Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
X-Cache
CF-RAY
X-AspNet-Version
Strict-Transport-Security
P3P
X-Pingback
Age
Content-Language
X-UA-Compatible
Via
Access-Control-Allow-Origin
X-Adblock-Key
Upgrade
X-Varnish
X-Cacheable
X-Check
X-Template
X-Language
P3p
Content-Security-Policy
X-Generator
X-Buckets
X-Drupal-Cache
X-AspNetMvc-Version
X-Type
X-Cache-Group
X-Xss-Protection
X-Pass-Why
X-Request-Id
X-Hacker
X-Ac
Content-Location
X-Powered-By-Plesk
X-Cache-Hits
X-Runtime
X-Permitted-Cross-Domain-Policies
MS-Author-Via
X-Download-Options
Host-Header
Cartoon
Alt-Svc
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-ShardId
X-Sorting-Hat-PodId
X-Dc
X-Sorting-Hat-Section
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-IPLB-Instance
X-Request-ID
X-Powered-CMS
X-Served-By
Status
X-UA-Device
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
X-Amz-Cf-Id
Access-Control-Allow-Methods
X-Via
X-Iinfo
X-Cache-Status
X-Backend
X-Timer
X-Contextid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
CF-Cache-Status
X-Wix-Server-Artifact-Id
X-DIS-Request-ID
X-ServedBy
X-PC-Key
X-PC-Hit
X-Mod-Pagespeed
Powered-By
X-PC-AppVer
X-PC-Date
X-PC-Host
X-Server
X-Logged-In
Keep-Alive
Content-Encoding
X-Cache-Hit
X-CDN
X-Rid
X-Port
X-Host
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-CST
X-Server-Powered-By
Referrer-Policy
X-Robots-Tag
X-Pad
X-Cache-Enabled
X-Tumblr-Pixel-2
Fastly-Debug-Digest
X-Nginx-Cache-Status
WP-Super-Cache
X-Seen-By
X-Wix-Renderer-Server
X-Wix-Request-Id
X-Endurance-Cache-Level
X-Accel-Version
X-Page-Speed
X-Wix-PunisherID
X-Turbo-Charged-By
X-Forwarded-For
X-Content-Powered-By
X-Drupal-Dynamic-Cache
X-Forwarded-Proto
X-Rack-Cache
X-Content-Digest
X-Varnish-Cache
X-Tumblr-Pixel-3
X-FRAME-OPTIONS
X-AH-Environment
Surrogate-Key-Raw
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Content-Security-Policy-Report-Only
X-Proxy-Cache
X-GitHub-Request-Id
X-Cnection
SPRequestGuid
X-SharePointHealthScore
X-Request-Country
MicrosoftSharePointTeamServices
X-XRDS-Location
X-MS-InvokeApp
X-Cache-Lookup
X-LiteSpeed-Cache
X-Died
X-Original-Date
Edge-Control
Cf-Railgun
X-Safe-Firewall
Timing-Allow-Origin
MicrosoftOfficeWebServer
Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Webserver
X-FullPageCaching
X-Node
Charset
X-FW-Hash
X-PhApp
X-FW-Type
X-FW-Static
X-FW-Serve
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
X-INKT-URI
X-INKT-SITE
X-CF-Powered-By
X-HS-Cache-Config
X-HS-Content-Id
X-Hits
Composed-By
X-Content-Security-Policy
Access-Control-Max-Age
X-Tumblr-Pixel-4
X-Swift-CacheTime
X-Swift-SaveTime
Liferay-Portal
EagleId
Access-Control-Expose-Headers
Served-By
X-Hyper-Cache
Content-MD5
Grace
X-Spip-Cache
