Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
P3P
X-AspNet-Version
X-Pingback
Age
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Language
X-Template
X-Generator
Alt-Svc
X-Buckets
X-Request-Id
X-Drupal-Cache
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Content-Location
Host-Header
X-Runtime
X-ShopId
X-ShardId
X-Dc
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Alternate-Cache-Key
MS-Author-Via
X-FRAME-OPTIONS
Cartoon
X-UA-Device
X-Powered-CMS
X-IPLB-Instance
X-Served-By
P3p
Access-Control-Allow-Headers
Status
Access-Control-Allow-Credentials
X-Amz-Cf-Id
Access-Control-Allow-Methods
X-Cache-Status
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
CF-Cache-Status
X-Contextid
X-Backend
Referrer-Policy
Powered-By
X-PC-Key
X-PC-Hit
X-Mod-Pagespeed
X-ServedBy
X-PC-Date
X-PC-AppVer
X-PC-Host
X-DIS-Request-ID
X-WPE-Loopback-Upstream-Addr
Content-Encoding
X-CST
X-Logged-In
X-Request-ID
Keep-Alive
X-Rid
X-Cache-Hit
X-Host
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Port
X-Server
X-CDN
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Server-Powered-By
X-Robots-Tag
X-Endurance-Cache-Level
X-Tumblr-Pixel-2
X-Nginx-Cache-Status
X-Wix-Request-Id
X-Seen-By
X-Wix-Server-Artifact-Id
X-Accel-Version
X-Original-Date
X-Turbo-Charged-By
X-Page-Speed
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
X-Content-Digest
WP-Super-Cache
X-Proxy-Cache
X-Rack-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-AH-Environment
X-Tumblr-Pixel-3
X-LiteSpeed-Cache
X-Varnish-Cache
X-GitHub-Request-Id
X-Ua-Compatible
X-Request-Country
SPRequestGuid
X-SharePointHealthScore
Edge-Control
X-XRDS-Location
X-MS-InvokeApp
X-Cnection
MicrosoftSharePointTeamServices
X-Cache-Lookup
Timing-Allow-Origin
X-Died
X-Node
Cf-Railgun
X-FW-Hash
X-Amz-Request-Id
X-Amz-Id-2
X-Trace
Charset
X-FW-Type
X-FW-Static
X-FW-Serve
Request-Id
Edge-Cache-Tag
X-Content-Security-Policy
X-Webserver
X-Webcom-Cache-Status
X-FullPageCaching
X-HS-Cache-Config
X-HS-Content-Id
X-PhApp
MicrosoftOfficeWebServer
X-Safe-Firewall
X-CF-Powered-By
X-Hits
SPIisLatency
SPRequestDuration
Request-Context
X-Newrelic-App-Data
Access-Control-Max-Age
X-BC-Stapler
X-INKT-SITE
X-INKT-URI
Composed-By
X-PHP-Backend
Access-Control-Expose-Headers
X-Tumblr-Pixel-4
Grace
X-Swift-CacheTime
X-Swift-SaveTime
X-SERVER
EagleId
X-CDN-Pop-IP
Served-By
X-CDN-Pop
X-Hyper-Cache
X-Spip-Cache
Liferay-Portal
X-Backend-Server
X-Device
X-Dw-Request-Base-Id
X-Microcache
X-Fastly-Request-ID
X-Server-Name
X-LiteSpeed-Cache-Control
X-RateLimit-Remaining
Content-Style-Type
Rating
X-RateLimit-Limit
X-Wix-Renderer-Server
X-FB-Debug
X-ServerName
