Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
P3P
X-AspNet-Version
Age
X-Pingback
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Template
X-Language
X-Generator
Alt-Svc
X-Buckets
X-Request-Id
X-Drupal-Cache
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Content-Location
Host-Header
X-Runtime
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-ShardId
X-Dc
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sorting-Hat-Section
X-Sorting-Hat-PodId-Cached
X-Alternate-Cache-Key
MS-Author-Via
X-FRAME-OPTIONS
Cartoon
X-Powered-CMS
X-UA-Device
X-IPLB-Instance
X-Served-By
Access-Control-Allow-Headers
Status
Access-Control-Allow-Credentials
X-Amz-Cf-Id
Access-Control-Allow-Methods
P3p
X-Cache-Status
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
CF-Cache-Status
X-Contextid
X-Backend
Referrer-Policy
Powered-By
X-PC-Hit
X-PC-Key
X-DIS-Request-ID
X-Mod-Pagespeed
X-ServedBy
X-PC-Date
X-PC-AppVer
X-PC-Host
Content-Encoding
X-WPE-Loopback-Upstream-Addr
X-CST
X-Logged-In
X-Request-ID
Keep-Alive
X-Rid
X-Host
X-Server
X-Cache-Hit
X-Port
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-CDN
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Server-Powered-By
X-Robots-Tag
X-Endurance-Cache-Level
X-Nginx-Cache-Status
X-Tumblr-Pixel-2
X-Wix-Request-Id
X-Seen-By
X-Wix-Server-Artifact-Id
X-Accel-Version
X-Turbo-Charged-By
X-Original-Date
X-Page-Speed
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
WP-Super-Cache
X-Content-Digest
X-Proxy-Cache
X-AH-Environment
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rack-Cache
X-Tumblr-Pixel-3
X-Varnish-Cache
X-LiteSpeed-Cache
X-GitHub-Request-Id
X-Ua-Compatible
SPRequestGuid
X-SharePointHealthScore
X-Request-Country
Edge-Control
X-MS-InvokeApp
X-XRDS-Location
MicrosoftSharePointTeamServices
X-Cnection
X-Cache-Lookup
Timing-Allow-Origin
X-Amz-Id-2
X-Amz-Request-Id
X-Died
Cf-Railgun
X-FW-Hash
X-Node
X-Trace
Charset
X-FW-Type
X-FW-Serve
X-FW-Static
Request-Id
X-Webserver
Edge-Cache-Tag
X-Content-Security-Policy
X-FullPageCaching
X-HS-Cache-Config
X-Webcom-Cache-Status
X-HS-Content-Id
X-PhApp
MicrosoftOfficeWebServer
X-Hits
SPIisLatency
X-Safe-Firewall
SPRequestDuration
X-CF-Powered-By
Request-Context
Access-Control-Max-Age
X-Newrelic-App-Data
X-INKT-URI
X-INKT-SITE
X-BC-Stapler
X-PHP-Backend
Composed-By
Access-Control-Expose-Headers
X-Swift-CacheTime
X-Swift-SaveTime
Grace
Served-By
EagleId
X-CDN-Pop-IP
X-Tumblr-Pixel-4
X-CDN-Pop
X-SERVER
Liferay-Portal
X-Hyper-Cache
X-Spip-Cache
X-Backend-Server
X-Device
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-Microcache
X-LiteSpeed-Cache-Control
X-Server-Name
X-VCache