X-CDN-Pop
X-CDN-Pop-IP
Request-Context
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-Device
X-BC-Stapler
X-Backend-Server
X-Server-Name
X-Dw-Request-Base-Id
Rating
X-Microcachable
X-Fastly-Request-ID
X-Newrelic-App-Data
X-Firenze-Processing-Times
X-Microcache
X-Tumblr-Content-Rating
X-FB-Debug
X-RateLimit-Remaining
Content-Style-Type
X-VCache
X-RateLimit-Limit
Content-Script-Type
X-User-Agent
X-ServerName
Public-Key-Pins
X-RateLimit-Reset
X-Clacks-Overhead
X-Jimdo-Instance
X-Jimdo-Wid
Xkey
X-Cloud-Trace-Context
X-Cache-Config
X-Loop
X-TNCMS
Real-Hostname
Expect-CT
X-DDC-Arch-Trace
Refresh
X-Acc-Exp
Surrogate-Control
WPE-Backend
X-Age
Front-End-Https
X-XN-Trace-Token
X-XN-XNHTML
X-Aspnetmvc-Version
Fpc-Cache-Id
X-Hostname
PageSpeed
X-Px
Display
X-Generated-By
X-Middleton-Response
Response
X-Middleton-Display
X-Sol
X-SS-Location
X-N-OperationId
X-SS-Conf
Surrogate-Key
X-DNS-Prefetch-Control
X-Cached
X-Tumblr-Pixel-5
X-SERVER
X-LiteSpeed-Cache-Control
X-Topify-Platform
X-MiniProfiler-Ids
X-Cached-By
X-Pantheon-Site
X-Pantheon-Environment
X-Pantheon-Phpreq
X-URL
X-StackifyID
X-Zen-Fury
X-WebKit-CSP
X-Request-Time
X-Servedby
X-Content-Options
Edge-Control-Message
Rt-Fastcgi-Cache
X-Outils-CS
X-OneAgent-JS-Injection
X-HOST
X-FORWARDED-FOR
X-Amz-Version-Id
X-Whom
TCN
X-CMS-Version
X-Url
X-Ruxit-JS-Agent
X-DynaTrace
X-AspNetWebPages-Version
X-Umbraco-Version
X-ApacheServer
X-Varnish-Cache-Hits
X-PERF
X-DynaTrace-JS-Agent
X-Varnish-TTL
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Correlation-Id
Product
Imagetoolbar
Access-Control-Request-Method
X-Handled-By
Alternate-Protocol
Host
X-Engine
X-Magento-Tags
Powered
X-Kinsta-Cache
DynaTrace
X-Powered-By-360WZB
WZWS-RAY
X-Recruiting
X-NWS-LOG-UUID
X-Cache-Rule
P-WS
P-LB
Generator
X-From
X-Msg-2-Log
X-Micro-Cache
X-Edge-Location
X-Track
X-CacheServer
X-Response-Time
X-Location-Id
ServedBy
X-Hosted-By
Fhost
X-VTEX-Cache-Status-Janus-ApiCache
No
X-Vtex-Processed-At
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-VTEX-Janus-Router-Backend-App
X-Powered-By-VTEX-Janus-ApiCache
X-B-Cache
X-Cache-Age
X-VARNISH-Cache
X-Goog-Hash
X-LBLID
X-Tumblr-Pixel-6
X-Fastcgi-Cache
X-Powered-By-VTEX-Janus-Edge
X-Application-Context
Origin
X-Instart-Request-ID
Fastcgi-Cache
Arr-Disable-Session-Affinity
X-Varnish-Host
X-Developer
X-RESOURCE
X-UD-Method
X-URLSCHEME
Content-Hash
Akamai-IP
X-TransIP-Balancer
X-BS
X-I-Sp
X-Actual-URL
X-Matrix-Proxy
X-Matrix-Server
X-Returned-From
X-Returned-From-DLL
X-Passed-To-DLL
X-Original-Request
X-App-Hosting
X-Passed-To
X-LB
X-Returned-From-BeforeDispatch
X-Origin
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
Dmn
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Cache-Info