X-VCache
Content-Script-Type
X-Clacks-Overhead
X-Cloud-Trace-Context
X-RateLimit-Reset
X-Jimdo-Instance
X-Jimdo-Wid
X-User-Agent
X-DDC-Arch-Trace
Surrogate-Control
X-Acc-Exp
X-Cache-Config
Front-End-Https
X-Firenze-Processing-Times
Real-Hostname
X-Loop
X-TNCMS
Public-Key-Pins
Refresh
X-Tumblr-Content-Rating
X-Middleton-Display
X-Middleton-Response
X-StackifyID
Response
X-Sol
Display
Fpc-Cache-Id
X-XN-Trace-Token
X-XN-XNHTML
X-DNS-Prefetch-Control
X-HS-Combine-CSS
X-Servedby
Xkey
X-Age
X-SS-Location
X-SS-Conf
X-Microcachable
X-Vtex-Processado-Em
X-Hostname
X-Tumblr-Pixel-5
X-Cached
X-Generated-By
X-Zen-Fury
X-Px
X-N-OperationId
X-OneAgent-JS-Injection
X-Cdn
PageSpeed
X-Correlation-Id
X-Request-Time
X-Topify-Platform
X-MiniProfiler-Ids
X-Frame-Option
X-Cached-By
TCN
X-Ruxit-JS-Agent
P-WS
P-LB
X-Kinsta-Cache
X-WebKit-CSP
X-Outils-CS
X-Url
X-Whom
X-CMS-Version
X-URL
X-Amz-Version-Id
X-Varnish-TTL
X-Handled-By
X-Magento-Tags
Edge-Control-Message
Rt-Fastcgi-Cache
Product
X-DynaTrace-JS-Agent
X-Via-JSL
X-Content-Options
Surrogate-Key
X-AspNetWebPages-Version
X-B-Cache
Imagetoolbar
X-VARNISH-Cache
Powered
X-Edge-Location
X-CacheServer
Fastly-Debug-Digest
X-Debug-Info
Access-Control-Request-Method
Host
X-SRCache-Fetch-Status
X-Forwarded-For
X-SRCache-Store-Status
X-Track
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
No
X-Cache-Rule
X-VTEX-Janus-Router-Backend-App
X-Powered-By-VTEX-Janus-ApiCache
X-Vtex-Processed-At
X-Umbraco-Version
X-Engine
X-DynaTrace
X-Recruiting
ServedBy
Fhost
X-FORWARDED-FOR
X-HOST
X-Varnish-Cache-Hits
X-Application-Context
X-NWS-LOG-UUID
Alternate-Protocol
X-Powered-By-VTEX-Janus-Edge
Public-Key-Pins-Report-Only
X-LBLID
X-Signature
WZWS-RAY
X-Msg-2-Log
X-Powered-By-360WZB
X-Goog-Hash
X-Actual-URL
X-Cache-Age
X-ApacheServer
X-Passed-To-DLL
X-Passed-To
X-Original-Request
X-PERF
X-Platform
X-Returned-From
X-Returned-From-DLL
X-From
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Accel-Expires
X-Varnish-Beresp-Grace
X-Location-Id
X-Response-Time
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Tumblr-Pixel-6
Generator
X-Platform-Router
X-Platform-Processor
Arr-Disable-Session-Affinity
X-Developer
X-Stale
X-Upstream
Dmn
Akamai-IP
Fastcgi-Cache
X-Platform-Cluster
HTTPS
X-Hosted-By
DynaTrace
X-Micro-Cache
X-LW-Cache
X-RESOURCE
X-Cache-Info
Surrogate-Key-Raw
X-Pantheon-Site
X-Source
X-Pantheon-Environment
X-LB
X-Pantheon-Phpreq
X-UD-Method
X-URLSCHEME
X-Supported-By
X-Rocket-Nginx-Bypass
X-I-Sp
X-BS
X-Fastcgi-Cache
X-Device-Type
X-Version
Origin
X-Varnish-Host
X-Varnish-HitMiss
Cache-Provider
X-Director
X-Varnish-Count
X-Shop-Id
Retry-After