X-RateLimit-Remaining
Rating
X-ServerName
X-RateLimit-Limit
X-FB-Debug
Content-Style-Type
X-Cloud-Trace-Context
X-Clacks-Overhead
Content-Script-Type
X-RateLimit-Reset
X-Wix-Renderer-Server
X-Jimdo-Wid
X-Jimdo-Instance
Surrogate-Control
X-DDC-Arch-Trace
X-Firenze-Processing-Times
Front-End-Https
X-Acc-Exp
X-User-Agent
X-TNCMS
Real-Hostname
X-Loop
Refresh
Public-Key-Pins
X-Cache-Config
X-Tumblr-Content-Rating
X-XN-Trace-Token
X-XN-XNHTML
X-HS-Combine-CSS
X-DNS-Prefetch-Control
X-StackifyID
X-Middleton-Response
X-Middleton-Display
Fpc-Cache-Id
Response
X-Sol
Display
X-Age
Xkey
X-Hostname
X-SS-Conf
X-SS-Location
X-Microcachable
X-Vtex-Processado-Em
X-Generated-By
X-Cached
X-Tumblr-Pixel-5
X-Zen-Fury
X-Cdn
X-Px
X-N-OperationId
X-OneAgent-JS-Injection
PageSpeed
X-Servedby
X-Topify-Platform
X-MiniProfiler-Ids
X-Cached-By
X-Frame-Option
X-Correlation-Id
X-Request-Time
X-WebKit-CSP
TCN
X-Url
X-Kinsta-Cache
P-WS
P-LB
X-Handled-By
X-Whom
X-Amz-Version-Id
Rt-Fastcgi-Cache
X-CMS-Version
X-Ruxit-JS-Agent
X-Outils-CS
X-Varnish-TTL
X-DynaTrace-JS-Agent
X-URL
X-Magento-Tags
Product
X-Content-Options
X-Msg-2-Log
X-From
X-VARNISH-Cache
X-B-Cache
Surrogate-Key
X-Via-JSL
Imagetoolbar
X-AspNetWebPages-Version
X-DynaTrace
Powered
Edge-Control-Message
Host
Access-Control-Request-Method
X-CacheServer
Fastly-Debug-Digest
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Engine
X-FORWARDED-FOR
X-Debug-Info
X-Forwarded-For
X-Track
ServedBy
X-Varnish-Cache-Hits
No
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
X-Edge-Location
X-Powered-By-VTEX-Janus-ApiCache
Fhost
X-HOST
X-Recruiting
X-Cache-Rule
Alternate-Protocol
X-Umbraco-Version
X-LBLID
X-NWS-LOG-UUID
X-ApacheServer
X-PERF
X-Goog-Hash
X-Powered-By-VTEX-Janus-Edge
Public-Key-Pins-Report-Only
X-Actual-URL
X-Application-Context
Generator
X-Returned-From
X-Original-Request
X-Returned-From-DLL
X-Passed-To
X-Passed-To-DLL
X-Returned-From-PostProcessResponse
DynaTrace
X-Passed-To-BeforeDispatch
X-Platform
X-Passed-To-PostProcessResponse
X-Signature
X-Returned-From-BeforeDispatch
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Powered-By-360WZB
WZWS-RAY
X-Accel-Expires
X-Location-Id
X-Stale
X-Cache-Age
X-Upstream
Dmn
X-Response-Time
X-Developer
X-Platform-Router
X-Platform-Processor
X-Hosted-By
X-Micro-Cache
X-Tumblr-Pixel-6
Arr-Disable-Session-Affinity
Fastcgi-Cache
X-RESOURCE
Akamai-IP
X-LB
HTTPS
X-Platform-Cluster
X-UD-Method
X-Source
X-LW-Cache
X-Supported-By
X-Pantheon-Site
X-Pantheon-Phpreq
X-Pantheon-Environment
X-Varnish-Host
Surrogate-Key-Raw
X-URLSCHEME
X-Version
X-Cache-Info
X-I-Sp
X-BS
X-Rocket-Nginx-Bypass
Content-Hash
