Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
P3P
X-AspNet-Version
Age
X-Pingback
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Template
X-Language
X-Generator
X-Buckets
Alt-Svc
X-Request-Id
X-Drupal-Cache
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Powered-By-Plesk
X-Permitted-Cross-Domain-Policies
Content-Location
X-Download-Options
Host-Header
X-Runtime
X-ShopId
MS-Author-Via
X-Sorting-Hat-Section
X-Dc
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-FRAME-OPTIONS
Cartoon
X-Powered-CMS
X-UA-Device
X-IPLB-Instance
X-Served-By
Access-Control-Allow-Headers
Status
Access-Control-Allow-Credentials
X-Amz-Cf-Id
Access-Control-Allow-Methods
X-Cache-Status
P3p
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
CF-Cache-Status
X-Contextid
X-Backend
Referrer-Policy
Powered-By
X-PC-Hit
X-PC-Key
X-Mod-Pagespeed
X-DIS-Request-ID
X-PC-Date
X-PC-Host
X-PC-AppVer
X-ServedBy
Content-Encoding
X-WPE-Loopback-Upstream-Addr
X-CST
X-Logged-In
Keep-Alive
X-Request-ID
X-Rid
X-Host
X-Server
X-Cache-Hit
X-Port
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-CDN
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Server-Powered-By
X-Robots-Tag
X-Endurance-Cache-Level
X-Nginx-Cache-Status
X-Tumblr-Pixel-2
X-Wix-Request-Id
X-Seen-By
X-Wix-Server-Artifact-Id
X-Accel-Version
X-Turbo-Charged-By
X-Original-Date
X-Page-Speed
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
X-Content-Digest
WP-Super-Cache
X-Proxy-Cache
X-Rack-Cache
X-AH-Environment
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Tumblr-Pixel-3
X-Varnish-Cache
X-LiteSpeed-Cache
X-GitHub-Request-Id
X-Ua-Compatible
SPRequestGuid
X-Request-Country
X-SharePointHealthScore
Edge-Control
X-XRDS-Location
X-MS-InvokeApp
X-Cnection
MicrosoftSharePointTeamServices
X-Cache-Lookup
Timing-Allow-Origin
Cf-Railgun
X-Died
X-Node
X-Amz-Id-2
X-Amz-Request-Id
X-FW-Hash
X-Trace
Charset
X-FW-Type
X-FW-Static
X-FW-Serve
Request-Id
X-Webserver
Edge-Cache-Tag
X-FullPageCaching
X-Content-Security-Policy
X-HS-Cache-Config
X-Webcom-Cache-Status
X-HS-Content-Id
X-PhApp
MicrosoftOfficeWebServer
X-Hits
Request-Context
X-Safe-Firewall
SPIisLatency
SPRequestDuration
X-CF-Powered-By
Access-Control-Max-Age
X-Newrelic-App-Data
X-INKT-URI
X-INKT-SITE
X-PHP-Backend
X-BC-Stapler
Composed-By
Access-Control-Expose-Headers
Grace
Served-By
X-Swift-CacheTime
X-Swift-SaveTime
EagleId
X-CDN-Pop-IP
X-CDN-Pop
X-Tumblr-Pixel-4
Liferay-Portal
X-Spip-Cache
X-SERVER
X-Hyper-Cache
X-Backend-Server
X-Device
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-Microcache
X-Server-Name
