Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
X-AspNet-Version
Age
Content-Language
X-Pingback
P3P
Via
X-UA-Compatible
Upgrade
Expect-CT
Access-Control-Allow-Origin
X-Adblock-Key
Content-Security-Policy
X-Cacheable
X-Check
X-Language
X-Template
X-Varnish
Alt-Svc
X-Generator
X-Buckets
X-Drupal-Cache
P3p
X-Xss-Protection
X-Request-Id
X-Type
WPE-Backend
Referrer-Policy
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-Powered-By-Plesk
Host-Header
Content-Location
X-ShopId
X-Sorting-Hat-ShopId
MS-Author-Via
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-Section
X-Sorting-Hat-PodId
X-Dc
X-Sorting-Hat-PrivacyLevel
X-ShardId
X-Sorting-Hat-PodId-Cached
X-Alternate-Cache-Key
X-Runtime
X-UA-Device
X-Sorting-Hat-FeatureSet
X-Powered-CMS
X-IPLB-Instance
X-Served-By
X-FRAME-OPTIONS
Cartoon
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Cache-Status
Access-Control-Allow-Credentials
X-Amz-Cf-Id
X-Request-ID
Status
X-Via
X-Iinfo
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Timer
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-ServedBy
CF-Cache-Status
X-Contextid
X-PC-Hit
X-PC-Key
X-Backend
Powered-By
X-PC-Date
X-PC-AppVer
X-PC-Host
X-Mod-Pagespeed
X-CST
Content-Encoding
X-Host
X-WPE-Loopback-Upstream-Addr
X-Logged-In
X-Server
X-CDN
X-DIS-Request-ID
Keep-Alive
X-Rid
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Cache-Hit
X-Port
X-Cache-Enabled
X-Endurance-Cache-Level
X-Server-Powered-By
X-Tumblr-Pixel-1
X-Original-Date
X-Accel-Version
X-Nginx-Cache-Status
X-Robots-Tag
X-Drupal-Dynamic-Cache
X-NewRelic-App-Data
X-Ua-Compatible
X-Seen-By
X-Wix-Request-Id
X-Page-Speed
X-Tumblr-Pixel-2
X-Turbo-Charged-By
X-Wix-Punisher
X-Content-Powered-By
X-Forwarded-For
X-Proxy-Cache
X-Content-Digest
X-Forwarded-Proto
X-AH-Environment
X-Pad
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Varnish-Cache
X-LiteSpeed-Cache
X-Rack-Cache
WP-Super-Cache
Content-Security-Policy-Report-Only
X-Tumblr-Pixel-3
X-GitHub-Request-Id
SPRequestGuid
X-Request-Country
Edge-Control
X-SharePointHealthScore
X-MS-InvokeApp
X-XRDS-Location
MicrosoftSharePointTeamServices
X-Cache-Lookup
Timing-Allow-Origin
X-Cnection
X-Node
X-FW-Hash
X-Amz-Request-Id
X-Content-Security-Policy
X-Amz-Id-2
X-FullPageCaching
Charset
Cf-Railgun
X-FW-Static
X-FW-Serve
X-FW-Type
Request-Id
X-Trace
X-Died
X-Webcom-Cache-Status
X-PhApp
Edge-Cache-Tag
Request-Context
X-HS-Cache-Config
X-Hits
X-BC-Stapler
X-HS-Content-Id
X-CF-Powered-By
SPIisLatency
SPRequestDuration
X-INKT-SITE
X-INKT-URI
X-PHP-Backend
MicrosoftOfficeWebServer