X-Device-Type
X-TransIP-Balancer
X-Instart-Request-ID
X-Varnish-Count
X-Varnish-HitMiss
X-Fastcgi-Cache
Retry-After
Origin
Cache-Provider
X-Shop-Id
X-Defender
X-Rnd
X-NetCat-Version
X-Cache-TTL
X-HS-Content-Campaign-Id
X-Magento-Cache-Debug
X-Cache-Key
X-S
X-EdgeConnect-Origin-MEX-Latency
X-Storage
X-ATG-Version
X-F-Cache
X-Powered-By-VelaWeb
X-Page-Cache
X-AOL-HN
X-App-Hosting
X-CSRF-Protection
X-TransIP-Backend
X-I
Last-Published
Version
USPLoggingUUID
X-Art-Request-Id
X-Dispatcher
X-EdgeConnect-MidMile-RTT
X-Matrix-Server
X-Matrix-Proxy
X-Cache-Tags
X-Translation
X-Microcache-Status
IBM-Web2-Location
X-Front
Ohc-File-Size
X-Daa-Tunnel
X-Gamma-Serve
Allow
X-Revision
X-Environment
X-Drupal-Cache-Tags
X-Varnish-Seen-By
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-Server-ID
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-LB-Node
X-Expires-Orig
X-Vcap-Request-Id
X-Hypernode
X-Server-Upstream
RTSS
Powered-By-ChinaCache
Pagespeed
X-Cache-Operation
Pool
X-Dispatch
MIME-Version
X-Ua-Device
X-ARC
Content-Disposition
X-Platform-Cache
Page-Completion-Status
X-Platform-Server
X-Director
X-SSL-Cipher
X-SSL-Protocol
Content-MD5
X-Route-Server
X-Flow-Powered
Cache-Key
X-Content-Encoded-By
X-Cache-Only-Varnish
X-Lambda-Id
X-Cache-Debug
X-Loopia-Node
X-SV-Edge
X-SV-Expires
X-SV-FromDBCache
X-SV-Duration
X-SV-CreatedAt
SSPAppContext
X-Url-Base
X-SV-Cacheable
X-SV-Nginx-Duration
X-SV-CacheTags
X-SV-Pid
X-Litespeed-Cache
Node
X-Abgroup
X-Varnish-Age
Wsr-Cache
X-Varnish-Cacheable
X-Drupal-Cache-Contexts
X-Cache-Lifetime
X-UPSTREAM
Lsrequestid
X-NoCache
X-ORACLE-DMS-ECID
X-Github-Request-Id
X-Hiawatha-Cache
X-Edge-IP
X-Grace
Accept-Encoding
X-IsCacheURL
X-Nbs
Section-Io-Id
X-Debug
X-GeoIP-Country-Code
X-Cache-Server
X-Ttl
X-Generated
X-Id
X-Cache-Control-Orig
Pv
Proxy-Connection
X-CJ-Soft
X-SRCache-Key
X-Firenze-Processing-Time
X-Sapient
ServerID
X-PwB-Node
Srv
X-RequestId
X-Vhost
X-Cache-Engine
X-Proxy
Content-Encoding-Handler
Fw-Via
X-Cache-Expires
X-Sentry-ID
X-Ezoic-Cdn
X-Discourse-Route
X-VTEX-Cache-Status-Janus-Edge
X-Cache-Type
Location
X-ACMCache
S-Cnection
X-Server-Id
X-N
Cneonction
X-Client-IP
X-Dns-Prefetch-Control
ServerName
Backend
X-Browser
Server-Name
SN
X-Magento-Cache-Control
X-Amz-Meta-S3cmd-Attrs
Author
X-SERVER-NAME
X-Duration
X-Processing-Time
X-Cache-Control
X-TTL
FAI-W-FLOW
X-Geo-Country
X-Nginx-Cache
X-NB-Cached-Page
X-Location
X-Middleware-Start
X-Speed-Cache-Key
X-Speed-Cache
SRV
If-Modified-Since
X-Country-Code
X-ServerID
IM-Version
Req-Id
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Dynatrace-Js-Agent
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Cookie-Domain
