Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Set-Cookie
Server
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
CF-RAY
X-XSS-Protection
Age
X-Cache
Expect-CT
Content-Language
P3P
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
Access-Control-Allow-Origin
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Request-Id
X-Varnish
Referrer-Policy
X-Adblock-Key
X-Check
X-Generator
X-Language
X-Template
X-Type
X-Buckets
X-Cache-Group
X-Pass-Why
WPE-Backend
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Download-Options
Alt-Svc
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Cache-Hits
X-Ac
Host-Header
X-Hacker
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-AspNetMvc-Version
X-ShopId
X-Sorting-Hat-PodId-Cached
X-ShardId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sorting-Hat-FeatureSet
X-Via
X-Runtime
X-Served-By
X-Powered-By-Plesk
X-Contextid
P3p
X-PC-Hit
X-PC-Key
X-UA-Device
X-Amz-Cf-Id
X-PC-AppVer
MS-Author-Via
X-ServedBy
Content-Location
X-PC-Host
X-PC-Date
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Powered-CMS
X-IPLB-Instance
X-Timer
X-Seen-By
Status
X-Wix-Request-Id
X-Rid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Ua-Compatible
CF-Cache-Status
X-Tumblr-Pixel-1
Cartoon
X-Iinfo
X-Tumblr-Pixel-2
Access-Control-Allow-Credentials
X-Backend
X-WPE-Loopback-Upstream-Addr
X-Cache-Status
Content-Encoding
X-Host
Powered-By
X-CST
X-Endurance-Cache-Level
X-Mod-Pagespeed
X-Cache-Enabled
X-Cache-Hit
X-FRAME-OPTIONS
X-Port
X-CDN
X-NewRelic-App-Data
X-Tumblr-Pixel-3
X-Newrelic-App-Data
X-Logged-In
X-Server-Powered-By
Keep-Alive
X-DIS-Request-ID
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server
X-Robots-Tag
X-Accel-Version
X-Proxy-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Turbo-Charged-By
X-Page-Speed
X-Content-Powered-By
X-GitHub-Request-Id
X-LiteSpeed-Cache
X-Content-Digest
Content-Security-Policy-Report-Only
X-Rack-Cache
X-Request-ID
X-Tumblr-Pixel-4
X-AH-Environment
X-FW-Hash
X-FW-Server
X-FW-Serve
X-FW-Type
Request-Context
X-FW-Static
X-Pad
X-Varnish-Cache
Edge-Control
X-Hits
X-Webcom-Cache-Status
X-Trace
X-Request-Country
SPRequestGuid
X-XRDS-Location
X-SharePointHealthScore
Access-Control-Expose-Headers
X-BC-Stapler
X-MS-InvokeApp
MicrosoftSharePointTeamServices
Edge-Cache-Tag
Cf-Railgun
X-HS-Cache-Config
X-Node
WP-Super-Cache
X-HS-Content-Id
X-CF-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-HS-Combine-CSS
Timing-Allow-Origin
Charset
X-Died
X-Webserver
X-Content-Security-Policy
X-FullPageCaching
X-SERVER
X-Fastly-Request-ID
X-Cache-Lookup
X-INKT-SITE
X-INKT-URI
X-PHP-Backend
X-Cnection
X-PhApp
Request-Id
Access-Control-Max-Age
X-Backend-Server
SPIisLatency
SPRequestDuration
X-Edge-Cache-Key
X-Edge-Cache
MicrosoftOfficeWebServer
EagleId
CONTENT-SECURITY-POLICY
X-CDN-Pop
X-CDN-Pop-IP
X-Swift-CacheTime
X-Swift-SaveTime
X-Servedby
Rating
Composed-By
X-SS-Location