X-Cdn
X-Varnish-Beresp-Grace
X-Internal-ReqID
X-Shop-Id
X-Defender
X-Akamai-Transformed
X-Storage
X-Stale
X-I
X-Device-Type
IBM-Web2-Location
X-Source
X-S
X-Rocket-Nginx-Bypass
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
X-NetCat-Version
X-HS-Content-Campaign-Id
X-Cache-TTL
X-Varnish-RemainingTTL
X-Accel-Expires
X-Varnish-RemainingLife
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-TransIP-Backend
X-Upstream
X-Varnish-Seen-By
USPLoggingUUID
X-Cache-Debug
X-Powered-By-VelaWeb
X-Cache-Tags
X-Varnish-Cacheable
Ohc-File-Size
X-Dispatcher
X-Gamma-Serve
X-Revision
Pool
X-EdgeConnect-Origin-MEX-Latency
X-Microcache-Status
X-Varnish-HitMiss
X-Varnish-Count
HTTPS
X-Translation
X-Front
X-Version
X-Signature
X-Daa-Tunnel
X-Route-Server
X-LB-Node
X-Last-Modified
X-VTEX-Cache-Status-Janus-Edge
X-Cache-Operation
X-Varnish-Backend
X-Platform
Version
X-Cache-Lifetime
X-Content-Encoded-By
X-UPSTREAM
X-Supported-By
Srv
Content-Disposition
X-Expires-Orig
X-NoCache
X-SDS
MIME-Version
Powered-By-ChinaCache
Last-Published
X-EdgeConnect-MidMile-RTT
X-Cache-Key
X-NewRelic-App-Data
X-ATG-Version
X-Art-Request-Id
X-Dispatch
ServerName
X-Server-Upstream
Node
X-Director
X-Page-Cache
X-Server-Id
X-Duration
Public-Key-Pins-Report-Only
X-AOL-HN
X-Vcap-Request-Id
Cache-Key
X-SSL-Protocol
Proxy-Connection
X-Platform-Cache
X-Hypernode
X-Varnish-Age
X-Debug
X-SSL-Cipher
X-Debug-Info
X-TTL
X-Firenze-Processing-Time
Cache-Tag
Page-Completion-Status
X-Flow-Powered
X-Cache-Only-Varnish
X-Url-Base
X-F-Cache
ServerID
SSPAppContext
X-Cookie-Domain
X-SV-Cacheable
X-SV-CreatedAt
X-SV-CacheTags
X-SV-Duration
X-SV-Edge
X-Abgroup
X-SV-Expires
X-SV-FromDBCache
X-Sapient
FAI-W-FLOW
X-Abuse
X-SV-Nginx-Duration
X-SV-Pid
X-PwB-Node
X-Country-Code
Allow
X-Edge-IP
X-Platform-Server
X-Cache-Expires
Edge-Content-Tag
X-Cache-Control-Orig
Lsrequestid
IM-Version
X-Amz-Meta-S3cmd-Attrs
X-Cache-CFC
Cneonction
WSR-Cache
X-GeoIP-Country-Code
PICS-Label
X-Geo-Country
X-Dns-Prefetch-Control
X-CJ-Soft
X-Grace
X-ServerID
X-Nbs
X-Speed-Cache
X-Client-IP
X-Magento-Cache-Debug
X-ORACLE-DMS-ECID
X-Server-ID
X-Sucuri-ID
If-Modified-Since
X-Speed-Cache-Key
SN
Location
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
Accept-Encoding
Content-Encoding-Handler
X-GeoIP-Country-Name
X-Processed-By
X-Frontend
X-Sucuri-Cache
NnCoection
X-Content-Age
X-Id
Author
X-RequestId
X-Akamai-Device-Characteristics
X-Purge-URL
X-FW
X-Processing-Time
Backend
X-SERVER-NAME
Cache-Provider
X-Varnish-IP
X-LW-Cache
X-CDN-Cache-Status
X-CDN-Node
X-Cache-Server
X-Orig-Vary
CacheControlHeader
Req-Id
X-Goog-Stored-Content-Length
X-Proxy
X-GUploader-UploadID
X-Purge-Host
X-BackendServer
