
IISExport
X-SDE-Name
X-ESI
X-Nginx-Host
X-Hosting-Env
X-SmartBan-URL
Url
X-AF-Userserver
X-RiS-UFDI
X-Garden-Version
X-Cacheable-TTL
X-Dev
X-Highwire-SessionId
X-Cache-Varnish
Worker
X-Cms-Mode
X-Server-IP
X-Framework
X-Backend-Status
SVR
X-Provisioner-Version
X-VCS-Ttl
X-Highwire-RequestId
X-CAPServer
X-VCS-Cacheable
X-SmartBan-Host
X-Req-Head-Response
CLMOB
X-Map-Context
Cmsid
Copyright
X-EPiphany-Vid
X-Client-Vid
X-Ms-Request-Id
Referer
X-Client-Image-Vid
Cmstype
X-Detected-Device
X-HeBS-Cache-Status
Frame-Options
X-Proxy-Skip
X-Consent-Required
Proxy-Agent
ScoreTracker
X-Upgrade-Enabled
AETN-Continent-Code
AETN-Country-Code
AETN-Country-Name
AETN-DEVICE
X-HTML-Minification-Powered-By
X-PBY
X-Resty-Request-Id
X-Upstream-Status
*
X-Amz-Id-1
X-Upstream-Backend
X-Confluence-Request-Time
AETN-Area-Code
AETN-EU
X-Streams-Distribution
AETN-City
AETN-Longitude
X-GSL-Server
WP-AdvCache-MemCached
CF-Worker-Script
Myheader
Paypal-Debug-Id
Dispatcher
X-Desc
X-DevSrv-CMS
AMP-Redirect-To
X-Refresh
VANITY-HOST
AETN-Postal-Code
X-Amcomm-Site
AETN-Latitude
AETN-State-Code
X-Adnet
AKA-DEVICE
X-Actindo-Rs
X-Actindo-Thread-Id
X-Captured
Cleartype
X-DSMX-Rewrite-MS
Home
X-DSMX-Render-MS
X-EC2-Instance-Id
X-Varnish-Cache-Local
X-HA-Backend
X-Application
Traffic-Origin
Il-Cl
X-Domino-CacheValidationWithETagResult
X-Aramark-SID
X-B2f-Not-Route
Environment
Thanks
X-Domino-CacheValidationWithETagReason
Play-Detected-Device
Play-Detected-UserAgent
Proxy-Cache
X-HA-Frontend
AR-ATIME
X-Header
X-HashTwo
X-Data-Request
X-Cocoon-Version
X-Autoru-Host
X-TKP-SRV-ID
X-Oferteo-Domain
X-MAT-GEO
X-Proxy-Cache-Control
X-Soro
AR-SID
AR-PoweredBy
AR-CACHE
Num
Access-Control
X-UA-Bot
X-Via-S
X-WebNode
Max-Age
X-Actindo-Request-Id
Filters
X-Block-RuleID
VServer
X-7d-Trace-Id
X-7d-Instance-Id
X-Block-Rule
Resin-Trace
Machine
Description
X-Bip
X-PHP-Response-Code
X-CacheLoc
X-Rebelmouse-Cache-Control
X-Cache-Dispatcherpragma
X-CRA-DC
X-Cache-On
X-Cache-Dispatchercachecontrol
Access-Control-Allow-Header
Keywords
X-Cache-Doesi
X-AOL-HN
Og
NtCoent-Length
X-WP
X-SV
X-Rack-Cors
X-Highwire-Smart-Code
X-DataDome
X-Smartcache-Timeout
Pramga
X-Dynatrace
ServerTokens
ServerSignature
Dynatrace
COMMERCE-SERVER-SOFTWARE
X-Varnish-URL
X-Compress-Hint
Web
X-HostName
X-Highwire-Sitecode
Now
RN-Server
X-Envoy-Upstream-Service-Time
Bios
X-OpenCart-Lightning
X-Smartcache-Keys
X-Via-NSCOPI
X-Now-Trace
X-CACHE-TTL
X-Flex-Tags
X-Flex-Tag
X-Nx
X-Timestamp
X-Batcache-Reason
X-Response
X-Gyrobase-Publication
X-Flex-Lastmod
X-Cdn-Origin
X-Flex-Lang
X-Flex-Community