X-SS-Conf
Grace
X-Tumblr-Pixel-5
X-Safe-Firewall
X-Device
X-Server-Name
Ali-Swift-Global-Savetime
X-Tumblr-Content-Rating
X-NF-Request-ID
Liferay-Portal
X-DDC-Arch-Trace
Served-By
X-Dw-Request-Base-Id
X-Spip-Cache
X-VCache
X-Hyper-Cache
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-HeyJason
X-Cloud-Trace-Context
X-Microcache
Front-End-Https
P-LB
P-WS
Surrogate-Control
X-Original-Date
X-LiteSpeed-Cache-Control
X-Cluster-Node
X-TNCMS
X-Loop
X-Middleton-Display
Display
X-Sol
X-RateLimit-Remaining
X-RateLimit-Limit
X-Middleton-Response
Response
X-OneAgent-JS-Injection
X-Acc-Exp
X-Clacks-Overhead
Content-Style-Type
X-Firenze-Processing-Times
X-StackifyID
X-RateLimit-Reset
X-Jimdo-Wid
X-Jimdo-Instance
X-FB-Debug
Content-Script-Type
X-Kinsta-Cache
X-DNS-Prefetch-Control
X-Vtex-Processado-Em
Public-Key-Pins
X-Wix-Punisher
X-Debug-Info
X-Age
X-Shopid
X-Sorting-Hat-Featureset
X-Shardid
X-Sorting-Hat-Podid
X-Tumblr-Pixel-6
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid-Cached
X-Sorting-Hat-Privacylevel
X-Amz-Version-Id
X-User-Agent
X-HOST
X-Magento-Tags
X-DynaTrace-JS-Agent
X-Url
Fpc-Cache-Id
X-Goog-Hash
X-XN-XNHTML
X-XN-Trace-Token
X-Ruxit-JS-Agent
X-LW-Cache
X-Zen-Fury
PageSpeed
Xkey
X-Cache-Config
X-N-OperationId
X-Px
X-Cached
X-Hostname
X-WebKit-CSP
Feature-Policy
Wpe-Backend
Retry-After
X-Version
X-Upstream
Refresh
X-Topify-Platform
X-Handled-By
X-Frame-Option
X-Generated-By
Rt-Fastcgi-Cache
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Edge-Location
X-Goog-Storage-Class
X-Goog-Metageneration
X-Source
Allow
X-MiniProfiler-Ids
Access-Control-Request-Method
X-Loopia-Node
Fastcgi-Cache
X-FORWARDED-FOR
X-ET-API-ROOT
X-ET-API-ORIGIN
X-ET-API-VERSION
TCN
X-EdgeConnect-Origin-MEX-Latency
X-Whom
X-Request-Time
X-Cached-By
X-B-Cache
X-EdgeConnect-MidMile-RTT
Powered
ServedBy
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-SRCache-Store-Status
X-CMS-Version
X-SRCache-Fetch-Status
X-Engine
Product
X-Outils-CS
X-RESOURCE
X-URLSCHEME
X-From
X-Fastcgi-Cache
X-Guploader-Uploadid
X-DynaTrace
Last-Published
X-Application-Context
X-AspNetWebPages-Version
X-Accel-Expires
X-F-Cache
X-Magento-Cache-Debug
X-Vtex-Remote-Cache
X-Vtex-Processed-At
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
No
X-VTEX-Cache-Status-Janus-ApiCache
X-CacheServer
X-Content-Options
X-Varnish-Count
X-Developer
X-Varnish-HitMiss
X-Varnish-Host
X-Varnish-Cache-Hits
X-ARC
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
Fhost
X-Cache-Key
X-Location-Id
Warning
X-Signature
X-S
Public-Key-Pins-Report-Only
X-UD-Method
Cache-Provider
X-Microcachable
X-Shop-Id
Generator
Imagetoolbar
X-Defender
X-Original-Request
Host
X-Device-Type
X-Passed-To-DLL
X-Passed-To
X-Returned-From
X-Returned-From-DLL
Dmn
X-NWS-LOG-UUID
X-Actual-URL
X-Platform-Server
X-Ezoic-Cdn
X-ApacheServer
X-Response-Time
X-Cache-Info
X-PERF
Pagespeed
X-Umbraco-Version