X-SRCache-Key
X-ARC
X-Shield-Request-Id
X-Goog-Storage-Class
X-Goog-Metageneration
X-Nginx-Cache
A-Powered-By
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Akamai-Device-Model
X-N
X-Discourse-Route
X-NB-Cached-Page
X-Middleware-Start
X-Real-Server
X-Vhost
Qs-Cache
X-Yadis-Location
S-Cnection
X-Time
X-Varnish-Url
X-Trace
NetMindSessionID
X-Lambda-Id
X-Framework
X-BKSrc
X-Loopia-Node
X-Ttl
MJ12bot
Cached
SEOMOZ
X-Generated
X-Browser
AMF-Ver
Section-Io-Id
Fw-Via
RTSS
X-Healthy
X-Cache-Handler
Use-Proxy
Pv
X-TB-M
X-DealerOn
Accept-Charset
MC
X-Magnolia-Registration
X-IsCacheURL
Nodo
X-Cache-Control
X-Cache-Type
X-Content-Security-Policy-Report-Only
S
X-Twitter-Response-Tags
X-Hiawatha-Cache
X-Always-Cache
X-Connection-Hash
X-Transaction
Cache
NODE
Cteonnt-Length
RATING
X-CDN-Forward
X-Varnish-Server
X-Unique-ID
Tracecode
X-Varnish-Hits
X-Cache-Level
Local-Info
X-Pressidium-NinukisWP-Ver
WWW-Authenticate
X-Config-Blacklist-Version
X-SE-Debug
X-WR-Flags
X-Worker
X-PF-Uncompressing
Access-Control-Allow-Header
Nitro-Cache
Thanks
X-Content-Type-Option
SVR
X-Cache-Engine
Server-Info
X-ClientSide-Caching
X-Drupal-Cache-Tags
Identity
Content-Transfer-Encoding
X-Srv
X-Sys-Req-ID
Retry-After
Xc-Version
Cm-Server
Frame-Options
X-Cache-PageType
X-Empowered-By
X-Cache-Fix
X-Adobe-Content
X-Adobe-Loc
X-Mobilized-By
X-HP-Trace-ID
Server-Name
HAVer
HCVer
X-HP-Trace-Project
X-LW-Web-Server
X-Varnish-Retries
X-High-Performance
X-CF-Passed-Proto
X-Traffic
X-Varnish-Ttl
X-VC-TTL
X-ID
X-Symfony-Cache
NtCoent-Length
Buuteeq-Source
X-Cache-Device-Type
Eomportal-Instance
X-Server-IP
X-Route-To
X-Drectory-Script
EagleEye-TraceId
X-Remote-Addr
X-Fedora-School-Id
X-Resty-Request-Id
X-Session-Reinit
BALANCEDTO
X-Magento-Cache-Control
X-Hit-Cache
X-Amz-Storage-Class
CLMOB
X-Site-Name
X-Pagename
X-Varnish-ID
X-SO
X-Directory-Script
X-LB-Server
X-Cache-TTL-Remaining
X-Static
X-CB-Server
X-ACMCache
AsisCache
X-WN-ClientGroup
HitType
WN
X-A
Disablevcache
SBGI-1
X-JG-Page-Cache
X-Webcelerate
X-AF-Userserver
Web-App-Origin-Name
X-Runtime-Rack
SBGI-7
X-RiS-UFDI
SBGI-RealPath
SBGI-9
SBGI-Device
Content_type
X-OPNET-Transaction-Trace
SBGI-RenderTime
Max-Age
SBGI-5
SBGI-10
X-Cache-Source
X-Environment
X-Disney-Akamai-Rule
X-Cache-Provider
X-Yottaa-Metrics
Pics-Label
X-Yottaa-Optimizations
X-Cocoon-Version
From-Origin
X-Middleton-PageSpeed
AC-ELC
X-FORWARDED-PROTO
X-VC-Enabled
X-UA
X-Generated-Time
X-LP
X-WHOIS-Cached
X-Cache-Node
X-FireWall-Port
X-Culture
XDomainRequestAllowed
X-Powered-By-Server
X-Client-Image-Vid
X-Client-Vid
X-EPiphany-Vid
X-Served-Server
ScoreTracker
ServerTokens
ServerSignature
X-Jphone-Copyright
X-E
X-Ser
X-App
Dispatcher
SRV
X-Cache-Dispatcherpragma