X-Defender
X-TransIP-Balancer
Content-Hash
X-Rnd
X-EdgeConnect-Origin-MEX-Latency
X-ATG-Version
X-Instart-Request-ID
X-S
X-Magento-Cache-Debug
X-Storage
X-Powered-By-VelaWeb
X-NetCat-Version
X-EdgeConnect-MidMile-RTT
X-Cache-Key
X-HS-Content-Campaign-Id
X-CSRF-Protection
X-Page-Cache
X-Dispatcher
X-Cache-TTL
X-Cache-Tags
X-TransIP-Backend
Version
X-F-Cache
X-AOL-HN
X-App-Hosting
X-Microcache-Status
X-Front
X-Art-Request-Id
X-Translation
Last-Published
X-Drupal-Cache-Tags
X-Daa-Tunnel
X-Matrix-Proxy
X-I
IBM-Web2-Location
X-LB-Node
X-Matrix-Server
USPLoggingUUID
Allow
Powered-By-ChinaCache
X-Revision
X-Gamma-Serve
Ohc-File-Size
X-Expires-Orig
X-Hypernode
RTSS
X-Platform-Cache
X-Platform-Server
MIME-Version
Pool
X-Dispatch
X-Server-ID
X-Server-Upstream
X-Cache-Operation
X-Cache-Debug
Content-Disposition
X-Ua-Device
X-Content-Encoded-By
X-Varnish-GracePeriod
X-Varnish-ObjectSource
Pagespeed
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Varnish-RemainingLife
X-Flow-Powered
X-ARC
X-Lambda-Id
X-Cache-Only-Varnish
Content-MD5
X-Route-Server
X-SSL-Cipher
Node
X-SSL-Protocol
Cache-Key
X-SV-Pid
X-SV-Cacheable
X-SV-FromDBCache
X-SV-Edge
X-SV-Expires
X-SV-Duration
X-SV-Nginx-Duration
X-SV-CacheTags
X-Drupal-Cache-Contexts
Wsr-Cache
X-SV-CreatedAt
SSPAppContext
X-Vcap-Request-Id
X-UPSTREAM
X-Abgroup
X-ORACLE-DMS-ECID
X-Loopia-Node
X-Environment
X-Cache-Lifetime
X-Varnish-Age
Lsrequestid
Page-Completion-Status
X-Varnish-Cacheable
X-Edge-IP
ServerID
X-Github-Request-Id
X-Id
X-Cache-Server
X-NoCache
Accept-Encoding
X-Cache-Control-Orig
X-Grace
X-Hiawatha-Cache
X-Debug
X-IsCacheURL
Section-Io-Id
Content-Encoding-Handler
X-CJ-Soft
X-Generated
X-Ttl
Fw-Via
X-PwB-Node
X-Vhost
Pv
Srv
X-RequestId
X-Firenze-Processing-Time
S-Cnection
X-Url-Base
X-SRCache-Key
X-Sapient
Proxy-Connection
X-Cache-Type
Location
Cneonction
X-Client-IP
X-Proxy
X-GeoIP-Country-Code
X-Sentry-ID
X-Cache-Expires
X-Cache-Engine
X-Orig-Vary
X-TTL
X-VTEX-Cache-Status-Janus-Edge
X-Ezoic-Cdn
Server-Name
X-Magnolia-Registration
X-Server-Id
X-Magento-Cache-Control
Author
X-Dns-Prefetch-Control
X-Litespeed-Cache
ServerName
Backend
X-Nbs
If-Modified-Since
X-Geo-Country
X-Amz-Meta-S3cmd-Attrs
X-Cache-CFC
X-ServerID
X-Akamai-Transformed
X-Duration
X-Country-Code
X-N
SN
X-Browser
FAI-W-FLOW
X-Processing-Time
X-Discourse-Route
X-Content-Age
X-Cache-Control
Req-Id
X-Nginx-Cache
X-Always-Cache
X-Location
SRV
Nodo
IM-Version
X-Speed-Cache
X-Speed-Cache-Key
X-Cookie-Domain
X-FW
X-Dynatrace-Js-Agent
X-Time
X-Yadis-Location
X-Sucuri-ID
X-NB-Cached-Page
Server-Info
AMF-Ver
X-Framework
X-Akamai-Device-Model
Cached
X-GeoIP-Country-Name