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Cache-Key
X-Sapient
X-HS-Content-Campaign-Id
X-Stale
X-Msg-2-Log
X-Passed-To-BeforeDispatch
X-Hosted-By
X-Passed-To-PostProcessResponse
X-Forwarded-For
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Platform
DynaTrace
Alternate-Protocol
X-Gateway-Cache-Status
X-Cache-Rule
X-Micro-Cache
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
Version
X-Via-JSL
X-LBLID
X-Recruiting
Content-Hash
Origin
X-Cache-Namespace
X-SO
X-I-Sp
X-BS
Surrogate-Key
X-Microcache-Status
X-Translation
X-Lambda-Id
X-Platform-Cache
X-SSLProxy
X-Track
Akamai-IP
X-Cache-Age
X-SSLUpstream
X-Powered-By-360WZB
X-Akam-SW-Version
Arr-Disable-Session-Affinity
X-Acquia-Application-UUID
X-Rnd
X-Dealeron-Original-Url
X-DealerOn
X-Instart-Request-ID
X-Dealeron-Backend
X-Dispatcher
X-Magento-Cache-Control
MIME-Version
X-Svr-Proxy
X-SVR-IIS
X-Cache-Tags
SSPAppContext
X-Powered-By-VTEX-Janus-Edge
X-Cache-TTL
S-Cnection
X-Correlation-Id
X-Powered-By-VelaWeb
WZWS-RAY
X-Duration
X-Supported-By
X-Dns-Prefetch-Control
RTSS
X-Environment
USPLoggingUUID
Content-Disposition
X-URL
X-Server-Upstream
X-SSL-Cipher
X-Abgroup
X-SSL-Protocol
X-Matrix-Proxy
X-Matrix-Server
X-Director
X-NetCat-Version
X-App-Hosting
X-Art-Request-Id
Node
X-App-Status
X-TransIP-Balancer
X-Edge-IP
X-Expires-Orig
Pool
Wsr-Cache
X-Cache-Control-Orig
X-ORACLE-DMS-ECID
X-Page-Cache
X-CSRF-Protection
X-Storage
X-Hypernode
X-LB-Node
Accept-Encoding
X-TransIP-Backend
X-Cache-Debug
Cache
X-Rocket-Nginx-Bypass
X-Debug
X-Vcap-Request-Id
X-Revision
X-Correlation-ID
X-Daa-Tunnel
X-Varnish-Cacheable
X-Drupal-Cache-Tags
X-Cache-Handler
ServerID
X-I
X-Cache-Server
FAI-W-FLOW
X-Server-Id
X-Generated
X-Client-IP
X-VARITI-CCR
X-ATG-Version
X-ServerName
X-Front
X-Now-Id
X-Env
Powered-By-ChinaCache
X-Server-ID
X-Geo-Country
X-Gamma-Serve
Update-Time
X-Cache-Lifetime
Src-Update
X-Hiawatha-Cache
X-SmugMug-Values
X-Rocket-Nginx-Serving-Static
X-SV-Cacheable
Smug-CDN
X-TTFB-L
X-SmugMug-Hiring
X-SV-CacheTags
X-TTFB
X-SV-Duration
X-SV-Nginx-Duration
X-Cache-Operation
X-NoCache
X-SV-FromDBCache
X-SV-Pid
X-SV-Edge
X-SV-CreatedAt
X-SV-Expires
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-Route-Server
X-Varnish-Seen-By
X-Varnish-ObjectSource
X-Varnish-GracePeriod
SiteSpeed
Contao-Page-Layout
X-IsCacheURL
X-LB-Server
X-Acquia-Application-Trace
SN
X-Varnish-Age
X-SRV
X-Grace
Content-Encoding-Handler
X-Url-Base
Edge-Control-Message
X-Cache-Level
X-Vhost
X-Ttl
X-Country-Code
X-Dispatch
X-Discourse-Route
X-Cache-Engine
X-Firenze-Processing-Time
X-Flow-Powered
X-Litespeed-Cache-Control
X-Varnish-Url
X-Drupal-Cache-Contexts
Req-Id
X-Varnish-TTL
X-Cache-Only-Varnish
X-Amz-Meta-S3cmd-Attrs
Cneonction
X-GeoIP-Country-Code
X-Pressidium-NinukisWP-Ver
X-Content-Type-Option
X-Time
X-Sucuri-ID
Cache-Tags
Backend
X-Sucuri-Cache
X-Forwarded-Proto
X-Unbounce-Variant
X-CJ-Soft
X-Server-Instance
Lsrequestid
Https