X-Newrelic-App-Data
X-Webserver
Access-Control-Expose-Headers
Access-Control-Max-Age
Composed-By
X-Safe-Firewall
Grace
EagleId
X-Swift-SaveTime
X-Swift-CacheTime
Served-By
X-Spip-Cache
X-CDN-Pop-IP
X-CDN-Pop
X-Fastly-Request-ID
X-Firenze-Processing-Times
X-Hyper-Cache
X-Backend-Server
X-VCache
X-Tumblr-Pixel-4
Liferay-Portal
X-Dw-Request-Base-Id
X-Server-Name
X-SERVER
X-Device
X-StackifyID
X-Microcache
X-FB-Debug
Surrogate-Control
X-LiteSpeed-Cache-Control
Refresh
Front-End-Https
X-SS-Location
X-SS-Conf
X-Cloud-Trace-Context
Xkey
X-RateLimit-Remaining
X-Clacks-Overhead
X-TNCMS
X-Loop
X-RateLimit-Limit
Content-Style-Type
X-DNS-Prefetch-Control
X-RateLimit-Reset
Rating
Content-Script-Type
Public-Key-Pins
X-XN-Trace-Token
X-Jimdo-Wid
X-XN-XNHTML
X-HS-Combine-CSS
X-Jimdo-Instance
X-Acc-Exp
X-DDC-Arch-Trace
X-Vtex-Processado-Em
X-User-Agent
X-WebKit-CSP
Fpc-Cache-Id
X-Age
X-Cache-Config
X-Dscp-Value
X-Middleton-Response
Response
X-Middleton-Display
Display
X-Sol
X-ServerName
X-Hostname
X-N-OperationId
X-Px
X-Generated-By
X-Cached
X-Tumblr-Pixel-5
X-Tumblr-Content-Rating
X-Topify-Platform
X-Correlation-Id
X-MiniProfiler-Ids
X-Url
X-Zen-Fury
X-Request-Time
X-Kinsta-Cache
X-Handled-By
P-LB
P-WS
X-Magento-Tags
TCN
X-Outils-CS
X-Whom
X-Loopia-Node
X-OneAgent-JS-Injection
X-Amz-Version-Id
PageSpeed
X-CMS-Version
Edge-Control-Message
X-B-Cache
X-DynaTrace
Dmn
ServedBy
X-URL
X-Content-Options
X-Cached-By
X-Debug-Info
X-Varnish-TTL
Rt-Fastcgi-Cache
X-Msg-2-Log
X-From
X-LBLID
Access-Control-Request-Method
X-Edge-Location
X-Location-Id
X-DynaTrace-JS-Agent
X-Ruxit-JS-Agent
Imagetoolbar
Host
Product
Public-Key-Pins-Report-Only
X-Goog-Hash
Surrogate-Key
X-FORWARDED-FOR
Powered
X-AspNetWebPages-Version
X-Varnish-Cache-Hits
X-CacheServer
X-Engine
X-Cache-Rule
X-Shard
X-Passed-To
DynaTrace
X-Actual-URL
X-Returned-From
X-Returned-From-DLL
X-Passed-To-DLL
X-Original-Request
X-Upstream
Retry-After
Fhost
X-Signature
X-Fastcgi-Cache
X-Powered-By-VTEX-Janus-ApiCache
X-NWS-LOG-UUID
X-F-Cache
X-Cluster-Node
X-Vtex-Remote-Cache
No
X-Vtex-Processed-At
X-VTEX-Cache-Status-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-Varnish-Beresp-Ttl
X-Passed-To-PostProcessResponse
X-Varnish-Beresp-Status
X-Accel-Expires
X-Varnish-Beresp-Grace
X-SRCache-Fetch-Status
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-SRCache-Store-Status
X-Passed-To-BeforeDispatch
X-Via-JSL
X-Stale
X-Platform
Alternate-Protocol
X-Platform-Processor
X-Platform-Router
X-Umbraco-Version
X-Micro-Cache
X-Recruiting
X-Art-Request-Id
X-Platform-Cluster