X-Content-Age
X-Yadis-Location
X-Orig-Vary
X-Varnish-Url
X-Cache-CFC
Nodo
X-Sucuri-ID
X-GeoIP-Country-Name
AMF-Ver
Server-Info
X-Akamai-Device-Characteristics
X-Always-Cache
X-Akamai-Device-Model
X-Worker
PICS-Label
X-Varnish-Backend
X-Time
X-FW
X-Magnolia-Registration
Use-Proxy
NnCoection
X-Cache-Level
X-Cache-Namespace
X-Forwarded-Proto
Cached
HAVer
X-Real-Server
HCVer
X-Pressidium-NinukisWP-Ver
Cm-Server
X-Akamai-Transformed
X-Framework
X-Cache-PageType
X-Cache-Device-Type
X-DealerOn
X-Correlation-ID
X-Cache-Fix
X-App-Server
X-Webkit-CSP
X-BackendServer
X-Sucuri-Cache
X-Shield-Request-Id
Accept-Charset
X-Drectory-Script
Qs-Cache
SVR
X-BKSrc
S
X-SO
X-Frontend
X-Processed-By
X-Cluster-Node
Thanks
X-Srv
X-Abuse
Xc-Version
X-Ss-Location
X-LB-Server
NetMindSessionID
X-Empowered-By
Pf.Web.Request.Id
Cache
X-Adobe-Content
X-Adobe-Loc
X-Purge-URL
X-Ss-Conf
X-JG-Page-Cache
X-Amz-Storage-Class
X-CF-Passed-Proto
X-Session-ID
Pics-Label
X-Server-IP
X-CDN-Forward
Local-Info
X-Origin
MC
X-Config-Blacklist-Version
X-Varnish-Retries
X-High-Performance
X-Runtime-Rack
X-Purge-Host
Server-Timing
Magicmarker
X-Last-Modified
X-Traffic
X-SRV
X-Route-To
X-Varnish-IP
X-DataDome
SiteSpeed
Nitro-Cache
Tracecode
X-Fastly-Request-Id
SEOMOZ
X-Sys-Req-ID
X-Rocket-Nginx-Serving-Static
X-Disney-Akamai-Rule
A-Powered-By
X-PF-Uncompressing
MJ12bot
X-Litespeed-Cache-Control
SBGI-1
SBGI-9
SBGI-RenderTime
X-NginX-Cache
X-LP
SBGI-10
SBGI-5
SBGI-RealPath
SBGI-7
SBGI-Device
X-WR-Flags
X-ClientSide-Caching
X-Cf-Powered-By
W
Content_type
X-Content-Type-Option
X-FastCGI-Cache
X-HTML-Minification-Powered-By
X-Pagename
X-RiS-UFDI
X-Hit-Cache
X-Content-Security-Policy-Report-Only
X-Cache-TTL-Remaining
X-Sorting-Hat-Expire-Cache
X-Provisioner-Version
X-Domain-Checked
EagleEye-TraceId
X-SDS
From-Origin
X-FTR-Request-ID
X-AF-Userserver
X-App-Status
X-Balanceador
Keywords
HitType
Frame-Options
WN
Eomportal-Instance
X-WN-ClientGroup
WWW-Authenticate
X-VARITI-CCR
X-Cache-Handler
P-ID
X-Twitter-Response-Tags
X-FireWall-Port
Cache-Tag
X-Runtime-Memory
X-Varnish-ID
X-Transaction
AC-ELC
X-Connection-Hash
X-Yottaa-Optimizations
X-Yottaa-Metrics
CacheControlHeader
X-OpenCart-Lightning
X-Mobilized-By
Content-Transfer-Encoding
X-Jphone-Copyright
X-Clara-ASAP
X-Cache-Doesi
X-Varnish-Debug-Age
X-ASAP-Cache
X-Client-Image-Vid
X-Amz-Meta-Cb-Modifiedtime
Adm-Server
X-AEM
Max-Age
Cache-Tags
X-ORACLE-DMS-RID
X-Directory-Script
X-ID
Description
X-Varnish-Hits
X-Rq
X-HW
ServerSignature
X-Varnish-Debug-TTL
ServerTokens
Ufe-Result
X-Redman-Backend
X-Akamai-Edgescape
X-Client-Vid
X-Avg-Cookie-Expires
X-AVG-Country-Code