X-LiteSpeed-Cache-Control
X-ServerName
Content-Style-Type
X-RateLimit-Remaining
X-VCache
Rating
X-Wix-Renderer-Server
X-RateLimit-Limit
X-Clacks-Overhead
X-FB-Debug
Content-Script-Type
X-Cloud-Trace-Context
X-RateLimit-Reset
X-Jimdo-Instance
X-Jimdo-Wid
X-User-Agent
Surrogate-Control
X-DDC-Arch-Trace
X-Acc-Exp
X-Loop
X-Firenze-Processing-Times
Real-Hostname
X-TNCMS
Front-End-Https
X-Cache-Config
Public-Key-Pins
Refresh
X-Tumblr-Content-Rating
X-XN-XNHTML
X-XN-Trace-Token
X-DNS-Prefetch-Control
X-Middleton-Response
X-Middleton-Display
Fpc-Cache-Id
X-Hostname
X-Servedby
X-Sol
X-Age
Display
X-HS-Combine-CSS
Response
X-StackifyID
Xkey
X-SS-Location
X-SS-Conf
X-Microcachable
X-Vtex-Processado-Em
X-Generated-By
X-Cached
X-Tumblr-Pixel-5
X-Px
X-Zen-Fury
X-Cdn
X-N-OperationId
X-OneAgent-JS-Injection
PageSpeed
X-Topify-Platform
X-MiniProfiler-Ids
X-Cached-By
X-Correlation-Id
X-Request-Time
X-Frame-Option
TCN
X-Url
X-Kinsta-Cache
X-WebKit-CSP
X-Ruxit-JS-Agent
X-Amz-Version-Id
P-WS
P-LB
X-CMS-Version
X-Whom
Rt-Fastcgi-Cache
X-Handled-By
X-Varnish-TTL
X-Outils-CS
X-Magento-Tags
X-DynaTrace-JS-Agent
Product
X-URL
X-Content-Options
Imagetoolbar
X-Via-JSL
Edge-Control-Message
X-B-Cache
Surrogate-Key
X-VARNISH-Cache
Powered
X-AspNetWebPages-Version
Access-Control-Request-Method
X-CacheServer
Host
X-Engine
X-DynaTrace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Track
Fastly-Debug-Digest
X-Edge-Location
No
X-Vtex-Remote-Cache
X-Debug-Info
X-Varnish-Cache-Hits
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processed-At
X-VTEX-Cache-Status-Janus-ApiCache
X-Powered-By-VTEX-Janus-ApiCache
X-Forwarded-For
X-Recruiting
X-Cache-Rule
ServedBy
Alternate-Protocol
X-Umbraco-Version
Fhost
X-HOST
X-FORWARDED-FOR
X-ApacheServer
X-PERF
X-Powered-By-VTEX-Janus-Edge
X-Goog-Hash
X-Application-Context
X-NWS-LOG-UUID
Public-Key-Pins-Report-Only
X-LBLID
X-Signature
X-Msg-2-Log
X-Actual-URL
X-Powered-By-360WZB
WZWS-RAY
Generator
X-Passed-To-DLL
X-Returned-From-DLL
X-Passed-To
X-Original-Request
X-Platform
X-Returned-From
X-From
X-Passed-To-BeforeDispatch
X-Returned-From-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Response-Time
X-Location-Id
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Accel-Expires
DynaTrace
X-Cache-Age
X-Hosted-By
X-Stale
X-Developer
Arr-Disable-Session-Affinity
X-UD-Method
Dmn
Fastcgi-Cache
X-Upstream
X-Tumblr-Pixel-6
X-Source
X-Platform-Router
X-Platform-Processor
X-Micro-Cache
HTTPS
X-RESOURCE
X-LB
X-LW-Cache
X-Version
Akamai-IP
X-Platform-Cluster
X-Cache-Info
X-Varnish-Host
X-Supported-By
X-Rocket-Nginx-Bypass
X-URLSCHEME