X-Varnish-Host
X-LW-Cache
Arr-Disable-Session-Affinity
X-Version
X-Cache-Info
X-Response-Time
X-Magento-Cache-Debug
X-Developer
Ohc-File-Size
X-Device-Type
X-Source
X-Hosted-By
X-Rocket-Nginx-Bypass
X-HS-Content-Campaign-Id
Fastcgi-Cache
X-ApacheServer
X-PERF
X-URLSCHEME
X-Application-Context
WZWS-RAY
X-Powered-By-360WZB
X-S
X-Cdn
X-Matrix-Proxy
X-Matrix-Server
X-UD-Method
X-Microcachable
X-Supported-By
Cache-Provider
X-Instart-Request-ID
Origin
X-Rnd
X-App-Status
Last-Published
X-Tumblr-Pixel-6
X-EdgeConnect-Origin-MEX-Latency
X-Frame-Option
Generator
X-Platform-Server
Akamai-IP
X-Shop-Id
X-Defender
Pagespeed
X-Gamma-Serve
X-Storage
X-TransIP-Balancer
X-HOST
X-Cache-TTL
X-Microcache-Status
X-Varnish-HitMiss
X-Cache-Namespace
X-RESOURCE
X-Translation
X-Varnish-Count
X-Daa-Tunnel
X-Track
Version
X-I-Sp
X-App-Hosting
X-BS
X-TransIP-Backend
X-Front
X-Powered-By-VelaWeb
Content-Hash
X-Server-ID
X-Hypernode
X-Cache-Age
Powered-By-ChinaCache
X-Platform-Cache
X-Pantheon-Site
X-Pantheon-Environment
Surrogate-Key-Raw
HTTPS
X-Pantheon-Phpreq
X-Sapient
X-Flow-Powered
X-NetCat-Version
X-Drupal-Cache-Tags
X-Cache-Key
X-WebServer
ServerID
RTSS
X-Route-Server
X-ATG-Version
Cache-Key
X-Powered-By-VTEX-Janus-Edge
X-Duration
X-EdgeConnect-MidMile-RTT
USPLoggingUUID
X-Varnish-RemainingTTL
Lsrequestid
X-I
X-Varnish-ObjectSource
X-Varnish-Seen-By
X-Varnish-RemainingLife
X-ORACLE-DMS-ECID
X-Dispatcher
X-Firenze-Processing-Time
X-Varnish-GracePeriod
Pool
X-Last-Modified
X-Expires-Orig
X-CSRF-Protection
X-Vcache
X-Director
Allow
X-Ezoic-Cdn
X-Page-Cache
X-Cache-Tags
X-SV-CreatedAt
X-SV-Pid
X-SDS
X-Ttl
X-SV-Duration
X-Content-Encoded-By
SSPAppContext
X-Cache-Operation
Content-Disposition
X-Server-Upstream
X-SV-Nginx-Duration
X-SSL-Cipher
X-SV-Edge
MIME-Version
X-SV-FromDBCache
X-SSL-Protocol
X-Cache-Debug
Pv
X-Litespeed-Cache
X-Generated
X-Drupal-Cache-Contexts
X-Vcap-Request-Id
SN
X-SV-Expires
X-Client-IP
S-Cnection
X-SV-Cacheable
Cneonction
X-SV-CacheTags
X-Varnish-Age
X-Lambda-Id
Accept-Encoding
X-Varnish-Cacheable
X-Environment
NnCoection
X-Magento-Cache-Control
X-Server-Id
X-Grace
Node
X-LB-Node
AMF-Ver
X-Abgroup
X-CJ-Soft
X-Origin
X-ARC
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Cache-Control-Orig
X-Edge-IP
X-Cache-Server
Server-Timing
X-Debug
X-Revision
Wsr-Cache
X-NoCache
X-Time
X-Amz-Meta-S3cmd-Attrs
Req-Id
FAI-W-FLOW
X-Varnish-Ttl
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Varnish-Url
Fw-Via
X-Goog-Stored-Content-Encoding
X-IsCacheURL
X-GUploader-UploadID
Section-Io-Id
IBM-Web2-Location