X-Unbounce-VisitorID
X-Unbounce-PageId
X-TransIP-Reserved
Proxy-Connection
If-Modified-Since
X-Varnish-IP
X-Middleware-Start
X-Varnish-Backend
Service-Worker-Allowed
X-Content-Encoded-By
X-Litespeed-Cache
Author
X-GUploader-UploadID
Strikingly-Cached-Version
MJ12bot
SEOMOZ
X-Always-Cache
X-Last-Modified
Page-Completion-Status
Location
X-Amz-Rid
Strikingly-Cached
Strikingly-Cache-Region
From-Origin
X-Trace-Id
X-Cache-Expires
AMF-Ver
X-Twitter-Response-Tags
X-Connection-Hash
X-BackendServer
X-Cache-Type
X-Locale
X-Service-Id
X-FIRSTBase
X-Transaction
Content-MD5
X-SRCache-Key
X-Real-Server
Server-Name
X-Esi
Custom-Header
W
X-ORACLE-DMS-RID
X-GeoIP-Country-Name
X-Cache-Control
X-PwB-Node
Use-Proxy
X-High-Performance
X-Webkit-CSP
X-Varnish-Retries
X-Speed-Cache
X-Speed-Cache-Key
X-Magnolia-Registration
Section-Io-Id
X-Shard
X-Config-Blacklist-Version
X-CF-Passed-Proto
X-Akamai-Device-Characteristics
X-FTR-Request-ID
X-TTL
X-WR-MODIFICATION
Srv
X-FW
X-LB
X-Now-Cache
X-Akamai-Device-Model
ServerName
NnCoection
X-N
X-ServerID
X-Frontend
X-Cache-Fix
X-Cache-PageType
X-Content-Security-Policy-Report-Only
MC
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Dynamic-Cache
IBM-Web2-Location
X-Symfony-Cache
X-Nginx-Cache
X-Cookie-Domain
FindLaw
X-Storage-Cache
Edit
X-Storage-Cache-Date
X-Storage-Cache-Expires
X-CDN-Forward
NetMindSessionID
Qs-Cache
X-Xrds-Location
X-Cache-Device-Type
X-Nitro-Cache
X-HW
X-Processing-Time
Pv
X-Srv
X-Varnish-Server
X-Empowered-By
Swift-Performance
Prama
Xc-Version
X-ID
X-PF-Uncompressing
X-Pool
Local-Info
X-Key
S
Content-Transfer-Encoding
X-Runtime-Memory
X-Amz-Meta-Content-Md5
X-NginX-Cache
X-Yadis-Location
Nodo
Fw-Via
Drupal-Pagecache-Memcache
PICS-Label
X-SDS
X-Nbs
X-RequestId
X-ACMCache
Content_type
X-Pantheon-Site
Ohc-File-Size
Surrogate-Key-Raw
X-Vip
X-Pantheon-Environment
Tracecode
X-Pantheon-Phpreq
X-Varnish-Hits
X-Varnish-Ttl
X-Browser
X-Origin
X-Analytics
IM-Version
Hummingbird-Cache
X-Distributor
Access-Control-Allow-Method
X-Shield-Request-Id
X-FireWall-Port
Pics-Label
X-Id
X-Cache-Miss-From
X-Sedo-Request-Id
X-Amz-Storage-Class
X-Location
X-A
X-Worker
Cached
Backend-Timing
X-LP
Ramp
X-Content-Age
X-Disney-Akamai-Rule
X-Orig-Vary
Ram
Noq
X-SP-UniqueName
Server-Timing
X-SP-Farm
X-WR-Flags
X-SERVER-ID
CacheControlHeader
RequestId
X-Yottaa-Metrics
X-Role
X-Purge-URL
X-Cache-2
X-Purge-Host
X-Varnish-ID
X-CacheFROM
X-BKSrc
X-Yottaa-Optimizations
SRV
X-Drectory-Script
X-AEM
X-Akamai-Edgescape
X-Avg-Cookie-Expires
X-AVG-Country-Code
Cm-Server
HAVer
X-Hit-Cache
X-Pagename
X-4ormat-Cacheable
X-E
X-Adobe-Loc
X-SERVER-NAME
X-Hstore
X-Sys-Req-ID
X-TB-M
X-Hrouter
X-Redman-Backend
HCVer
X-Runtime-Rack
X-LW-Web-Server
X-Unique-ID
X-Cache-CFC
Front
X-Varnish-Hostname
X-Adobe-Content
Server-Info
AsisCache
X-App
X-VC-Enabled
X-UPSTREAM
X-Redman-Final-Url
Adm-Server
X-JSESSIONID
X-NginX-Server
X-Real-IP
Proxy-Agent