X-Dynatrace-Js-Agent
X-Beatles
X-Fastly-Request-Id
X-Clara-ASAP
X-Flex-Evstart
X-ASAP-Cache
X-Flex-Evend
X-Lb
X-Served-Server
X-M-Log
Ttl
Content-Sn
TYPO3-Sitename
TYPO3-Pid
X-AutoRu-App-Id
X-Geo
X-RiS-PX
XX
X-M-Reqid
X-Nx-All
X-Cache-Detail
X-Directory-Script
X-Test
X-Requestid
ModuleCacheType
VAR-Cache
X-Varnish-Id
X-Qnm-Cache
MageStack-Web-Node
Fastly-Debug-Digest
From
N365rili
Dis-Env
Ibf5scheme
Yoncu-Errno
PServer
HitType
Magicmarker
X-Amzn-RequestId
MageStack-Cache-Lifetime
X-Amz-Apigw-Id
X-Blog
Provider
X-B3-Sampled
MageStack-Cache-Hits
MageStack-Cache
FRONT-END-SECUREBROWSER
X-Cache-Time
X-Proxy-Cache-Key
X-SilverStripe-Cache
X-Geo-IP
MageStack-Area
X-Fpc
X-CacheID
X-Beget-Proxy
X-DN-Cache-Control
X-MCF-ID
X-Skip-Cache
X-Resolver-IP
X-UnsetCookies
X-Custom-Name
X-Depends
X-Middleton-PageSpeed
X-WebKit-CSP-Report-Only
X-Info
X-Varnish-Cached-TTL
X-Varnish-Cached
MageStack-PageSpeed
MageStack-Tag
X-Generated-Time
X-Policy
Aurora-Node
Viewport
DNNOutputCache
Fastly-Backend-Name
Prot
Edgecast
X-UPServer
X-Ghost-Cache-Status
X-MCB-Server
X-WEBMGR-CACHE
MageStack-Cacheable
X-Amzn-Trace-Id
ServerNode
MageStack-Cache-Status
MageStack-Config
MageStack-Debug
MageStack-Magento-Version
X-Secret
X-SH-Cache-Status
MageStack-Loadbalancer
X-Protected-By
X-Sn-Servicetimems
X-LBPoolMember
X-ENDPOINT
X-Cdn-Forward
X-RAMCache
BackendServer
X-Sid
NLCacheNote
Xc
X-FORWARDED-PROTO
Device
X-Pj-Cache-Status
X-ROUTING
X-Served
X-APIVERSION
X-Varnish-Debug-Hits
X-Vary-Options
X-Appversion
X-TLS-Version
X-Serv
X-Varnish-Ip
X-Gateway-Rate-Limit-Delayed
X-Cache-Me-Harder
X-Appid
X-DB-Content-Length
X-Access-Control-Allow-Origin
X-Tag-Playlist
X-Deity
VSID
X-FastCGI-Cache-Status
X-Reflector-Cache
Serverid
X-Varnish-Action
X-Reflector
CommunityServer
ViewMode
NODE
X-APIAUTH-VAL
X-ORIKEY
X-IP
Report-To
X-PBS-Appsvrname
X-PBS-Appsvrip
X-PBS-Fwsrvname
X-Status
X-Page
X-Proxy-Server
X-RemovedCookies
X-NewsFlow-Sitename
X-We-Are-Hiring
X-Instance-Id
X-HS-Status
X-ENV
X-ReqId
X-MainProfileCategory
X-MainProfileID
X-MyName
X-MainProfileURL
X-MainProfileName
HSTS
Webserver
X-Nginx
X-ProcessESI
X-Compressed-By
X-Cluster
X-Nginx-Request-Processing-Time
X-Ms-Version
X-Svr
X-AMAZEEIO
X-Reqid
X-Cache-Extended
X-Cache-Action
SB-Cache-Remaining
SB-Cache-Life
SBSS
Content
TP-Cache
X-Box
TP-L2-Cache
SB-Site-Device
SB-Site-IE-VERSION
X-ZSITES-DNS
TC-Cache-IC
TC-Cache
TC-Cache-U
TC-S-Cache
TC-S-Cache-M
Session-From
ServerIP
X-Title
X-Static
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
Ufe-Result
X-Layout
X-Obvious-Info
X-Obvious-Tid