X-Akamai-Device-Characteristics
X-N
X-Hiawatha-Cache
X-Magnolia-Registration
X-Bb-Deploy-Id
X-UPSTREAM
Backend
Server-Info
ServerName
Server-Name
Location
X-Oneagent-Js-Injection
X-Yadis-Location
X-ID
X-Runtime-Rack
X-TTL
X-PwB-Node
X-ORACLE-DMS-RID
X-WEBSERVER
X-Cache-Expires
Page-Completion-Status
X-Esi
Content-Encoding-Handler
X-Cache-Engine
X-App-Server
X-Dispatch
IM-Version
X-Geo-Country
X-Content-Age
X-GeoIP-Country-Code
X-Cache-Lifetime
Srv
Fastly-Debug-Digest
X-Avg-Cookie-Expires
X-Akamai-Device-Model
X-AOL-HN
Content-MD5
X-AVG-Country-Code
X-Akamai-Edgescape
X-BackendServer
X-Cache-Only-Varnish
X-Redman-Backend
X-Discourse-Route
X-Varnish-Backend
Front
X-Redman-Final-Url
X-Vhost
X-Real-Server
X-Content-Security-Policy-Report-Only
X-Country-Code
S
X-Config-Blacklist-Version
X-Amz-Storage-Class
PICS-Label
Content-Transfer-Encoding
Nodo
X-Varnish-IP
X-LB
X-Speed-Cache-Key
X-Speed-Cache
X-RequestId
X-Cache-Handler
HCVer
W
Proxy-Connection
X-Cache-Type
Qs-Cache
Nitro-Cache
X-Always-Cache
X-SO
HAVer
If-Modified-Since
X-ServerID
X-Cache-Level
SRV
X-Url-Base
Cache
X-FTR-Request-ID
X-Cache-Fix
X-Sucuri-ID
Eomportal-Instance
X-Nbs
Author
X-SRV
X-Cache-PageType
X-Proxy
X-Middleware-Start
X-Dealeron-Original-Url
X-Varnish-Retries
WWW-Authenticate
Frame-Options
X-Dealeron-Backend
X-CF-Passed-Proto
X-Empowered-By
X-High-Performance
Cache-Tags
X-DealerOn
X-Pressidium-NinukisWP-Ver
X-Location
X-GeoIP-Country-Name
X-Cookie-Domain
Environment
Accept-Charset
CacheControlHeader
X-Stage
X-Nginx-Cache
X-Processing-Time
X-Rq
X-BKSrc
Cached
Pf.Web.Request.Id
MC
X-Worker
X-Frontend
X-VARITI-CCR
X-Airee-Node
X-Cache-CFC
Xc-Version
X-Env
X-Resource
X-HTML-Minification-Powered-By
X-Dynatrace-Js-Agent
VANITY-HOST
X-PF-Uncompressing
X-SRCache-Key
X-Content-Type-Option
X-Browser
X-Cache-Device-Type
X-WPL-DATA
X-Shield-Request-Id
Cache-Tag
Contao-Page-Layout
X-Sucuri-Cache
Pics-Label
X-Purge-URL
Use-Proxy
X-Correlation-ID
X-Varnish-Server
X-Ruxit-Js-Agent
X-Litespeed-Cache-Control
X-Symfony-Cache
Custom-Header
X-Purge-Host
X-TTFB-L
Cm-Server
BALANCEDTO
X-Unbounce-Variant
X-Unbounce-PageId
From-Origin
X-Unbounce-VisitorID
X-Rocket-Nginx-Serving-Static
X-Srv
X-Id
X-CB-Server
X-Server-Instance
Thanks
X-AF-Userserver
X-Remote-Addr
X-TTFB
X-SmugMug-Values
Smug-CDN
X-SmugMug-Hiring
Tracecode
X-Source-ID
X-Akamai-3PM-SW-Version
X-FW
X-CAPServer
X-Akam-SW-Version
IISExport
X-WebKit-CSP-Report-Only
X-Client-Vid
X-EPiphany-Vid
X-Cache-Control
X-Pagename
X-Hit-Cache
X-Framework
X-Client-Image-Vid
NetMindSessionID
X-Varnish-Hostname