X-Real-Server
NetMindSessionID
X-Akamai-Device-Characteristics
X-Middleware-Start
X-Litespeed-Cache-Control
X-Varnish-Url
PICS-Label
X-Goog-Stored-Content-Length
NnCoection
X-Cache-Level
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Generation
X-Worker
X-Goog-Metageneration
Cm-Server
X-Pressidium-NinukisWP-Ver
HCVer
X-Cache-Namespace
HAVer
X-SERVER-NAME
X-Abuse
X-DealerOn
X-Cache-Fix
X-Cache-PageType
X-Cache-Device-Type
Use-Proxy
X-Varnish-Backend
X-Correlation-ID
X-Processed-By
X-ACMCache
Accept-Charset
X-BackendServer
X-Sucuri-Cache
X-App-Server
X-Webkit-CSP
X-Drectory-Script
Pics-Label
X-Shield-Request-Id
X-SO
X-Varnish-IP
S
X-Frontend
X-Cluster-Node
X-BKSrc
SVR
X-Fastly-Request-Id
Qs-Cache
X-Forwarded-Proto
X-Ss-Location
Xc-Version
X-Ss-Conf
X-Srv
Content_type
Pf.Web.Request.Id
Cache
X-SRV
Thanks
X-Purge-URL
X-CDN-Forward
Local-Info
SBGI-10
X-Origin
SBGI-Device
X-Config-Blacklist-Version
MC
X-Server-IP
X-Session-ID
SBGI-9
SBGI-1
SBGI-RealPath
X-Amz-Storage-Class
SBGI-RenderTime
X-Runtime-Rack
SBGI-5
Tracecode
SBGI-7
X-JG-Page-Cache
CacheControlHeader
Server-Timing
Magicmarker
X-Traffic
X-LB-Server
X-Last-Modified
X-Purge-Host
X-Route-To
X-DataDome
X-RiS-UFDI
X-Varnish-Retries
X-Content-Security-Policy-Report-Only
X-High-Performance
X-Disney-Akamai-Rule
X-CF-Passed-Proto
Nitro-Cache
X-Rocket-Nginx-Serving-Static
MJ12bot
SEOMOZ
X-PF-Uncompressing
A-Powered-By
SiteSpeed
X-LP
X-Cf-Powered-By
X-WR-Flags
X-ClientSide-Caching
X-FastCGI-Cache
W
X-Content-Type-Option
X-NginX-Cache
X-Empowered-By
HitType
Keywords
X-SDS
From-Origin
X-Varnish-Debug-Age
X-Sorting-Hat-Expire-Cache
X-AF-Userserver
X-Provisioner-Version
X-Hit-Cache
X-HTML-Minification-Powered-By
X-Pagename
X-App-Status
X-Domain-Checked
EagleEye-TraceId
X-Balanceador
X-FTR-Request-ID
X-Cache-TTL-Remaining
X-ID
X-WN-ClientGroup
X-ARRServer
X-VARITI-CCR
WN
Frame-Options
Eomportal-Instance
X-Cache-Handler
WWW-Authenticate
ServerTokens
P-ID
X-Sys-Req-ID
X-Varnish-Debug-TTL
ServerSignature
X-Transaction
X-Twitter-Response-Tags
Content-Transfer-Encoding
X-Yottaa-Metrics
X-Runtime-Memory
X-Varnish-ID
X-Generated-Time
X-Yottaa-Optimizations
X-Connection-Hash
X-Mobilized-By
X-OpenCart-Lightning
X-Webstats-RespID
Cache-Tag
AC-ELC
X-Jphone-Copyright
X-Akamai-Edgescape
X-Adobe-Loc
Dis-Env
X-Varnish-Hits
Cache-Tags
X-VNode
Description
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Rq
X-Debug-Token
X-AEM
Adm-Server
X-Adobe-Content
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Doesi
X-HW
X-Client-Vid
X-Client-Image-Vid
X-Directory-Script
VANITY-HOST
Ufe-Result
X-AVG-Country-Code
X-Avg-Cookie-Expires