X-Proxy-Backend
X-Runtime-Affili
X-App-Runtime
Cteonnt-Length
X-Proxy
X-Varnish-Debug-Age
X-Varnish-Debug-TTL
X-Span
Accept-Language
X-CB-Server
X-WPL-DATA
X-GoCache-CacheStatus
Lookup-Cache-Hit
Web-App-Origin-Name
X-ClientSide-Caching
Accept-Charset
X-Remote-Addr
X-Atraveo-Expires
X-Atraveo-ETag
Accept-CH
X-Stage
X-Atraveo-From-Varnish-Cache
X-Atraveo-Set-Cookie
X-Atraveo-Param-Rm
Server-ID
X-Atraveo-Cache-Control
X-ServerIndex
X-Appmachine-Environment
X-Dw-Trace-Id
X-V
X-Culture
Nginx-Cache
Lb
X-Balanceador
X-VC-TTL
A-Powered-By
X-Atraveo-TTL
X-Source-ID
X-Forwarded-Host
X-Rq
X-CAPServer
X-JG-Page-Cache
X-Generated-Timestamp
X-ARRServer
X-Path-Route
SHInfo
X-Fedora-School-Id
Dtk-Cache-Check-0
X-PRAM
X-Request-Uri
WWW-Authenticate
X-CLOUD-TRACE-CONTEXT
X-Force
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
CF-Worker-Script
X-Vcache
X-Ratelimit-Remaining
XDomainRequestAllowed
Access-Control-Request-Headers
X-Webstats-RespID
X-Agent
X-Session-ID
X-GeoIP
X-Distil-CS
X-Ratelimit-Limit
X-Ratelimit-Reset
X-Jphone-Copyright
Frame-Options
Beyond-Iis
X-HydroSheep
X-Pantheon-Az
X-NWS-UUID-VERIFY
Pf.Web.Request.Id
Eomportal-Instance
Request-Country
X-CacheDebug
Request-EU
X-Cache-Dispatcherpragma
X-Akamai-Transformed
Upgrade-Insecure-Requests
X-Cache-Ttl
Load-Balancer
X-Backend-Status
X-Dev
IES-Server
X-SE-Debug
X-Provisioner-Version
X-ESI
X-SDE-Name
X-Cache-Dispatchercachecontrol
X-Server-IP
X-Rule
IISExport
X-Plat
X-Hosting-Env
X-Domain-Checked
X-RiS-UFDI
Yoncu-Errno
X-Cacheable-TTL
X-App-Server
X-RealServer
X-Processed-By
Worker
X-Frames-Options
Firespring-Website-Id
X-Session-Reinit
X-Framework
SVR
Disablevcache
CS-SERVER
X-Batcache
Url
X-Cms-Mode
WP-FROM-CACHE
X-Nginx-Host
X-Client-Vid
Referer
Copyright
ScoreTracker
X-Consent-Required
X-HeBS-Cache-Status
X-Req-Head-Response
X-Map-Context
Cmsid
Cmstype
CLMOB
X-EPiphany-Vid
X-Client-Image-Vid
X-Proxy-Skip
X-Upgrade-Enabled
X-Detected-Device
X-IIJ-Cache
X-Resource
Proxy-Cache
X-Resty-Request-Id
X-Garden-Version
Thanks
Num
AMP-Redirect-To
X-PBY
Paypal-Debug-Id
Play-Detected-Device
X-GSL-Server
WP-AdvCache-MemCached
Home
Il-Cl
X-Upstream-Backend
X-Upstream-Status
Play-Detected-UserAgent
X-Desc
X-Actindo-Request-Id
X-Actindo-Rs
X-Domino-CacheValidationWithETagResult
Access-Control-Allow-Header
VANITY-HOST
AR-ATIME
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
X-Actindo-Thread-Id
X-Adnet
X-B2f-Not-Route
X-HTML-Minification-Powered-By
X-Aramark-SID
AR-SID
X-MAT-GEO
X-Domino-CacheValidationWithETagReason
AR-CACHE
AR-PoweredBy
*
AETN-State-Code
X-Varnish-Cache-Local
Max-Age
X-Soro
X-Application
X-TKP-SRV-ID
X-HA-Backend
X-ETag
X-Oferteo-Domain
X-UA-Bot
X-VCS-Ttl
X-Amz-Id-1
X-VCS-Cacheable
Access-Control
X-WebNode
X-Amcomm-Site
Identity
X-Ghost-Cache-Status
X-Via-S
AETN-Area-Code
X-Proxy-Cache-Control
AETN-Latitude
AETN-EU
X-HA-Frontend
X-Debug-Token
X-Data-Request
X-Confluence-Request-Time