NtCoent-Length
SEOMOZ
X-Compress-Hint
X-Cacheable-TTL
X-ACMCache
Identity
X-HW
X-Atraveo-ETag
X-Atraveo-Expires
MJ12bot
X-CDN-Forward
X-Page
X-Atraveo-TTL
X-Atraveo-Set-Cookie
Local-Info
X-Atraveo-Param-Rm
X-Runtime-Memory
X-Atraveo-Varnish-Server-Id
X-Atraveo-From-Varnish-Cache
X-NginX-Cache
X-Real-IP
X-Garden-Version
Ufe-Result
X-Atraveo-Cache-Control
X-Atraveo-Zone
Cmsid
X-Omnis-SiteID
Proxy-Agent
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
Cmstype
X-Abuse
X-Drectory-Script
X-Server-IP
X-Info
X-Directory-Script
X-Force
X-Provisioner-Version
X-FW-Server
Beyond-Iis
X-Akamai-Transformed
X-WA-Info
Id
X-Trace-Id
Accept-CH
SVR
X-IIJ-Cache
X-PRAM
X-IP
X-Highwire-SessionId
X-Session-Reinit
Access-Control-Allow-Method
X-SmartBan-URL
X-SmartBan-Host
X-Highwire-RequestId
X-Nginx-Host
NLCacheNote
X-Domain-Checked
X-App
X-Ser
X-Resolver-IP
Machine
X-Sites
X-Analytics
X-NodeID
X-FPC
X-VC-Enabled
Ohc-Response-Time
X-DTC
X-Mobilized-By
X-W3TC-Minify
Accept-Language
EagleEye-TraceId
AC-ELC
X-JG-Page-Cache
Description
HitType
X-Fedora-School-Id
X-RTag
X-Resty-Request-Id
Keywords
ServerSignature
ServerTokens
X-Orig-Vary
X-ASAP-Cache
X-Clara-ASAP
X-Fstrz
X-SERVER-NAME
Service-Worker-Allowed
X-Locale
A-Powered-By
X-Dns-Prefetch-Control
X-ClientSide-Caching
X-RealServer
Bios
X-Blog
X-Request-Uri
WN
X-Adnet
X-Plat
X-LB-Server
Hummingbird-Cache
X-WN-ClientGroup
SS
SERVER-ID
X-WR-Flags
X-GeoIP
X-CACHE-TTL
X-Sys-Req-ID
Content_type
X-Secret
X-Cache-Doesi
X-Backend-Status
X-Time-Microsecs
Backend-Timing
X-Session-ID
X-Batcache
X-Search-Id
X-Adobe-Content
X-AEM
X-Yottaa-Metrics
Adm-Server
X-Adobe-Loc
X-Rewritten-By
X-EC2-Instance-Id
X-Smartcache-Timeout
X-FORWARDED-PROTO
X-MCB-Server
X-Unique-ID
X-VC-TTL
Web-App-Origin-Name
X-ACCELERATE
X-HydroSheep
X-Cf-Powered-By
X-WP
X-ManagedFusion-Rewriter-Version
X-Smartcache-Keys
X-Yottaa-Optimizations
X-Traffic
X-OpenCart-Lightning
X-GoCache-CacheStatus
X-Twitter-Response-Tags
Url
X-Transaction
Yoncu-Errno
X-ServerIndex
X-Route-To
NODE
X-TB-M
X-Server-Addr
X-Webstats-RespID
From
X-Connection-Hash
X-Node-Name
X-RiS-UFDI
SBGI-7
X-Cocoon-Version
X-Gannett-Site-Version
X-Title
X-Culture
X-PROCESSED-BY
X-LP
X-Refresh
SBGI-5
Og
SBGI-9
Gzip
RN-Server
X-Key
X-LW-Web-Server
SBGI-1
SBGI-10
X-Layout
X-FireWall-Port
X-Varnish-Id
X-CacheID
X-Map-Context
ClientIP
F5-IpCliente
X-Grid-Server
X-Webkit-CSP
X-Debug-Token
RequestId
X-Cache-Node
Report-To
Myheader
TheAnswer
X-4ormat-Cacheable
Max-Age
X-Webcelerate
Magicmarker
X-Powered-By-Home.Pl
X-ARRServer
Edit
X-Varnish-Debug-Age