X-Redman-Final-Url
X-EPiphany-Vid
Web-App-Origin-Name
X-VNode
VANITY-HOST
NODE
X-Server-Instance
X-Webstats-RespID
X-WPL-DATA
X-Fedora-School-Id
SERVER-ID
X-Esi
Contao-Page-Layout
X-Generated-Time
X-LW-Web-Server
X-Resty-Request-Id
X-Unique-ID
X-Varnish-Ttl
Backend-Timing
X-ARRServer
X-Garden-Version
X-Unbounce-VisitorID
X-Analytics
X-Unbounce-PageId
Proxy-Agent
X-Unbounce-Variant
Noq
Play-Detected-UserAgent
Play-Detected-Device
X-Wikidot-Static-Cache
X-PRAM
X-Force
Hname
X-Hstore
BALANCEDTO
X-Wikidot-Backend
X-Hrouter
Front
X-Varnish-Hostname
X-Key
X-CAPServer
X-ServerIndex
Paypal-Debug-Id
X-Mobile-URL
X-HP-Trace-Project
Ram
X-HOSTNAME
Ramp
X-HP-Trace-ID
X-MCB-Server
X-Atraveo-From-Varnish-Cache
X-GeoIP
X-CB-Server
X-Desc
Dispatcher
X-GoCache-CacheStatus
X-MAT-GEO
X-Webkit-Csp
X-Page
X-Remote-Addr
X-Source-ID
X-Debug-Token
X-Atraveo-TTL
X-CacheResult
X-Atraveo-Varnish-Server-Id
X-Atraveo-Zone
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
X-Atraveo-Cache-Control
X-Cache-Keep
X-Atraveo-ETag
X-Atraveo-Expires
X-Dev
X-Runtime-Affili
X-Cms-Mode
Machine
Cmstype
Cmsid
X-Nginx-Host
X-SH-Cache-Status
X-Backend-Status
Worker
X-App-Runtime
Dis-Env
X-CACHE-TTL
X-Culture
NLCacheNote
Beyond-Iis
X-App
X-TTFB
X-TTFB-L
TC-Cache-U
X-SmugMug-Hiring
TC-Cache-IC
X-Real-IP
Resin-Trace
TC-Cache
Cteonnt-Length
X-Trace-Id
X-Env
X-WebKit-CSP-Report-Only
X-Compressed-By
X-Distributor
TC-S-Cache-M
Disablevcache
Access-Control-Allow-Header
TC-S-Cache
Nginx-Cache
Og
X-NginX-Server
Strikingly-Cache-Region
X-Plat
SHInfo
From
Strikingly-Cached
Strikingly-Cached-Version
X-Detected-Device
X-Symfony-Cache
X-WP
X-Smartcache-Timeout
X-Smartcache-Keys
XDomainRequestAllowed
X-Varnish-Server
X-GSL-Server
COMMERCE-SERVER-SOFTWARE
Smug-CDN
X-SmugMug-Values
X-HydroSheep
X-Cache-Node
X-Frames-Options
X-Resolver-IP
AMP-Access-Control-Allow-Source-Origin
X-IIJ-Cache
X-Avvio-Cms-Cacheload
Fastly-Backend-Name
X-V
X-Stage
Lb
Custom-Header
X-A
X-Airee-Node
Device
X-KoobooCMS-Version
Id
X-Proto
X-Varnish-Ip
MW-Webserver
MS-CV
X-VC-TTL
X-AutoRu-App-Id
X-Autoru-Host
X-Dynamic-Cache
X-Autoru-LB
X-Fstrz
Web
Bios
X-VC-Enabled
X-Batcache
X-EC2-Instance-Id
X-Batcache-Reason
X-ETag
Identity
Home
X-Dw-Trace-Id
Myheader
X-Amcomm-Site
X-SDE-Name
X-Pj-Cache-Status
Arrnode
X-OPNET-Transaction-Trace
X-Session-Reinit
X-Server-Generated
ViewMode
X-Hosting-Env
X-Refresh
X-Viator-Tapersistentcookie
X-RDP
X-TB-M
Content-Server
X-Req-Head-Response
Yoncu-Errno
X-WR-MODIFICATION
X-ENV
X-Forwarded-Host
X-Machine-Name
Hamster
X-Map-Context
X-Confluence-Request-Time
X-E
ClientIP
X-Cache-On
X-Bip
Ibf5scheme
N365rili
Ews
X-Render-Time
X-HashTwo