X-ASAP-Cache
X-Redman-Backend
X-Redman-Final-Url
X-EPiphany-Vid
X-ORACLE-DMS-RID
X-Clara-ASAP
Web-App-Origin-Name
X-Esi
X-LW-Web-Server
X-V
SERVER-ID
X-WPL-DATA
X-Unique-ID
X-Analytics
Backend-Timing
NODE
X-Resty-Request-Id
X-Garden-Version
X-Server-Instance
Proxy-Agent
X-Fedora-School-Id
Lb
X-Varnish-Ttl
X-Unbounce-PageId
X-FireWall-Port
X-Unbounce-VisitorID
X-Unbounce-Variant
X-SH-Cache-Status
Play-Detected-Device
X-SmugMug-Hiring
XDomainRequestAllowed
X-PRAM
X-SmugMug-Values
X-Force
X-TTFB
X-TTFB-L
X-ServerIndex
X-Rewrite
Cteonnt-Length
X-Env
Smug-CDN
X-Mobile-URL
X-HP-Trace-Project
X-GSL-Server
X-MCB-Server
X-Avvio-Cms-Cacheload
X-HP-Trace-ID
Play-Detected-UserAgent
X-Webkit-Csp
X-GeoIP
X-Key
Nginx-Cache
X-Cache-Keep
X-CacheResult
Hname
X-Atraveo-Zone
X-MAT-GEO
X-HOSTNAME
Dispatcher
Front
X-Page
X-GoCache-CacheStatus
X-CAPServer
X-Varnish-Hostname
Ramp
Ram
Noq
X-CB-Server
Max-Age
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
X-Atraveo-ETag
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
X-Atraveo-Varnish-Server-Id
X-Atraveo-TTL
X-Source-ID
X-Atraveo-Cache-Control
X-Remote-Addr
Paypal-Debug-Id
X-WebKit-CSP-Report-Only
BALANCEDTO
Cmstype
Cmsid
X-Dev
X-Cms-Mode
Custom-Header
X-Runtime-Affili
Worker
X-KoobooCMS-Version
X-Backend-Status
X-Nginx-Host
Contao-Page-Layout
X-A
Machine
X-Culture
X-App-Runtime
Device
Beyond-Iis
NLCacheNote
X-CACHE-TTL
X-Varnish-Server
TC-Cache
X-Server-Generated
TC-S-Cache
TC-S-Cache-M
X-Frames-Options
X-Real-IP
TC-Cache-U
X-Plat
X-Resolver-IP
TC-Cache-IC
X-Symfony-Cache
Resin-Trace
X-Webcelerate
COMMERCE-SERVER-SOFTWARE
X-TB-M
X-OPNET-Transaction-Trace
X-Distributor
X-E
X-Hrouter
X-Hstore
X-App
Og
Disablevcache
X-Sc-Cache
X-Trace-Id
X-NginX-Server
X-Smartcache-Keys
From
X-Cache-Node
Strikingly-Cached
Strikingly-Cache-Region
X-CDN-RULE
Access-Control-Allow-Header
X-CDN-COMPRESS
Strikingly-Cached-Version
X-Detected-Device
X-HydroSheep
X-WP
X-Smartcache-Timeout
X-Varnish-Ip
Web
BackendServer
X-Autoru-Host
MS-CV
X-Dynamic-Cache
MW-Webserver
X-VC-TTL
X-Airee-Node
AMP-Access-Control-Allow-Source-Origin
X-AutoRu-App-Id
X-Autoru-LB
X-Proto
X-IIJ-Cache
Bios
X-VC-Enabled
Id
X-Stage
X-Fstrz
Fastly-Backend-Name
X-SDE-Name
X-Viator-Tapersistentcookie
X-Render-Time
X-Cache-On
X-RDP
OriginServer
X-Hosting-Env
X-HashTwo
X-Batcache-Reason
X-Captured
X-Data-Request
PagesDisplayed
X-Batcache
Traffic-Origin
X-Bip
X-Pj-Cache-Status
N365rili
SHInfo
X-Application
X-Compressed-By
X-Desc
SG
X-Dw-Trace-Id
X-Confluence-Request-Time
Identity
X-ETag
X-ENV
X-Forwarded-Host
Hamster
Ibf5scheme
X-EC2-Instance-Id
Content-Server
Yoncu-Errno
X-Machine-Name
X-Amcomm-Site