X-Pantheon-Environment
Surrogate-Key-Raw
X-Pantheon-Phpreq
X-Pantheon-Site
X-Varnish-HitMiss
X-TransIP-Balancer
X-Varnish-Count
X-I-Sp
X-BS
X-Defender
X-Fastcgi-Cache
X-Shop-Id
Retry-After
Content-Hash
Origin
X-Device-Type
X-Rnd
X-Instart-Request-ID
X-S
Cache-Provider
X-Cache-TTL
X-EdgeConnect-Origin-MEX-Latency
X-NetCat-Version
X-Magento-Cache-Debug
X-Storage
X-Cache-Key
X-CSRF-Protection
X-HS-Content-Campaign-Id
X-Cache-Tags
X-Powered-By-VelaWeb
X-ATG-Version
X-EdgeConnect-MidMile-RTT
X-F-Cache
USPLoggingUUID
X-AOL-HN
X-Page-Cache
X-Dispatcher
X-App-Hosting
X-Art-Request-Id
X-Director
X-Front
Version
X-TransIP-Backend
Last-Published
X-Matrix-Proxy
X-Matrix-Server
X-Daa-Tunnel
X-Microcache-Status
X-Translation
IBM-Web2-Location
X-Drupal-Cache-Tags
Allow
Ohc-File-Size
X-Gamma-Serve
X-Expires-Orig
X-Revision
X-Varnish-GracePeriod
Powered-By-ChinaCache
Content-MD5
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-I
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Hypernode
X-Environment
X-Cache-Operation
X-Vcap-Request-Id
X-LB-Node
MIME-Version
X-Server-ID
X-Platform-Server
RTSS
X-Server-Upstream
X-ARC
Pool
X-Dispatch
Pagespeed
X-Content-Encoded-By
X-Flow-Powered
X-Ua-Device
X-Cache-Debug
Content-Disposition
X-Platform-Cache
Cache-Key
X-Route-Server
X-SSL-Cipher
Page-Completion-Status
X-SSL-Protocol
SSPAppContext
X-Cache-Only-Varnish
X-Lambda-Id
X-Drupal-Cache-Contexts
Node
X-SV-Expires
X-SV-Edge
X-SV-Nginx-Duration
X-SV-FromDBCache
X-Url-Base
X-SV-Cacheable
X-SV-CreatedAt
X-SV-Duration
X-Loopia-Node
X-SV-CacheTags
Wsr-Cache
X-SV-Pid
X-UPSTREAM
X-Abgroup
X-Cache-Lifetime
Section-Io-Id
Lsrequestid
X-ORACLE-DMS-ECID
X-Varnish-Age
Proxy-Connection
X-Varnish-Cacheable
X-Edge-IP
X-NoCache
X-Github-Request-Id
Accept-Encoding
X-Cache-Control-Orig
X-Hiawatha-Cache
X-Grace
ServerID
X-Debug
X-Cache-Server
X-IsCacheURL
X-Id
X-Generated
Content-Encoding-Handler
X-Ttl
X-SERVER-NAME
Fw-Via
Pv
Srv
X-RequestId
X-Nbs
S-Cnection
X-Cache-Type
X-Sapient
X-CJ-Soft
X-SRCache-Key
X-Firenze-Processing-Time
X-Sentry-ID
X-N
X-GeoIP-Country-Code
X-Vhost
X-Cache-Engine
Cneonction
X-PwB-Node
X-Cache-Expires
X-Proxy
X-VTEX-Cache-Status-Janus-Edge
X-ACMCache
X-Ezoic-Cdn
Location
X-Server-Id
X-Magento-Cache-Control
Server-Name
X-Client-IP
X-Litespeed-Cache
Backend
ServerName
X-Dns-Prefetch-Control
X-Geo-Country
SN
X-Amz-Meta-S3cmd-Attrs
X-Middleware-Start
X-NB-Cached-Page
X-Country-Code
Author
X-ServerID
X-Duration
X-Browser
X-Magnolia-Registration
X-TTL
X-Varnish-Url
X-Goog-Stored-Content-Length
FAI-W-FLOW
X-Processing-Time
X-Discourse-Route