AETN-Postal-Code
AETN-Longitude
X-Autoru-Host
X-Cocoon-Version
AETN-Country-Code
AETN-Continent-Code
AETN-City
X-Header
X-HashTwo
AETN-DEVICE
AETN-Country-Name
AKA-DEVICE
Myheader
X-Highwire-SessionId
CDN-Cache
X-PHP-Response-Code
X-SmartBan-Host
X-Highwire-RequestId
X-CRA-DC
X-Cache-On
X-Cache-Varnish
CDN-CachedAt
BALANCEDTO
Dispatcher
Filters
Arrnode
Cleartype
X-Refresh
VServer
X-SAPP
Traffic-Origin
X-SmartBan-URL
X-Varnish-Grace
CDN-PullZone
X-Rebelmouse-Cache-Control
X-Bip
X-AF-Userserver
X-7d-Instance-Id
CDN-Uid
CDN-RequestId
X-7d-Trace-Id
X-Rack-Cors
Bios
X-Compress-Hint
ServerSignature
ServerTokens
Web
X-Now-Trace
COMMERCE-SERVER-SOFTWARE
Dynatrace
X-HostName
NtCoent-Length
X-DataDome
X-Dynatrace
X-OpenCart-Lightning
X-Varnish-URL
X-CACHE-TTL
X-SV
X-Via-NSCOPI
X-Smartcache-Timeout
Pramga
X-Ms-Request-Id
Now
X-WP
RN-Server
X-Smartcache-Keys
X-Envoy-Upstream-Service-Time
X-Gyrobase-Publication
X-Geo
X-Dynatrace-Js-Agent
X-LBPoolMember
X-Qnm-Cache
X-Timestamp
X-Info
TC-S-Cache
MageStack-Web-Node
ServerNode
X-Streams-Distribution
X-M-Log
X-Middleton-PageSpeed
PServer
X-M-Reqid
Viewport
X-Served-Server
MageStack-Cache-Hits
MageStack-Magento-Version
X-Beatles
MageStack-PageSpeed
MageStack-Cache
X-Cache-Doesi
MageStack-Loadbalancer
MageStack-Cacheable
X-EC2-Instance-Id
MageStack-Cache-Lifetime
X-DN-Cache-Control
MageStack-Area
VAR-Cache
X-Cache-Detail
MageStack-Cache-Status
X-Goog-Meta-Policy
MageStack-Tag
TC-Cache-U
MageStack-Debug
MageStack-Config
Ttl
X-Goog-Meta-Replace
TC-Cache
TC-Cache-IC
X-Test
Keywords
X-MCB-Server
Aurora-Node
DNNOutputCache
X-Lb
X-Depends
X-Custom-Name
X-Geo-IP
FRONT-END-SECUREBROWSER
X-Protected-By
X-Secret
X-Response
X-Policy
X-Beget-Proxy
X-Nx-All
X-CacheID
X-Captured
X-SilverStripe-Cache
HitType
Machine
X-Nx
From
Ibf5scheme
Fastly-Debug-Digest
Magicmarker
Resin-Trace
X-Blog
X-Skip-Cache
X-Amzn-Trace-Id
X-Amzn-RequestId
X-Varnish-Id
X-Amz-Apigw-Id
X-Fastly-Request-Id
X-Requestid
X-Hit
TC-S-Cache-M
Og
N365rili
X-Flex-Tag
X-Flex-Tags
X-WEBMGR-CACHE
X-AOL-HN
X-SH-Cache-Status
X-Clara-ASAP
X-CacheLoc
X-Block-RuleID
X-ASAP-Cache
X-Block-Rule
X-Flex-Lastmod
X-Flex-Lang
Environment
Edgecast
Dis-Env
Prot
X-RiS-PX
X-WebKit-CSP-Report-Only
Fastly-Backend-Name
XX
X-Flex-Evend
X-Flex-Evstart
X-Flex-Community
X-Node-App
Description
X-AutoRu-App-Id
X-DevSrv-CMS
X-Varnish-Debug-Hits
X-FORWARDED-PROTO
X-Sid
X-Varnish-Ip
X-Highwire-Sitecode
ViewMode
Serverid
X-Cdn-Forward
X-RAMCache
X-TLS-Version
X-Vary-Options
X-Appversion
X-Pj-Cache-Status
BackendServer
Device
VSID
X-Appid
X-Reflector
CommunityServer
X-Reflector-Cache
X-Varnish-Action
X-Cache-Bypass
Xc
X-FastCGI-Cache-Status
X-Cache-Me-Harder
X-DB-Content-Length
X-Gateway-Rate-Limit-Delayed
X-Deity
X-Served
X-Access-Control-Allow-Origin
X-Tag-Playlist
X-ROUTING
X-Highwire-Smart-Code
Report-To
NLCacheNote
NODE
X-IP
X-APIVERSION
X-APIAUTH-VAL
X-ENDPOINT
X-ORIKEY
CF-Cache-Key