X-Client-Id
Tk
X-ACCELERATE
Debug-Status
X-SAPP
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FPC
X-Varnish-Grace
X-Origin-Date
EagleEye-TraceId
CommercePlatform-Version
X-Custom-Header
DB-Nickname
Ohc-Response-Time
X-Beluga-Cache-Status
X-Beluga-Node
X-DynamicCache
Backend-Powered-By
X-Phpwcms-Release
X-Proxy-Id
X-Aramark-CSID
YF-ID
X-Beluga-Record
X-Beluga-Response-Time
CDN-CachedAt
CDN-PullZone
CDN-RequestId
CDN-Uid
CDN-Cache
BALANCEDTO
X-Beluga-Response-Time-X
X-Beluga-Status
X-Beluga-Trace
Arrnode
X-Phpwcms-Page-Processed-In
X-Origin-Server
Purge-Cache-Tags
MageStack-Last-Modified
WN
X-FromPodPressCache
Hit-Count
MageStack-Cache-Warning
MageStack-Cache-Lifetime-Sent
X-Processed
X-This-Proto
X-Firefox-Spdy
Response-Time
Cf-Ipcountry
X-Build-Id
X-Say-Cacheable
X-Varnish-Cache-Ttl
X-Say-TTL
X-SayCDN-TTL
X-V-Cache
X-ProBase-Server
X-Shopware-Allow-Nocache
X-XHTML-Minification-Powered-By
X-MID-Host
X-Shopware-Cache-Id
X-W3TC-Minify
X-Powered-By-Home.Pl
Ssl-Proxy-Server
X-Search-Id
X-Src-Webcache
X-Cache-LB
X-Cname-TryFiles
REFRESH
PBS
GranicusServer
HTTPS
MS-CV
AMP-Access-Control-Allow-Source-Origin
Tempo
X-PM-ID
X-HA
X-Goog-Meta-Replace
CF-Cache-Key
X-Goog-Meta-Policy
X-ETag
X-Max-Age
X-Rack-CORS
X-Varnish-Backend-Beresp-Backend
X-Backside-Transport
X-Pass-Through
X-Mighty-Proxy
X-M
X-WN-ClientGroup
X-Global-Transaction-ID
X-Vol-Mrp
X-Node-Id
X-ManagedFusion-Rewriter-Version
X-MrHost
X-NodeID
X-Powered-By-ADS
X-Instance
X-Webcelerate
Amfplus-Ver
X-Gannett-Site-Version
Nitro-Cache
X-BPool-Back
X-Airee-Node
X-BServer
X-Vol-Correlation
SINA-TS
SINA-LB
X-NoIndex
X-Origin-Cache
X-Cache-Node
X-CH-Device
X-Test-Debug
Hosted-By
X-Cache-FS-Status
X-Now-Instance
X-Wodby-Node
X-SCM-Server-Number
X-Route
X-Who
Provided-Host
CDCHOST
NGX
AC-ELC
X-Rewritten-By
Session-Id
Server-Id
X-PROCESSED-BY
Server-Ip
X-Xml-Http-Blocked
X-Server-Addr
X-CACHE-KEY
X-Scheme
X-Actual-Url
SERVER-ID
X-Mobilized-By
X-Oracle-Dms-Ecid
X-RENDER-TIME
X-DEBUG
X-COUNTRY-CODE
X-JoinUs
X-Appmachine-Duration
X-Cache-Warmer
X-Server-Hostname
X-Cache-HT
X-Appmachine-Name
X-Catalyst
X-Enhanced-By
X-FG-RequestId
D
X-AppServer-Cache-Exception
X-Ruxit-Js-Agent
X-Amzn-Remapped-Date
X-Server-Generated
X-AppServer-Status
X-From-Cache
X-NMT-Proxy
X-AppServer-Cache-Rule
Language
X-Ssl-Cipher
UrlWatchModule-Time
X-Unique-Id
Actual-Object-TTL
X-Middleton-Pagespeed
X-Machine
X-Appmachine-CreatedOn
SERVER-NAME
Fastly-Restarts
X-Autoru-App-Id
X-Serverid
X-Amz-Meta-S3b-Last-Modified
X-Old-Content-Length
X-Healthy
X-InDy-Query
X-CAMPUSSUITE-TENANT