X-Src-Webcache
X-Disney-Akamai-Rule
X-Machine
Disablevcache
X-Protected-By
X-Req-Head-Response
X-DataDome
SHInfo
X-BPool
Play-Detected-UserAgent
X-Depends
X-Cache-TTL-Age
X-Cache-TTL-Current
Play-Detected-Device
EN-User
SBGI-Device
SBGI-RealPath
SBGI-RenderTime
X-Varnish-Debug-TTL
X-Cache-Via
X-BPool-Bx-Cache
X-BPool-Back
X-Agent
Swift-Performance
X-NginX-Server
X-BPool-Fx-Cache
Resin-Trace
X-Origin-Server
X-BServer
X-Distil-CS
NZSpeedy
X-Detected-Device
Web
Dis-Env
X-Distributor
Device
X-A
X-Balanceador
Server-ID
X-Rack-Cors
X-Role
X-Hosting-Env
X-Pagely-Cache
VServer
X-Cdn-Forward
X-Middleton-Pagespeed
Noq
Ram
X-Batcache-Reason
X-Highwire-Smart-Code
X-Highwire-Sitecode
Ramp
SiteSpeed
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Jphone-Copyright
X-DEBUG
X-Amz-Meta-Cb-Modifiedtime
AMP-Access-Control-Allow-Source-Origin
X-SDE-Name
XDomainRequestAllowed
Fastly-Backend-Name
Lb
X-V
X-Captured
X-Serv
X-Varnish-ID
X-Cache-Varnish
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
Hamster
X-Varnish-Action
X-Viator-Tapersistentcookie
Backend-Name
BackendServer
CommercePlatform-Version
SINA-LB
X-Rack-CORS
X-Confluence-Request-Time
X-XHTML-Minification-Powered-By
X-OPNET-Transaction-Trace
X-E
N365rili
X-SH-Cache-Status
PagesDisplayed
X-Varnish-Cache-Ttl
Ibf5scheme
Prama
NS-VaryByCustom-Key
X-Compressed-By
X-CacheDebug
X-Cache-Me-Harder
X-Node-Id
X-DynamicCache
X-JSESSIONID
X-Varnish-Hits
Content-Generator
X-Hosting
X-Rewrite
X-Runtime-Affili
X-Old-Content-Length
X-Wikidot-Static-Cache
Backend-IP-Port
ID
X-Wikidot-Backend
MS-CV
X-App-Runtime
X-Amz-Id-1
X-Amcomm-Site
OriginServer
CLMOB
X-Cache-Time
X-Origin-Id
X-Ghost-Cache-Status
Access-Control-Allow-Header
X-Cache-On
X-B2f-Not-Route
X-Autoru-Host
Upgrade-Insecure-Requests
X-Goog-Meta-Policy
X-Autoru-LB
X-Data-Request
X-GSL-Server
X-Cluster
X-CRA-DC
X-DB-Content-Length
X-DN-Cache-Control
X-Generated-Time
X-Dw-Trace-Id
X-Frames-Options
X-Gyrobase-Publication
X-Rebelmouse-Cache-Control
X-Goog-Meta-Replace
X-AutoRu-App-Id
Home
Il-Cl
MW-Webserver
Proxy-Cache
X-Varnish-Cache-Local
X-Response
X-Redirector
COMMERCE-SERVER-SOFTWARE
X-RDP
Warning
X-Svr
X-Zendesk-Origin-Server
X-Rebelmouse-Surrogate-Control
X-Aramark-SID
X-HashTwo
Traffic-Origin
Apachenode
TZ-Server
X-Zendesk-User-Id
X-MidCOM-Meta-Cache
SINA-TS
MSSmartTagsPreventParsing
X-MAT-GEO
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
Server-Ip
MSThemeCompatible
X-Varnish-Cached
X-Varnish-Cached-TTL
X-Header
X-Meta-MSThemeCompatible
X-Proto
SB-Cache-Remaining
SB-Site-Device
SB-Site-IE-VERSION