X-WR-MODIFICATION
ViewMode
X-Reflector-Cache
X-Cdn-Forward
X-DTC
X-Proxy-Cache-Key
Service-Worker-Allowed
X-Info
X-SmartBan-URL
X-MSEdge-Ref
X-SmartBan-Host
X-Apm-Telemetry-Syncmark
X-Adnet
X-FPC
Home
Il-Cl
X-Akamai-3PM-SW-Version
Ews
X-Req-Head-Response
CLMOB
Myheader
X-Map-Context
X-Highwire-SessionId
X-Highwire-RequestId
ClientIP
F5-IpCliente
X-Gyrobase-Publication
X-DN-Cache-Control
Arrnode
X-Session-Reinit
Proxy-Cache
X-Reflector
X-Refresh
Gzip
Hostname
X-Cache-Dispatchercachecontrol
X-Cache-Dispatcherpragma
ScoreTracker
WebServer
X-Aramark-SID
X-Upstream-Status
X-B2f-Not-Route
IISExport
X-Varnish-Cache-Local
X-Origin-Server
CommunityServer
X-CacheID
X-Ser
X-Depends
SB-Cache-Life
SB-Cache-Remaining
X-L-Path
X-Environment-Context
X-Magento-Action
SB-Site-Device
X-Machine
X-Ghost-Cache-Status
X-Protected-By
X-RealServer
Xc
Serverid
X-Rack-CORS
NtCoent-Length
X-Rack-Cors
Warning
AsisCache
RN-Server
X-W3TC-Minify
X-WA-Info
X-HP-CAM-COLOR
Server-Id
X-HostName
X-Cocoon-Version
Url
X-Goog-Meta-Policy
X-Grid-Server
X-PM-ID
X-Header
Cleartype
X-RAMCache
X-UA
X-Unique-Id
X-Goog-Meta-Replace
X-Litespeed-Tag
SS
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
X-Does-He-Have-Time
X-Flex-Community
PServer
X-PHP-Response-Code
X-Redirector
X-TTL-Age
SB-Site-IE-VERSION
X-Your-GrandPa-Would-Wait
X-Author
Aoestatic
Ctx
X-Flex-Evend
X-Varnish-Id
X-Cache-Id
Edgecast
X-Magento-Lifetime
X-Streams-Distribution
X-Cache-Time
X-RemovedCookies
X-Origin-Cache
X-Zendesk-Origin-Server
X-ProcessESI
X-LBPoolMember
X-VC-Cache
X-Cache-Via
X-Zendesk-User-Id
X-Gateway-Skip-Cache
X-Upstream-Backend
X-Flex-Lastmod
X-Flex-Lang
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Flex-Tags
X-Flex-Tag
X-Src-Webcache
X-Secret
X-Cache-Set
X-Beatles-Hits
X-Amz-Meta-S3b-Last-Modified
X-Old-Content-Length
X-Powered-By-Home.Pl
Provided-Host
X-Tag-Playlist
User-Agent
ServerIP
Accept-Language
X-Flex-Evstart
Hosted-By
X-Cache-TTL-Current
Session-From
X-Cache-TTL-Age
Referer
X-Would-Your-GrandPa-Wait
X-M
X-Goog-Meta-Goog-Reserved-File-Mtime
NS-VaryByCustom-Key
X-Timestamp
X-CRA-DC
VServer
X-Beatles
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
DNNOutputCache
X-Rebelmouse-Cache-Control
X-Cache-FS-Status
X-Catalyst
X-Rebelmouse-Surrogate-Control
X-ASAP-Age
X-Instance-Id
X-Response
X-Middleton-PageSpeed
X-JSESSIONID
X-Cluster
X-Bcwwwid
X-Nginx
X-PBS-Appsvrip
X-We-Are-Hiring
X-PBS-Fwsrvname
X-PBS-Appsvrname
X-NewsFlow-Sitename
Hummingbird-Cache
X-IP
X-Backend-Host
Access-Control-Request-Headers
X-HS-Status
X-Netrix-ID
X-ReqId
X-Resource
VC-NoCache
X-HAProxy
X-DB-Content-Length
X-4ormat-Cacheable