X-App-Server
X-ARRServer
IISExport
X-Frame-Option
X-Cache-Dispatchercachecontrol
X-Runtime-Memory
X-Dynatrace-Js-Agent
Dis-Env
X-App-Runtime
Front
X-Balanceador
X-Runtime-Affili
X-Esi
Machine
Keywords
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Detail
X-Mobile-URL
X-Distributor
From
X-Site
X-Cached-Status
Ufe-Result
VServer
X-App-Status
X-Rack-Cors
X-WR-MODIFICATION
X-Page
X-Hosting-Env
X-Nginx-Host
X-Blog
X-SDE-Name
Magicmarker
X-OpenCart-Lightning
X-Debug-Token
X-Cache-Doesi
X-ORACLE-DMS-RID
X-Varnish-Hostname
Provider
X-Session-ID
Strikingly-Cached-Version
X-AEM
X-VARITI-CCR
X-NginX-Cache
X-PageType
SS
Strikingly-Cached
X-Drupal-Cache-Contexts
RN-Server
X-DataDome
Backend-Timing
Description
X-Info
X-ServerIndex
X-Analytics
X-GeoIP
Strikingly-Cache-Region
X-Garden-Version
X-HW
X-Atraveo-ETag
X-Atraveo-Expires
X-Domain-Checked
X-Atraveo-Cache-Control
X-Provisioner-Version
Cmstype
X-Unbounce-Variant
Cmsid
X-Atraveo-Param-Rm
X-Batcache
X-Wikidot-Static-Cache
X-Force
X-IIJ-Cache
X-PRAM
X-Server-Instance
NLCacheNote
X-Unbounce-PageId
X-Atraveo-Set-Cookie
X-Unbounce-VisitorID
X-Atraveo-TTL
X-Atraveo-Varnish-Server-Id
X-HP-Redirect
X-Atraveo-Zone
X-Atraveo-From-Varnish-Cache
X-Resolver-IP
X-Cache-On
X-Rewrite
X-SH-Cache-Status
X-Wikidot-Backend
DNNOutputCache
X-Desc
X-GSL-Server
X-CAPServer
X-Machine-Name
X-Key
X-Time-Microsecs
X-Actindo-RS
W
X-HydroSheep
Response-Time
X-Application
Home
Paypal-Debug-Id
X-MAT-GEO
Sophnep-Edge-FX
X-Machine
SG
Hname
X-Varnish-Action
X-RDP
X-SmugMug-Values
X-SmugMug-Hiring
X-Rebelmouse-Cache-Control
ViewMode
X-TTFB
X-TTFB-L
X-Source-ID
X-Rebelmouse-Surrogate-Control
X-Backend-Status
Bios
X-Amz-Id-1
X-Amcomm-Site
X-Pageid
CommunityServer
Ctx
Fastly-Backend-Name
X-FRUIT
X-Proto
Smug-CDN
Yoncu-Errno
X-Author
MW-Webserver
X-Location
X-PM-ID
X-Header
Ttl
X-Autoru-LB
X-NginX-Server
X-Render-Time
X-AutoRu-App-Id
X-Autoru-Host
Worker
Resin-Trace
X-Cms-Mode
X-Dev
X-Correlation-ID
X-Cdn-Forward
X-Map-Context
X-Detected-Device
X-Req-Head-Response
X-Grid-Server
FastCGI-Cache-Status
Lb
X-Frames-Options
X-KoobooCMS-Version
VANITY-HOST
X-WebKit-CSP-Report-Only
X-ASAP-Cache
X-Viator-Tapersistentcookie
X-Varnish-Debug-Age
Id
X-Cluster-Node
X-Varnish-Debug-TTL
Set-Cookie2
Cluster-ID
X-HashTwo
X-Hosting
X-Data-Request
X-HA-Frontend
X-HA-Backend
Xc
N365rili
X-Environment-Context
OriginServer
SBMCLOUD
X-Captured
X-Env
Ibf5scheme
X-Webapp
X-Clara-ASAP
X-RemovedCookies
X-Config-By
X-Smartcache-Timeout
X-L-Path
X-Magento-Action
X-Proxy-Cache-Key
X-CRA-DC
X-Sc-Cache
Content-Server
X-ProcessESI
X-WP
X-Trace-Id
X-Response
Beyond-Iis
X-Smartcache-Keys
X-Lb
X-ACCELERATE
X-SV
PagesDisplayed
X-Batcache-Reason
X-Stage
X-Optimization