X-Apm-Telemetry-Syncmark
X-Cdn-Forward
X-Varnish-Cache-Local
X-Info
X-SmartBan-URL
X-SmartBan-Host
X-FPC
OriginServer
X-Origin-Server
ScoreTracker
X-Gyrobase-Publication
X-Webcelerate
Service-Worker-Allowed
X-Adnet
X-DN-Cache-Control
X-Aramark-SID
IISExport
X-DTC
X-Proxy-Cache-Key
X-MSEdge-Ref
X-Highwire-SessionId
CLMOB
X-CDN-COMPRESS
Il-Cl
X-CDN-RULE
X-Data-Request
F5-IpCliente
Gzip
Hostname
Proxy-Cache
X-Reflector-Cache
PagesDisplayed
X-Akamai-3PM-SW-Version
X-Highwire-RequestId
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
X-Reflector
WebServer
Traffic-Origin
X-B2f-Not-Route
X-Captured
X-Backend-Host
X-Box
SG
X-Sc-Cache
X-Magento-Action
X-Cache-Extended
X-CacheID
X-Rewrite
X-Machine
FRONT-END-SECUREBROWSER
AsisCache
BackendServer
Serverid
X-Protected-By
X-Goog-Meta-Replace
X-Goog-Meta-Policy
X-PM-ID
X-Rack-CORS
NtCoent-Length
Cleartype
RN-Server
X-Rack-Cors
X-Header
X-HostName
X-HP-CAM-COLOR
Url
Warning
X-Grid-Server
Server-Id
X-UA
Xc
X-RealServer
X-WA-Info
X-Unique-Id
X-Cocoon-Version
X-W3TC-Minify
X-Ghost-Cache-Status
X-Flex-Evend
X-Gateway-Cache-Status
X-Flex-Community
X-Flex-Evstart
X-VC-Cache
Accept-Language
SS
X-Gateway-Cache-Key
NS-VaryByCustom-Key
Edgecast
X-Varnish-Id
X-Flex-Lastmod
X-Instance-Id
VServer
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-L-Path
Ctx
X-Origin-Cache
X-Tag-Playlist
X-LBPoolMember
X-Cache-FS-Status
X-Gateway-Skip-Cache
X-Flex-Tag
X-Beatles
X-Flex-Tags
X-Environment-Context
X-Flex-Lang
Access-Control-Request-Headers
X-DSMX-Render-MS
X-Does-He-Have-Time
X-RemovedCookies
XX
X-DSMX-Rewrite-MS
X-ProcessESI
X-Zendesk-Origin-Server
X-Zendesk-User-Id
X-Beatles-Hits
X-Depends
X-Powered-By-Home.Pl
X-Cache-Set
X-Cache-Time
X-Cache-Via
X-M
Session-From
X-Cache-TTL-Age
ServerIP
Hosted-By
Hummingbird-Cache
X-Amz-Meta-S3b-Last-Modified
X-Cache-TTL-Current
X-Your-GrandPa-Would-Wait
X-Secret
X-Src-Webcache
User-Agent
X-TTL-Age
X-Would-Your-GrandPa-Wait
X-Old-Content-Length
X-Catalyst
TP-L2-Cache
TP-Cache
X-Bcwwwid
X-Nginx
SB-Site-Device
X-ASAP-Age
SB-Cache-Remaining
X-PBS-Appsvrip
X-PBS-Appsvrname
X-PBS-Fwsrvname
X-Upstream-Status
X-Author
X-JSESSIONID
X-Response
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Goog-Meta-Goog-Reserved-File-Mtime
PServer
Aoestatic
X-Cache-Id
X-CRA-DC
DNNOutputCache
X-Application
X-Upstream-Backend
X-Streams-Distribution
X-Redirector
CommunityServer
X-Timestamp
X-Ser
X-Middleton-PageSpeed
X-PHP-Response-Code
SB-Cache-Life
X-Magento-Lifetime
X-NewsFlow-Sitename
X-We-Are-Hiring
X-IP
X-Cluster
X-Pagely-Cache
X-SV
X-DB-Content-Length
X-4ormat-Cacheable
X-FORWARDED-PROTO
Server-Ip
X-Varnish-Action
X-Netrix-ID
Mime-Version