X-Dynatrace
X-Varnish-Action
Viewport
X-Serv
Provider
X-Server-Addr
Server-Ip
X-Pagely-Cache
X-SV
Mime-Version
NZSpeedy
X-CSRF-Token
X-Lw-Cache
X-FORWARDED-PROTO
X-DEBUG
X-ACCELERATE
X-Served-Server
Upgrade-Insecure-Requests
X-CH-Device
X-Full-Url
Www.Aujourdhui.Com
X-Instart-Cache-Id
X-Max-Age
Session-Id
X-Amz-Id-1
RequestId
X-Router
X-Deity
X-Cname-TryFiles
WP-AdvCache-MemCached
X-Pixelsilk-Server
X-Pixelsilk-Version
Tempo
X-Hosting
AR-PoweredBy
Microcache
X-Domino-CacheValidationWithETagReason
EQ-Cache
X-Cjtype
AR-CACHE
X-Cache-Original-TTL
AR-ATIME
X-SayCDN-TTL
X-SCM-Server-Number
RSB-LINK
Control-Cache
X-Domino-CacheValidationWithETagResult
!~Request-OOB-Work
X-Say-TTL
X-Say-Cacheable
X-Backend-Name
X-UT-Cache
X-Server-Ip
Generate-Time
PB-PID
AR-SID
X-Cache-Detail
Ttl
X-Debug-Message
X-Amz-Meta-Content-Md5
X-Az
PB-RID
Tesla.Performance
X-CCM
Uuri
X-Custom-Header
X-DevSrv-CMS
Quri
X-AppVersion
X-Served
X-DynamicCache
X-Mobile-Rewrite
X-Route
X-VC-Cacheable
X-Turpentine-Esi
X-Nginx-Request-Time
X-Activity-Id
X-Search-Id
X-Header-Treatment
X-VC-Debug
X-Enabled2
X-Enabled1
X-Made-On
X-FastCGI-Cache-Status
X-Enabled3
X-VC-Hash
X-HA
Note
X-Status
Cache-Status
X-Geo-IP
X-MainProfileID
EN-User
X-XHR-Current-Location
X-MainProfileCategory
X-Skip-Cache
X-REDIRECTSERVER
X-Time-Microsecs
ServerNode
X-BeResp-Ttl
X-MainProfileName
X-Compress-Hint
X-Container
Ec-Machine
X-Node-ID
X-Via-NSCOPI
X-AISO-Server
X-MainProfileURL
StatusCode
X-AISO-Cache
X-AISO-Cacheable
X-S-Misc
X-Upgrade-Enabled
X-SuperCache
X-Uncacheable
ReqUrl
Kanooh-Host
X-7d-Instance-Id
Services
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-Hash
X-7d-Trace-Id
Progma
DrivedBy
X-D-Time
X-LOCATION
X-Generation-Time
X-Node-Name
X-Config-By
X-Cache-Varnish
X-Server-Instance-Name
X-AppServer-Cache-Rule
XDisk
X-Client-Ip
X-Cache-V
X-UnsetCookies
INFO
X-FIRSTBase
Access-Control-Allow-Method
X-RequesterIP
Ec-CorrId
TP-Cache
X-Artvisual-Server
X-Nginx-Request-Processing-Time
X-NodeID
CDCHOST
X-Blog
FRONT-END-SECUREBROWSER
X-XHTML-Minification-Powered-By
Cacheid
Fastly-Restarts
X-Test-Debug
X-Rewritten-By
X-Distil-CS
X-ManagedFusion-Rewriter-Version
X-Pubstack
X-AMAZEEIO
X-Not-Cacheable
X-Box
Expiries
MwpReleaseVersion
MachineName
X-Enhanced-By
Server-ID
TP-L2-Cache
X-MidCOM-Meta-Cache
X-Agent
Debug-Status
X-SilverStripe-Cache
AccessControlAllowOrigin
AMFplus-Ver
X-Instance
X-Cache-Extended
X-DS1D
X-Gannett-Site-Version
Dynatrace
X-Cache-Ttl
X-Oneagent-Js-Injection
X-Ruxit-Js-Agent
X-Ssl-Cipher
X-Lb
X-ESI
X-Oracle-DMS-ECID
Httpd-Identifier
Powered-By-VeryCDN
Language
X-Varnish-Cached
X-Varnish-Cached-TTL
X-Cache-Date