BackendServer
X-This-Proto
Og
X-ENV
X-Varnish-Info
Nginx-Cache
X-Hstore
X-Hrouter
X-Rack-CORS
X-MCB-Server
Device
X-ETag
X-Goog-Meta-Policy
X-EC2-Instance-Id
X-Test
X-Resource
X-Goog-Meta-Replace
Server-ID
X-JSESSIONID
X-Zendesk-Origin-Server
X-Depends
AccessControlAllowOrigin
Note
NS-VaryByCustom-Key
X-Cache-Via
RequestId
X-Zendesk-User-Id
WP-AdvCache-MemCached
X-Airee-Node
X-Reflector-Cache
X-Upgrade-Enabled
X-Cacheable-TTL
X-Varnish-Cache-Local
X-CacheResult
X-7d-Trace-Id
X-CDN-RULE
X-CDN-COMPRESS
FindLaw
X-Avvio-Cms-Cacheload
Proxy-Cache
Il-Cl
X-DTC
X-Adnet
X-Secret
Expect-Ct
X-MidCOM-Meta-Cache
X-Forwarded-Host
X-LBPoolMember
Cleartype
NCache
Access-Control-Request-Headers
X-Powered-By-Home.Pl
Traffic-Origin
X-Plat
X-MSEdge-Ref
X-RAMCache
X-Compressed-By
X-V
X-HTML-Minification-Powered-By
X-Cache-TTL-Age
X-Cache-TTL-Current
X-RealServer
X-7d-Instance-Id
Web
X-Reflector
Tempo
X-CACHE-TTL
X-Nginx-Request-Time
X-Rq
X-DB-Content-Length
X-We-Are-Hiring
X-Varnish-Instance
X-Nginx
X-Cache-Keep
X-APP
X-Src-Webcache
X-Dw-Trace-Id
SERVER-ID
X-AppServer-Cache-Rule
Content-Cache
X-AISO-Cacheable
X-AISO-Server
X-AISO-Cache
X-SilverStripe-Cache
X-Amzn-Trace-Id
SINA-TS
SINA-LB
X-Refresh
UrlWatchModule-Time
Webserver
Rewriter
X-Upstream-Backend
X-Amzn-RequestId
X-Sid
X-DevSrv-CMS
VAR-Cache
DbServerName
F5-IpCliente
TC-S-Cache-M
TC-S-Cache
X-Ghost-Cache-Status
X-ACLR-Version
COMMERCE-SERVER-SOFTWARE
X-Cache-Time
TC-Cache-U
TC-Cache-IC
X-Apm-Telemetry-Syncmark
X-SmartBan-URL
ServerIP
Session-From
TC-Cache
X-Server-Generated
X-Search-Id
X-DSMX-Rewrite-MS
X-Flex-Tag
X-Flex-Community
X-Flex-Lastmod
X-Flex-Lang
X-Flex-Evend
X-DSMX-Render-MS
Myheader
X-OCTOPOD
X-Distil-CS
X-Obj.Ttl
X-Flex-Tags
X-SCM-Server-Number
X-B2f-Not-Route
X-SmartBan-Host
X-S-Misc
X-Proxy-Id
X-Server-FQDN
X-SuperCache
X-Uncacheable
X-Time-Zone
X-HAProxy
X-Generation-Time
X-DDM-SERVER
X-D-Time
X-DDM-SERVER-UPDATED
X-ELB
X-Rocket-Nginx-Serving-Static
X-VLoc
X-XHR-Current-Location
X-LOCATION
X-Ezoic-Cdn
X-M
X-Node-Name
X-CCM
X-DN-Cache-Control
X-Highwire-SessionId
X-Highwire-RequestId
ClientIP
Accept-Language
X-Flex-Evstart
Gzip
X-Gyrobase-Publication
X-Country
X-Beresp-Ttl
Debug-Status
SiteSpeed
Provided-Host
AMFplus-Ver
X-Title
X-Layout
X-NewCloud-V-Cache
X-Rocket-Nginx-Reason
RSL-Trace-ID
SB-Cache-Life
WFE
X-CACHE-KEY
X-CH-Device
Session-Id
SB-Site-IE-VERSION
PServer
MageStack-PageSpeed
SB-Site-Device
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Fpc
MageStack-Cacheable
MageStack-Cache-Status
MageStack-Cache-Lifetime
MageStack-Tag
MageStack-Config
MageStack-Magento-Version
MageStack-Loadbalancer
MageStack-Debug
MageStack-Cache-Hits
MageStack-Web-Node
Brightspot-Id