SB-Cache-Life
Page-Template
X-Proxy-Skip
SG
Paypal-Debug-Id
X-UPServer
X-ServerAddr
X-Processed-By
Dispatcher
Cleartype
X-VNode
Nginx-Cache
ScoreTracker
AsisCache
X-Application
X-Mobile-URL
X-HP-Trace-Project
X-Built-With
X-MCF-ID
X-Script
X-Bcwwwid
X-Cjtype
X-HP-Trace-ID
Cteonnt-Length
X-Geo-IP
X-ASAP-Age
X-Desc
X-UnsetCookies
X-Artvisual-Server
X-AMAZEEIO
X-Actindo-Thread-Id
X-Actindo-Rs
X-Skip-Cache
X-ESI
X-Render-Time
X-SCM-Server-Number
X-Proxy-Cache-Key
Edgecast
X-Nginx-Request-Processing-Time
X-Actindo-Request-Id
X-Varnish-Grace
Www.Aujourdhui.Com
Provider
Language
X-SilverStripe-Cache
X-Enhanced-By
X-FG-RequestId
X-ReqId
Hostname
X-DS1D
X-Amz-Meta-Content-Md5
X-ZSITES-DNS
X-Who
DrivedBy
X-Tag-Playlist
Viewport
Worker
X-Cache-Detail
X-LBPoolMember
X-Reflector
X-Reflector-Cache
VC-NoCache
X-Magento-Lifetime
X-Dev
X-Cms-Mode
Aoestatic
X-PM-ID
TP-L2-Cache
X-Origin-Cache
X-NID
PServer
Ews
Strikingly-Cache-Region
X-Author
Ttl
Strikingly-Cached-Version
Strikingly-Cached
X-Magento-Action
TP-Cache
X-AISO-Cacheable
Ctx
X-AISO-Server
X-HS-Status
X-Upgrade-Enabled
MyHeader
Xc
X-AISO-Cache
X-Lb
X-Client-Ip
X-Forwarded-Host
X-Sid
X-7d-Instance-Id
X-DDM-SERVER
HA-Geolon
X-7d-Trace-Id
X-DDM-SERVER-UPDATED
X-Distributed-By
X-Hash
HA-Geocountry
HA-Geolat
HA-Urlpath
HA-Georegion
HA-Geocity
HA-Ipaddr
HA-Servedtime
X-Bip
X-VTEX-Cache-Status-Janus-Edge
X-Clx-Request
HA-Host
X-Qiniu-Zone
X-Qnm-Cache
X-CACHE-KEY
Requested-Host
X-Phpwcms-Page-Processed-In
X-Uncacheable
X-Reqid
X-UType
X-SuperCache
X-Phpwcms-Release
X-Proxy-Id
X-SE-Debug
X-PoweredBy
X-VG-WebCache
XX
Unique-Request-Id
HA-Cloudapp
X-M-Log
X-MSU-SOURCE
DB-Nickname
BlockPHPCallEnd
X-Log
X-REDIRECTSERVER
X-M-Reqid
X-Flex-Lang
X-RequesterIP
X-RemovedCookies
X-ProcessESI
X-Original-IP
X-SATserver
X-TA-CDN-Provider
X-Cache-Ttl
X-Ants-Machine-Id
X-Ants-Host
CDCHOST
X-Obvious-Tid
X-Obvious-Info
Dtk-Cache-Check-0
X-SV
X-Server-Generated
X-Dynamic-Cache
Request-Country
Request-EU
X-Instance
X-Feed
WSCLoggingUUID
Tk
X-COUNTRY-CODE
X-Custom-Name
X-Global-Transaction-ID
X-Flex-Tags
X-Flex-Tag
X-Flex-Lastmod
X-Max-Age
X-Nginx
X-We-Are-Hiring
X-Profiler
X-PressLabs-Stats
X-Pool
X-KoobooCMS-Version
X-Flex-Evstart
V-TTL
HSTS
X-Test-Debug
X-Pubstack
X-Backside-Transport
X-CD
X-Flex-Evend
X-Flex-Community
X-Device-Item
WP-FROM-CACHE
Session-From
X-HAProxy
X-Generation-Time
X-FreeTag-Count
X-Fpc
X-Homeaway-Requestmarker
X-Jcms-Ajax-Id
X-OpenUrlRewriter-Debug
X-OCTOPOD
X-Nitro-Cache
X-Member
X-D-Time
X-Config-By
NKBVHEADER
Load-Balancer
L5d-Success-Class
Kanooh-Host