X-Serv
X-Server-Addr
X-HS-Status
X-ACCELERATE
X-HAProxy
X-Served-Server
Viewport
Provider
NZSpeedy
X-RAMCache
X-ReqId
X-Dynatrace
X-CSRF-Token
VC-NoCache
X-Resource
X-Lw-Cache
X-Custom-Header
X-CCM
X-Amz-Id-1
Note
Ec-CorrId
RequestId
X-Domino-CacheValidationWithETagReason
X-SCM-Server-Number
X-Via-NSCOPI
X-Amz-Meta-Content-Md5
X-Turpentine-Esi
SB-Site-IE-VERSION
X-SayCDN-TTL
Ec-Machine
X-VC-Cacheable
X-VC-Hash
X-VC-Debug
X-DevSrv-CMS
X-Say-TTL
Provided-Host
X-CH-Device
X-Domino-CacheValidationWithETagResult
X-Hosting
Ttl
X-Say-Cacheable
X-Search-Id
X-FastCGI-Cache-Status
Referer
Upgrade-Insecure-Requests
Fastly-Restarts
Session-Id
Tesla.Performance
Tempo
Uuri
X-Az
X-AppVersion
X-Activity-Id
RSB-LINK
Quri
X-Cname-TryFiles
X-Made-On
X-Nginx-Request-Time
X-Litespeed-Tag
X-Instart-Cache-Id
X-Served
X-Server-Ip
PB-RID
X-Deity
PB-PID
Generate-Time
X-Cache-Me-Harder
Microcache
X-Route
WP-AdvCache-MemCached
X-Router
X-FIRSTBase
X-Header-Treatment
X-HA
X-Mobile-Rewrite
X-Enabled1
X-Enabled2
X-Enabled3
X-DynamicCache
X-Wix-Punisher
EQ-Cache
X-Debug-Message
X-Cache-Detail
X-MidCOM-Meta-Cache
Control-Cache
AR-SID
!~Request-OOB-Work
AR-ATIME
AR-CACHE
AR-PoweredBy
X-UT-Cache
X-D-Time
X-S-Misc
X-Node-Name
X-Time-Microsecs
X-XHR-Current-Location
Cache-Status
X-Generation-Time
X-Config-By
Kanooh-Host
Progma
X-AppServer-Cache-Rule
X-Cache-Varnish
EN-User
StatusCode
Expiries
MachineName
MwpReleaseVersion
Server-ID
Debug-Status
X-Node-ID
X-AISO-Cache
X-AISO-Cacheable
X-AISO-Server
X-Cache-V
X-Uncacheable
X-SuperCache
X-MainProfileName
X-MainProfileURL
X-Not-Cacheable
INFO
X-MainProfileID
X-MainProfileCategory
DrivedBy
ReqUrl
X-Pixelsilk-Version
X-LOCATION
X-Agent
X-Client-Ip
X-7d-Trace-Id
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-Hash
X-7d-Instance-Id
X-Upgrade-Enabled
X-Container
X-Geo-IP
X-REDIRECTSERVER
X-Skip-Cache
X-DS1D
Services
X-RequesterIP
ServerNode
Cacheid
Www.Aujourdhui.Com
X-Backend-Name
X-Cjtype
X-NodeID
X-Cache-Original-TTL
X-XHTML-Minification-Powered-By
X-UnsetCookies
X-Distil-CS
X-Blog
CDCHOST
X-ManagedFusion-Rewriter-Version
X-Pubstack
X-Test-Debug
X-Rewritten-By
X-Full-Url
X-Nginx-Request-Processing-Time
Access-Control-Allow-Method
X-Instance
X-Gannett-Site-Version
X-Enhanced-By
X-Status
X-SilverStripe-Cache
X-Artvisual-Server
X-Max-Age
X-AMAZEEIO
X-Pixelsilk-Server
X-ESI
X-Oracle-DMS-ECID
X-Cache-Ttl
X-Oneagent-Js-Injection
X-Ssl-Cipher
X-Ruxit-Js-Agent
X-Lb
Dynatrace
X-Request-Received
X-Request-Processing-Time
X-Server-App
Language
Powered-By-VeryCDN
X-PBY
X-Nginx-Page-Cache
X-Archive-Orig-ETag
X-Archive-Orig-Server
X-AWS
X-Built-By
X-Cache-Date
X-Debug-Serve