X-Cms-Server
AMP-Access-Control-Allow-Source-Origin
X-Cache-Me-Harder
MageStack-Area
MageStack-Cache
X-App-Version
X-Backend-TTL
Ews
SB-Cache-Remaining
X-Webstats-RespID
X-HostName
X-REDIRECTSERVER
X-Box
X-Brought-To-You-By
X-Cache-Extended
X-UseReverse-Proxy
X-W3TC-Minify
NZSpeedy
X-Cache-FS-Status
X-CacheID
X-PBS-Appsvrip
X-PBS-Appsvrname
X-PBS-Fwsrvname
XDisk
X-VC-Debug
X-Catalyst
X-DEBUG
Url
X-Provided-By
X-RiS-PX
X-Artvisual-Server
X-IP-Address
X-PHP-Response-Code
X-EC-Security-Audit
X-Front-Cache
X-Router
X-Router-Backend
X-Session-Id
X-Tradeindia-Request-GUID
X-DeliveryServer
X-Cache-Warmer
X-ReqId
X-Dynamic
X-Tradeindia-SMgmt
X-Webkit-CSP
X-Nocache
X-Pixelsilk-Version
Warning
StatusCode
X-4ormat-Cacheable
X-Dynamic-Cache
X-Ocache
X-IP
X-Lima-Id
X-Server-Addr
MS-CV
X-Tag-Playlist
Swift-Performance
Server-Ip
X-Cache-HT
X-Cache-BE
X-PBY
X-Pixelsilk-Server
X-ChromeLogger-Data
X-Turpentine-Esi
X-Custom-Header
X-Serendipity-InterfaceLangSource
FrontEnd
X-Cache-Id
X-Serendipity-InterfaceLang
X-FreeTag-Count
X-Amz-Meta-Content-Md5
X-Obj-Ttl
X-Header-Treatment
X-Route
X-Beatles
X-Cname-TryFiles
X-Debug-Message
MSThemeCompatible
ENV
X-UPSTREAM-Address
!~Request-OOB-Work
Access-Control-Allow-Method
INFO
X-Svr
X-UT-Cache
Cache-Status
X-Vary-Options
D
X-Cjtype
X-XHTML-Minification-Powered-By
Cache-Tags
X-Backend-Name
Fw-Cache-Status
X-UnsetCookies
X-Phpwcms-Release
X-Real-IP
X-Count
X-Phpwcms-Page-Processed-In
X-Origin-Cache
X-ServiceProvider
X-NID
X-NodeID
X-Deity
X-Made-On
X-Config-Version
X-Jcms-Ajax-Id
X-HASH
GP-Remote-Addr
GP-Version
X-Not-Cacheable
X-Server-Instance-Name
PLCDN
X-Old-Content-Length
X-Gannett-Site-Version
X-Aramark-SID
X-CM-FE
X-WPL-DATA
Server-Id
X-Highwire-Smart-Code
DrivedBy
X-GoCache-CacheStatus
X-Highwire-Sitecode
X-NewsFlow-Sitename
X-MainProfileURL
SHInfo
TP-Cache
TP-L2-Cache
X-WebNode
X-CSRF-Token
X-Served
X-Ss-Location
X-Ss-Conf
X-Webkit-Csp
X-Agent
X-MainProfileCategory
X-MainProfileID
X-MainProfileName
X-Container
X-HP-CAM-COLOR
Ibm-Web2-Location
X-Faeria
X-Who
RSB-LINK
X-Enhanced-By
X-Nginx-Request-Processing-Time
X-RequesterIP
X-Farm-Server
X-Varnish-Cached-TTL
X-Backend-Host
X-Varnish-Cached
X-WA-Info
Aurora-Node
X-AMAZEEIO
X-AppVersion
X-Built-With
X-Cache-Varnish
CDCHOST
Edgecast
X-DynamicCache
X-MCF-ID
IsMobile
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
X-Fstrz
X-Accel-Cache-Control
X-DS1D
X-Pagely-Cache
X-Meta-MSThemeCompatible
Generate-Time
Progma
X-Streams-Distribution
X-Node-ID
X-Wm-VIP
X-Unique-Id
X-Wm-1
MSSmartTagsPreventParsing
Expiries
Kp-EeAlive
X-Bcwwwid
X-Rewritten-By
X-AWS
X-FIRSTBase
X-Pubstack
X-Test-Debug
X-ManagedFusion-Rewriter-Version
X-COUNTRY-CODE
X-C2M-Server
X-C2M-Runtime