X-We-Are-Hiring
CDCHOST
Webserver
X-Page
AC-ELC
CF-Worker-Version
X-Aramark-CSID
X-Proxy-Id
X-ZSITES-DNS
X-Title
YF-ID
X-Phpwcms-Release
X-ENV
SBSS
X-Phpwcms-Page-Processed-In
X-Nginx
X-Svr
HSTS
TP-Cache
TP-L2-Cache
X-Box
X-Node-Id
X-NodeID
X-PBS-Appsvrip
X-PBS-Appsvrname
X-PBS-Fwsrvname
X-Status
X-Cache-Action
X-Cache-Extended
X-BServer
X-BPool-Back
X-Static
X-Airee-Node
X-Reqid
X-Gannett-Site-Version
X-Cluster
X-Compressed-By
X-ManagedFusion-Rewriter-Version
Content
Content-Sn
X-Varnish-Cached-TTL
X-Obvious-Info
X-Client-Id
X-ACCELERATE
X-Varnish-Cached
X-UPServer
X-Origin-Date
X-Sn-Servicetimems
X-Obvious-Tid
Tk
CommercePlatform-Version
Provider
Debug-Status
Ufe-Result
Session-From
ServerIP
EagleEye-TraceId
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
X-MCF-ID
X-Fpc
X-FPC
Ohc-Response-Time
TYPO3-Pid
X-B3-Sampled
ModuleCacheType
X-Proxy-Cache-Key
Backend-Powered-By
X-Goog-Meta-Goog-Reserved-File-Mtime
DB-Nickname
X-Beluga-Cache-Status
X-Beluga-Node
X-NewsFlow-Sitename
X-Resolver-IP
X-Cdn-Origin
X-Beluga-Trace
X-Beluga-Status
X-Beluga-Record
X-Beluga-Response-Time
X-Beluga-Response-Time-X
X-Layout
TYPO3-Sitename
X-MID-Host
X-Build-Id
REFRESH
X-ProBase-Server
X-Say-Cacheable
PBS
X-Backside-Transport
WN
X-Firefox-Spdy
X-FromPodPressCache
MageStack-Cache-Lifetime-Sent
MageStack-Cache-Warning
MageStack-Last-Modified
X-Say-TTL
X-SayCDN-TTL
X-Search-Id
X-Src-Webcache
X-PM-ID
X-Pass-Through
X-Max-Age
X-Mighty-Proxy
X-UnsetCookies
AMP-Access-Control-Allow-Source-Origin
X-WN-ClientGroup
X-V-Cache
Amfplus-Ver
X-Cache-Node
X-CH-Device
X-This-Proto
X-Processed
X-Instance
X-NoIndex
X-Custom-Header
X-Batcache-Reason
HTTPS
GranicusServer
X-Varnish-Backend-Beresp-Backend
X-Rack-CORS
X-Shopware-Cache-Id
X-Cache-Time
X-Shopware-Allow-Nocache
X-Route
X-Origin-Cache
MS-CV
Server-Id
X-M
X-HA
X-Now-Instance
X-Global-Transaction-ID
X-Powered-By-Home.Pl
X-Vol-Correlation
X-Wodby-Node
NGX
Tempo
Hosted-By
X-Cache-LB
X-Cname-TryFiles
Ssl-Proxy-Server
X-Vol-Mrp
X-XHTML-Minification-Powered-By
X-W3TC-Minify
X-Generated-Time
X-Varnish-Cache-Ttl
SINA-TS
Provided-Host
X-MainProfileCategory
Cf-Ipcountry
X-SCM-Server-Number
SINA-LB
X-MyName
X-MainProfileName
X-Webcelerate
Nitro-Cache
X-Test-Debug
X-MainProfileID
X-MainProfileURL
X-Powered-By-ADS
X-MrHost
X-Instance-Id
Session-Id
Hit-Count
Response-Time
Purge-Cache-Tags
X-HS-Status
X-Cache-FS-Status
X-DynamicCache
X-Rewritten-By
SERVER-ID
X-Server-Addr
X-Serv
X-PROCESSED-BY
X-Mobilized-By
X-Actual-Url
X-Xml-Http-Blocked
X-DEBUG
X-Oracle-Dms-Ecid
X-RENDER-TIME
Server-Ip
X-Scheme
X-Directory-Script
X-CACHE-KEY
X-COUNTRY-CODE
X-Nginx-Request-Processing-Time
X-Ms-Version
X-Appmachine-Duration
X-OPNET-Transaction-Trace
X-Telligent-Evolution
X-HP-CAM-COLOR
X-Appmachine-CreatedOn
X-Router
Fastly-Restarts
X-ORIGN-SERVER
Ews
X-Cache-Id
X-Ruxit-Js-Agent
X-NMT-Proxy
X-Enabled1
X-Enabled2
X-AMAZEEIO
X-Serverid
X-BIT-Node
X-Who