X-Cache-Control
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
IM-Version
X-Location
X-Always-Cache
X-Speed-Cache
SRV
X-Varnish-Backend
X-Cache-CFC
Server-Info
X-Speed-Cache-Key
Req-Id
X-Nginx-Cache
If-Modified-Since
X-Adobe-Content
X-Dynatrace-Js-Agent
X-FW
X-Content-Age
X-Orig-Vary
X-Yadis-Location
X-Cookie-Domain
Use-Proxy
X-Adobe-Loc
X-Akamai-Device-Characteristics
X-Akamai-Device-Model
Nodo
X-Akamai-Transformed
AMF-Ver
X-GeoIP-Country-Name
X-Sucuri-ID
PICS-Label
X-Time
NnCoection
X-Worker
X-DealerOn
X-Cache-Level
HCVer
HAVer
Cm-Server
X-Pressidium-NinukisWP-Ver
X-Framework
X-Cache-Namespace
Cached
X-Real-Server
X-Correlation-ID
X-Cache-PageType
X-Cache-Device-Type
X-Cache-Fix
X-Processed-By
X-Drectory-Script
X-LB-Server
X-Webkit-CSP
X-Sucuri-Cache
X-BackendServer
X-Shield-Request-Id
Accept-Charset
X-SRV
X-App-Server
X-Abuse
NetMindSessionID
S
X-SO
Qs-Cache
SVR
X-Litespeed-Cache-Control
X-CF-Passed-Proto
X-Cluster-Node
X-Varnish-Retries
X-Fastly-Request-Id
X-BKSrc
X-High-Performance
X-Frontend
Pf.Web.Request.Id
Xc-Version
X-Forwarded-Proto
Cache
X-Purge-URL
X-Ss-Location
X-Srv
X-Ss-Conf
Thanks
X-Config-Blacklist-Version
Local-Info
MC
Tracecode
X-CDN-Forward
X-Sys-Req-ID
X-Server-IP
X-Amz-Storage-Class
X-Session-ID
X-Origin
X-Runtime-Rack
Pics-Label
X-JG-Page-Cache
X-Balanceador
Content_type
X-Purge-Host
Magicmarker
X-Varnish-IP
Server-Timing
X-DataDome
X-Route-To
X-Last-Modified
X-Traffic
X-RiS-UFDI
X-Content-Security-Policy-Report-Only
SEOMOZ
X-Rocket-Nginx-Serving-Static
MJ12bot
HitType
X-PF-Uncompressing
A-Powered-By
X-Disney-Akamai-Rule
SiteSpeed
Nitro-Cache
X-Content-Type-Option
X-LP
SBGI-9
SBGI-Device
X-Cf-Powered-By
X-NginX-Cache
X-ClientSide-Caching
SBGI-RenderTime
X-FireWall-Port
SBGI-RealPath
X-FastCGI-Cache
X-Empowered-By
SBGI-10
SBGI-5
W
CacheControlHeader
X-WR-Flags
SBGI-1
SBGI-7
X-Varnish-Debug-TTL
EagleEye-TraceId
X-Varnish-Debug-Age
X-FTR-Request-ID
X-SDS
X-App-Status
X-Sorting-Hat-Expire-Cache
X-Provisioner-Version
X-AF-Userserver
X-Cache-TTL-Remaining
X-HTML-Minification-Powered-By
P-ID
ServerSignature
ServerTokens
X-Domain-Checked
Keywords
Max-Age
X-Hit-Cache
X-Pagename
X-VARITI-CCR
X-ID
From-Origin
Eomportal-Instance
WN
Frame-Options
X-WN-ClientGroup
WWW-Authenticate
X-Cache-Handler
X-Yottaa-Optimizations
X-Transaction
X-OpenCart-Lightning
AC-ELC
Cache-Tag
X-Twitter-Response-Tags
Contao-Page-Layout
X-Yottaa-Metrics
X-Mobilized-By
X-Varnish-ID
X-Jphone-Copyright
Content-Transfer-Encoding
X-Generated-Time
X-Runtime-Memory
X-Connection-Hash
X-Hstore
X-Redman-Backend
X-HW
X-Hrouter
Web-App-Origin-Name