X-Litespeed-Cache-Control
X-Cf-Powered-By
X-Varnish-URL
X-Oracle-DMS-ECID
X-Webkit-CSP-Report-Only
X-Ssl-Cipher
DB-Nickname
X-Ezpublish-Installationid
X-Client-Ip
WSCLoggingUUID
Lookup-Cache-Hit
Tk
X-ESI
X-Ezpublish-Nodeid
X-Obvious-Info
X-Obvious-Tid
X-Origin-Server
X-Stiffia-Cache
X-PROCESSED-BY
X-Pass-Through
X-FPC
E-TAG
X-FG-RequestId
X-Script
X-MSU-SOURCE
X-ServerAddr
X-Clx-Request
Requested-Host
X-Service-Id
X-SID
X-Cache-Bypass
X-VG-WebCache
X-Diazo-Applied
X-EC-Custom-Error
Cache-Ctrol
X-UPServer
X-EBAY-C-REQUEST-ID
X-SVR
X-Sn-Servicetimems
X-Generated-Date
Rlogid
M
X-Tt-Dbg
X-Skip-Cache
X-Geo-IP
B-Rlogid
Content-Generator
Language
Resource
WP-Cache
ReqUrl
X-Transaction-Name
X-Cache-ID
Upgrade-Insecure-Requests
Microcache
Be
Contao-Page-Layout
EQ-Cache
HostName
X-HEAD
X-Magento-Lifetime
X-Serverid
X-VNode
X-Pool-Info
X-Build-Id
Httpd-Identifier
X-ASAP-Age
X-Support
X-Varnish-Debug-Hits
Tesla.Performance
User-Cache-Control
Aoestatic
X-Prerendered
X-BC
X-Ants-Machine-Id
X-BPool
X-BPool-Back
X-BPool-Bx-Cache
X-Ants-Host
X-Netrix-ID
Accept-CH
X-SRV
X-Cachable
TheAnswer
X-BPool-Fx-Cache
X-BServer
Hosted-By
X-Cluster
Session
Server-Tuning
V-Age
X-Auto-Login
X-NMT-Proxy
X-Protected-By
CpuTime
X-Instance-Id
X-Theme
Container
X-Archive-Orig-Connection
X-Ec-Custom-Error
X-Archive-Guessed-Charset
Public-Extension
ResourceTag
Content-Legth
X-Varnish-Store
X-Varnish-Esi-Access
X-Varnish-Esi-Method
X-Varnish-Max-Age
X-Varnish-Set-Cookie
X-No-Session
X-Beatles-Hits
Memento-Datetime
EXT-CACHEEXPIRE
X-TTL-Age
Vserver
X-Enabled3
X-Enabled2
Server-Node
X-Cache-Set
X-Does-He-Have-Time
X-Enabled1
X-Varnish-Currency
X-Turpentine-Cache
X-Cache-Served
X-Ar-Debug
X-Debug-Out
X-Debug-Serve
X-ServedByHost
Www.Aujourdhui.Com
WebServer
X-Server-App
Kanooh-Host
OutputRewritten
ServerNode
X-Request-Received
X-Request-Processing-Time
X-Archive-Orig-Server
X-Archive-Orig-ETag
X-Archive-Orig-Date
X-Archive-Orig-Content-Length
X-Built-By
X-Content-Parsed-By
X-B3-Spanid
X-B3-Traceid
X-Hash
X-Max-Age
X-Would-Your-GrandPa-Wait
X-Your-GrandPa-Would-Wait
Ez
X-AG-MIPS
Application
MwpReleaseVersion
Debug-Expires
X-W-Cache-Hits
X-W-Cache
X-ZORequestID
Yola-ID
X-BeResp-Ttl
X-Cache-Action
VC-NoCache
Debug-Cache-Control
CD1
No-Cache
Url-Hash
Apple-Itunes-App
X-Instance-Name
X-FastCGI-Cache
X-UUID
AGI-Request-ID
Actual-Object-TTL
X-Restarts
X-Op-Benvironment
X-HS-Status
GranicusServer
ProxiaInstanceId
X-CPU-Time
X-Amz-Meta-Version-Id
X-Vol-Correlation
AR-SID
X-Vol-Mrp
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Cache-LB
X-Csrf-Token
Copyright
Prototype-RootPath
X-Czt
X-FCMS-Cache
0
X-SCProxy
X-Forwarded-By
X-Imforza-Hosted
X-Pj-Cache-Status
X-Processed
X-9XB-Server