Servername
X-SSL
X-Origin-Upstream-Status
X-InDy-Time
HitInfo
X-Origin-Server
LB
PB-PID
Amp-Access-Control-Allow-Source-Origin
X-Varnish-TTL-Debug
X-Varnish-Age-Debug
X-Optimization
X-Enabled3
X-Proxy-Server
PB-RID
PROGMA
X-Appmachine-Name
X-InDy-Memory
X-InDy-Query
X-Ssl-Cipher
X-Cache-HT
X-Grid-Server
Language
X-GZip
X-From-Cache
X-Mobile-Rewrite
X-Expires
X-Avvio-Cms-Cacheload
VC-NoCache
X-Bitrix-Composite
X-Catalyst
X-Middleton-Pagespeed
X-Healthy
ProxiaInstanceId
Gzip
X-Vid
X-Tradeindia-SMgmt
X-Boot
ClientIP
F5-IpCliente
Actual-Object-TTL
SERVER-NAME
X-AppServer-Status
X-AppServer-Cache-Rule
X-Autoru-App-Id
X-Server-Hostname
X-VHosting-Cache
X-AppServer-Cache-Exception
X-Amzn-Remapped-Date
D
X-Varnish-Cache-Control
X-Amz-Meta-S3b-Last-Modified
X-Unique-Id
UrlWatchModule-Time
X-Tradeindia-Request-GUID
X-Cache-ID
X-Olaf
X-Magento-Route
X-SG-Server
Generate-Time
X-Accel-Cache-Control
Prototype-RootPath
X-CSRF-Token
X-CAMPUSSUITE-TENANT
PagesDisplayed
EQ-Cache
V-Cache-Ttl
X-CAMPUSSUITE-DEBUGGING
X-CAMPUSSUITE-ENVIRONMENT
X-Itkg-Cache-Tags
X-SSLTerm-Server
X-Fastly-Backend-Reqs
X-Country
X-Front-Cache
X-No-Session
X-Pageid
X-Beresp-Ttl
RSL-Trace-ID
X-Time-Spent
X-TEST
X-UT-Cache
Fastly-Drupal-Html
Origin-Vm
X-Served-From
WebServer
Sl-Pgid
Web-Server
Unique-Request-Id
X-Built-With
X-CGP
X-CloudBurst-Backend
X-Content-Type
X-BeResp-Ttl
Request-Time
Progma
Arrow-RequestId
ID
X-Bcwwwid
X-CloudBurst-Cache
X-HAProxy
FastCGI-Cache
EN-User
X-CloudBurst-WordPress
X-Abuse
X-XHR-Current-Location
X-ServiceProvider
X-Ruby-Cluster-ID
X-Jcms-Ajax-Id
X-Homeaway-Requestmarker
Requested-Host
X-NginX-Upstream
X-CloudBurst-Frontend
X-Cachable
NKBVHEADER
X-VG-WebCache
X-UType
X-Transaction-Name
X-DDM-SERVER-UPDATED
BlockPHPCallEnd
X-SuperCache
X-PressLabs-Stats
X-MSU-SOURCE
X-PoweredBy
X-Requested-With
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
X-SEA-Instance-Name
X-DDM-SERVER
HA-Ipaddr
HA-Host
HA-Servedtime
HA-Urlpath
L5d-Success-Class
HA-Georegion
HA-Geolon
HA-Cloudapp
X-Clx-Request
HA-Geocity
HA-Geocountry
HA-Geolat
X-UPSTREAM-Address
X-SCProxy
SB-Cache-Life
Returned-Status
SB-Cache-Remaining
SB-Site-Device
X-Amz-Meta-Version-Id
SB-Site-IE-VERSION
X-Az
Pragrma
MachineName
Id
MwpReleaseVersion
NZSpeedy
Page-Template
SS
X-Activity-Id
X-D2id
X-Old-Content-Length
X-ProcessESI
X-RemovedCookies
X-ReqId
X-Render-Time
X-Machine
X-Cache-Warmer
X-ASAP-Age
X-Enhanced-By
X-FG-RequestId
X-JoinUs
DrivedBy
X-Proto
X-Oracle-Dms-Rid
X-Mobile-Device
StatusCode
X-Pagely-Cache
X-Server-Ip
X-Mobile-Device-Type
X-Qiniu-Zone
X-Ser
CmsfirstPublishTimestamp
Httpd-Identifier
MSSmartTagsPreventParsing
MSThemeCompatible
X-Built-By
X-Log
X-Meta-MSSmartTagsPreventParsing
X-Meta-Imagetoolbar
X-Meta-MSThemeCompatible
X-Nginx-Page-Cache
X-FastCGI-Cache
X-Instance-Name
X-Dck
X-Debug-Message
X-Navigation-Version
X-Cache-TTL-Age
X-Cache-TTL-Current
X-Firewall
X-Server-Generated