X-Varnish-Esi-Method
X-Varnish-Esi-Access
X-Varnish-Store
MageStack-Area
MageStack-Cache
X-Varnish-Currency
X-Fastly-Backend-Reqs
CpuTime
GranicusServer
X-Powered-Developer
X-FG-RequestId
X-Archive-Orig-Date
X-Archive-Orig-Content-Length
X-LB-Backend
X-Instance-Name
X-LB-Frontend
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
X-Cache-Warmer
WP-FROM-CACHE
Httpd-Identifier
MSSmartTagsPreventParsing
MSThemeCompatible
Realaction
X-Meta-MSThemeCompatible
X-Restarts
X-WHO
Memento-Datetime
X-Archive-Guessed-Charset
X-Archive-Orig-Connection
TTL
CD4
X-Server-Vrn
X-Wm-1
X-Wm-VIP
Actual-Object-TTL
MageStack-Cache-Hits
MageStack-Cache-Lifetime
X-Pool-Info
X-Pageid
X-Q-S
X-S-C
X-S-V
X-Nocache
X-Mw-Workerstats
X-I-V
X-M-P
X-M-T
X-M-V
X-T
X-Transaction-Name
X-Compress-Hint
X-Server-Instance-Name
X-NewRelic-App-Data
X-Varnish-URL
X-WebNode
X-UPSTREAM-Address
X-Healthy
X-Middleton-Pagespeed
X-MyName
X-OCTOPOD
X-Cacheable-TTL
X-Cachable
MageStack-Tag
MageStack-PageSpeed
MageStack-Web-Node
X-Backend-TTL
X-NewCloud-V-Cache
MageStack-Magento-Version
MageStack-Loadbalancer
MageStack-Cache-Status
MageStack-Cacheable
MageStack-Config
MageStack-Debug
X-Origin-Upstream-Status
X-ProBase-Server
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
X-B
X-Beresp-Ttl
Key
RlogId
X-Serverid
AMFplus-Ver
CommercePlatform-Version
Page-Template
CS-SERVER
Actioncode
Y-Trace
X-ZORequestID
Yola-ID
X-Time-Zone
Fw-Cache-Status
X-ServiceProvider
X-Server-FQDN
Requested-Host
X-Server-Ident
Cache-Ctrol
X-Title
X-Varnish-Instance
OutputRewritten
X-Cache-2
X-BeResp-Ttl
X-Cache-Served
X-IP-Address
Head
Countrycode
CmsfirstPublishTimestamp
X-VLoc
X-PROCESSED-BY
X-9XB-Server
X-Ar-Debug
SINA-LB
SINA-TS
X-Ants-Machine-Id
X-VG-WebCache
X-BC
X-SID
X-SE-Debug
Apple-Itunes-App
X-Ants-Host
X-Country
Aurora-Node
UrlWatchModule-Time
X-ELB
Copyright
X-MSU-SOURCE
X-ACLR-Version
X-Layout
X-Memcached
X-Varnish-Grace
X-Czt
X-Clx-Request
X-ZSITES-DNS
X-Accel-Cache-Control
X-Who
X-PG
X-This-Proto
X-Svr
IES-Server
DB-Nickname
Load-Balancer
Request-Time
X-B3-Spanid
Cookie
X-EBAY-C-REQUEST-ID
Webserver
X-Distributed-By
X-Proxy-Id
X-Service-Id
X-B3-Traceid
X-Built-With
X-Sn-Servicetimems
X-UPServer
X-Varnish-Cached
X-Varnish-Cached-TTL
X-ServerAddr
X-Script
X-CPU-Time
X-Fpc
X-MCF-ID
X-Nitro-Cache
Rewriter
FindLaw
X-Cache-Bypass
WSCLoggingUUID
E-TAG
VAR-Cache
X-Brought-To-You-By
Response-Time
X-COUNTRY-CODE
X-VCS-Cacheable
X-VCS-Ttl
X-WAF-Proxy
XDisk
ATI-Server-Id
X-Config-Version
X-Sid
X-CO-Host
Content-Cache
DbServerName
X-Rocket-Nginx-Reason
X-Rocket-Nginx-File
X-DEBUG
X-DeliveryServer
X-Dynamic
AccessControlAllowOrigin
Accept-CH