Actioncode
CS-SERVER
X-Server-Vrn
X-Archive-Orig-Connection
X-Archive-Orig-Content-Length
X-Archive-Orig-Date
X-Server-App
X-Archive-Guessed-Charset
X-WHO
Memento-Datetime
X-Debug-Serve
X-Archive-Orig-ETag
X-Request-Processing-Time
X-PBY
X-Built-By
X-AWS
X-Request-Received
X-Archive-Orig-Server
TTL
CD4
X-Instance-Name
X-LB-Backend
X-Cache-Warmer
WP-FROM-CACHE
MSThemeCompatible
Realaction
X-LB-Frontend
X-Meta-Imagetoolbar
X-Wm-VIP
Actual-Object-TTL
X-Wm-1
X-Restarts
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
MSSmartTagsPreventParsing
MageStack-Config
X-M-T
X-M-P
X-M-V
X-Mw-Workerstats
X-Nocache
X-I-V
X-Cacheable-TTL
OracleCommerceCloud-Version
OracleCommerceCloud-Sandiego
X-B
X-Beresp-Ttl
X-Cachable
X-Pageid
X-Pool-Info
X-MyName
X-Middleton-Pagespeed
X-OCTOPOD
X-UPSTREAM-Address
X-WebNode
X-Healthy
X-Transaction-Name
X-Q-S
X-S-C
X-S-V
X-T
Key
X-UPServer
MageStack-Cache
MageStack-Area
MageStack-Cache-Hits
MageStack-Cache-Lifetime
MageStack-Cache-Status
X-Varnish-Store
X-Varnish-Esi-Method
GranicusServer
X-Fastly-Backend-Reqs
X-Varnish-Currency
X-Varnish-Esi-Access
MageStack-Cacheable
MageStack-Debug
X-Origin-Upstream-Status
X-NewCloud-V-Cache
X-ProBase-Server
X-Serverid
CommercePlatform-Version
X-Backend-TTL
MageStack-Web-Node
MageStack-Loadbalancer
MageStack-Magento-Version
MageStack-PageSpeed
MageStack-Tag
CpuTime
Aurora-Node
X-EBAY-C-REQUEST-ID
RlogId
X-FG-RequestId
WSCLoggingUUID
X-PROCESSED-BY
Page-Template
X-Powered-Developer
Response-Time
X-Cache-Bypass
X-CO-Host
X-Nginx-Page-Cache
X-Varnish-Grace
X-Who
X-Cache-Served
X-Ar-Debug
X-Svr
X-This-Proto
X-ACLR-Version
OutputRewritten
X-BC
X-ZSITES-DNS
Accept-CH
X-Ants-Host
X-Ants-Machine-Id
Head
Countrycode
X-Clx-Request
SINA-TS
X-MSU-SOURCE
X-SE-Debug
X-SID
SINA-LB
Requested-Host
ATI-Server-Id
X-COUNTRY-CODE
X-9XB-Server
Cache-Ctrol
X-VG-WebCache
Apple-Itunes-App
X-Time-Zone
X-Varnish-Instance
X-VLoc
CmsfirstPublishTimestamp
X-ServiceProvider
X-Server-FQDN
UrlWatchModule-Time
X-Country
X-ELB
X-PG
X-Varnish-URL
Copyright
X-Service-Id
X-Proxy-Id
XX
Cookie
DB-Nickname
X-Distributed-By
Webserver
Content-Cache
DbServerName
FindLaw
Rewriter
IES-Server
Load-Balancer
X-MCF-ID
X-Nitro-Cache
X-Script
X-ServerAddr
X-Fpc
X-CPU-Time
Request-Time
X-B3-Spanid
X-B3-Traceid
X-Built-With
X-Sid
X-Rocket-Nginx-Reason
Y-Trace
X-ZORequestID
Yola-ID
Fw-Cache-Status
X-Cache-2
X-Title
X-Server-Ident
X-Accel-Cache-Control
X-Czt
X-Layout
X-Memcached
X-IP-Address
X-VCS-Cacheable
X-Config-Version
X-DeliveryServer
X-Dynamic
X-Rocket-Nginx-File
X-Cache-Me-Harder
X-Brought-To-You-By
X-VCS-Ttl
X-WAF-Proxy
E-TAG
VAR-Cache
X-Sn-Servicetimems