Progma
X-AWS
X-CGP
X-B3-Traceid
X-B3-Spanid
X-PG
X-PHP-Response-Code
X-Hit
X-CO-Host
X-Cache-Bypass
TC-S-Cache-M
X-Node-App
X-Unique-Id
ServerIP
Expiries
Debug-Status
CS-SERVER
TC-S-Cache
TC-Cache-U
X-Streams-Distribution
X-Sn-Servicetimems
X-ServiceProvider
X-S-Misc
X-XHR-Current-Location
Xcache
TC-Cache-IC
TC-Cache
Response-Time
IES-Server
X-VC-Debug
X-Cname-TryFiles
X-Cache-ID
X-Beatles
X-CSRF-Token
X-Debug-Token-Link
X-Gateway-Rate-Limit-Conn
X-ETag
X-Deity
X-Apm-Telemetry-Syncmark
RSB-LINK
X-VCS-Cacheable
X-Shopware-Cache-Id
X-Shopware-Allow-Nocache
X-VCS-Ttl
Be
HostName
GranicusServer
EQ-Cache
X-Gateway-Rate-Limit-Delayed
X-HEAD
MageStack-Cache
MageStack-Area
IsMobile
MageStack-Cache-Hits
MageStack-Cache-Lifetime
MageStack-Config
MageStack-Cacheable
MageStack-Cache-Status
Generate-Time
1A-CountryCode
X-Made-On
X-M
X-Header-Treatment
X-Pj-Cache-Status
X-Served
X-Varnish-Debug-Hits
X-Sorting-Hat-Expire-Cache
X-Served-Server
X-Route
X-PBY
X-Pass-Through
X-Timestamp
X-Site
X-Ssl-Cipher
X-Static
X-NMT-Proxy
DeleGate-Ver
X-Status
MwpReleaseVersion
X-BackendProxy
Cache-Status
Amp-Access-Control-Allow-Source-Origin
Httpd-Identifier
StatusCode
MachineName
Container
X-Instance-Name
X-VC-Cache
X-VC-Cacheable
X-Custom-Header
X-ClusterID
X-Cache-Original-TTL
X-DSMX-Render-MS
X-DSMX-Rewrite-MS
X-Pixelsilk-Version
X-Pixelsilk-Server
X-Full-Url
X-Cache-Id
X-ACLR-Version
CpuTime
Cacheid
X-VC-Hash
Server-Id
User-Agent
X-Ab-Selection
V-Age
MageStack-Debug
MageStack-Loadbalancer
X-Catalyst
X-Cache-FS-Status
Session-Id
X-Container
X-Healthy
X-MyName
X-Instance-Id
X-HP-CAM-COLOR
ReqUrl
ProxiaInstanceId
X-Litespeed-Tag
X-IP-Address
X-Instart-Cache-Id
X-Pageid
X-Pool-Info
XDisk
X-Transaction-Name
X-RAMCache
X-NewsFlow-Sitename
X-Nginx-Request-Time
FRONT-END-SECUREBROWSER
Fastly-Restarts
Actual-Object-TTL
X-Avvio-Cms-Cacheload
X-Backend-Host
X-Hrouter
X-Cache-Extended
X-Box
X-WebNode
X-Via-NSCOPI
X-PBS-Fwsrvname
X-PBS-Appsvrname
X-PBS-Appsvrip
X-SSLProxy
X-SSLUpstream
X-UPSTREAM-Address
X-Svr-Proxy
X-Front-Cache
X-FIRSTBase
X-Backend-TTL
X-B
X-Az
X-BP-NSA-REQID
X-Debug-Message
X-NewCloud-V-Cache
X-HA
X-FastCGI-Cache-Status
X-AppVersion
X-Amz-Meta-Version-Id
MageStack-Tag
MageStack-PageSpeed
MageStack-Magento-Version
MageStack-Web-Node
Request-Filtered-By
X-Activity-Id
Tesla.Performance
X-Ocache
X-ProBase-Server
Provided-Host
HA-Front
Copyright
Referer
RSL-Trace-ID
X-Country
X-CH-Device
X-Beresp-Ttl
CommunityServer
Amfplus-Ver
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-Serverid
X-T
X-UT-Cache
X-UA
X-Hstore