X-No-Session
X-Front-Cache
X-CSRF-Token
X-Magento-Route
X-Expires
X-Pageid
X-CAMPUSSUITE-ENVIRONMENT
EQ-Cache
X-Enabled3
PagesDisplayed
V-Cache-Ttl
X-Tradeindia-Request-GUID
X-CAMPUSSUITE-DEBUGGING
X-ASAP-Age
X-Fastly-Backend-Reqs
X-TEST
X-Time-Spent
X-SSLTerm-Server
Generate-Time
Prototype-RootPath
X-Itkg-Cache-Tags
X-SG-Server
X-UT-Cache
X-Beresp-Ttl
X-Country
RSL-Trace-ID
Origin-Vm
Fastly-Drupal-Html
X-Tradeindia-SMgmt
X-Enabled2
LB
Amp-Access-Control-Allow-Source-Origin
PB-PID
PB-RID
PROGMA
F5-IpCliente
Gzip
ProxiaInstanceId
X-Varnish-Age-Debug
X-Optimization
X-Bitrix-Composite
X-Avvio-Cms-Cacheload
VC-NoCache
X-Varnish-TTL-Debug
X-Grid-Server
X-InDy-Memory
X-Vid
X-Telligent-Evolution
Ews
Servername
X-Enabled1
X-Cache-Id
ClientIP
X-Router
X-InDy-Time
X-Accel-Cache-Control
X-Mobile-Rewrite
X-Origin-Upstream-Status
X-ORIGN-SERVER
X-GZip
HA-Geocity
X-Content-Type
X-BeResp-Ttl
X-Zendesk-User-Id
X-UPSTREAM-Address
X-WA-Info
X-Zendesk-Origin-Server
EN-User
FastCGI-Cache
X-Render-Time
X-Transaction-Name
X-Dck
X-Built-By
X-Abuse
X-RequesterIP
X-D2id
X-Cache-Via
X-Qiniu-Zone
Requested-Host
Unique-Request-Id
X-Clx-Request
Web-Server
X-Oracle-Dms-Rid
X-Log
X-Navigation-Version
X-HP-CAM-COLOR
X-Olaf
HitInfo
X-FastCGI-Cache
X-SEA-Instance-Name
X-Ser
X-Boot
X-CloudBurst-WordPress
X-Cache-ID
X-CloudBurst-Frontend
X-OPNET-Transaction-Trace
X-CloudBurst-Cache
ID
X-VHosting-Cache
X-Server-Ip
X-BIT-Node
X-Pagely-Cache
X-Served-From
X-Varnish-Cache-Control
X-SSL
X-CloudBurst-Backend
X-SCProxy
X-Mobile-Device-Type
SS
Arrow-RequestId
X-Cachable
X-Mobile-Device
X-Debug-Message
X-Activity-Id
Sl-Pgid
X-Amz-Meta-Version-Id
X-Az
X-PressLabs-Stats
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-Cache-TTL-Age
StatusCode
X-Cache-TTL-Current
X-Firewall
X-Instance-Name
X-Hit
MSThemeCompatible
MSSmartTagsPreventParsing
X-ServiceProvider
X-Ruby-Cluster-ID
X-XHR-Current-Location
CmsfirstPublishTimestamp
Httpd-Identifier
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
NZSpeedy
MwpReleaseVersion
Page-Template
Pragrma
Returned-Status
MachineName
Id
X-Nginx-Page-Cache
X-Meta-MSThemeCompatible
X-Node-App
X-Proto
DrivedBy
X-NginX-Upstream
X-Jcms-Ajax-Id
BlockPHPCallEnd
X-VG-WebCache
HA-Cloudapp
HA-Geocountry
HA-Geolon
HA-Geolat
X-UType
X-SuperCache
X-PoweredBy
X-MSU-SOURCE
X-Requested-With
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
HA-Georegion
HA-Host
X-Built-With
X-Bcwwwid
X-CGP
X-HAProxy
X-Homeaway-Requestmarker
Request-Time
Progma
HA-Servedtime
HA-Ipaddr
HA-Urlpath
L5d-Success-Class
NKBVHEADER
WebServer