X-ORACLE-DMS-RID
Dis-Env
X-Avg-Cookie-Expires
VANITY-HOST
X-Rq
Description
X-Debug-Token
X-Cache-Doesi
X-Directory-Script
Ufe-Result
X-Redman-Final-Url
Adm-Server
X-Client-Vid
X-VNode
X-Client-Image-Vid
X-Clara-ASAP
X-ASAP-Cache
X-Akamai-Edgescape
X-AVG-Country-Code
X-Amz-Meta-Cb-Modifiedtime
X-Distributor
Cache-Tags
X-AEM
X-Varnish-Hits
X-EPiphany-Vid
X-Resty-Request-Id
X-Fedora-School-Id
X-Varnish-Ttl
SERVER-ID
X-Webstats-RespID
X-Unbounce-Variant
X-Unbounce-VisitorID
X-Garden-Version
X-Unbounce-PageId
X-LW-Web-Server
X-Esi
Proxy-Agent
X-Server-Instance
X-Analytics
X-WPL-DATA
NODE
X-ARRServer
X-Unique-ID
Backend-Timing
X-SmugMug-Hiring
Play-Detected-UserAgent
X-PRAM
Play-Detected-Device
X-TTFB-L
X-Force
X-SmugMug-Values
X-TTFB
Smug-CDN
X-Env
Cteonnt-Length
X-MCB-Server
X-Key
X-Varnish-Hostname
X-GSL-Server
X-HP-Trace-ID
X-HP-Trace-Project
X-Mobile-URL
X-ServerIndex
X-Webkit-Csp
X-Atraveo-From-Varnish-Cache
Dispatcher
Noq
X-Wikidot-Backend
X-GeoIP
X-Cache-Keep
Nginx-Cache
Paypal-Debug-Id
X-Remote-Addr
X-Wikidot-Static-Cache
X-GoCache-CacheStatus
Hname
X-HOSTNAME
Ramp
X-CB-Server
X-Desc
BALANCEDTO
X-Page
X-WebKit-CSP-Report-Only
Ram
X-Atraveo-Param-Rm
X-Atraveo-Expires
X-Atraveo-Set-Cookie
X-Atraveo-TTL
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
X-Atraveo-ETag
X-CacheResult
X-Atraveo-Cache-Control
Front
X-MAT-GEO
X-Source-ID
X-CAPServer
X-Runtime-Affili
X-CACHE-TTL
X-Dev
X-A
X-App-Runtime
X-Cms-Mode
Worker
X-Culture
X-Backend-Status
Beyond-Iis
X-SH-Cache-Status
Machine
NLCacheNote
Cmsid
X-Nginx-Host
Cmstype
Og
Resin-Trace
TC-S-Cache-M
X-App
TC-S-Cache
X-NginX-Server
X-Webcelerate
COMMERCE-SERVER-SOFTWARE
X-Varnish-Server
X-OPNET-Transaction-Trace
X-Trace-Id
X-TB-M
TC-Cache-U
X-Rewrite
X-Plat
X-E
X-Symfony-Cache
X-Compressed-By
TC-Cache-IC
SHInfo
X-Frames-Options
X-Real-IP
Disablevcache
X-Resolver-IP
TC-Cache
X-Smartcache-Keys
X-WP
X-CDN-RULE
X-HydroSheep
X-Smartcache-Timeout
Strikingly-Cached
Access-Control-Allow-Header
Strikingly-Cached-Version
From
Strikingly-Cache-Region
X-Detected-Device
X-Cache-Node
XDomainRequestAllowed
X-CDN-COMPRESS
AMP-Access-Control-Allow-Source-Origin
BackendServer
X-Avvio-Cms-Cacheload
X-Proto
MS-CV
Custom-Header
X-V
X-KoobooCMS-Version
X-Airee-Node
X-Varnish-Ip
Lb
X-AutoRu-App-Id
X-Dynamic-Cache
X-VC-Enabled
Bios
X-Autoru-LB
X-Fstrz
Web
Device
Id
X-IIJ-Cache
X-Stage
X-VC-TTL
MW-Webserver
X-Autoru-Host
Fastly-Backend-Name
X-Reflector-Cache
X-Pj-Cache-Status
X-Batcache-Reason
X-Batcache
X-Captured
X-Cache-On
X-ENV
X-Confluence-Request-Time
X-Forwarded-Host
X-Machine-Name
X-WR-MODIFICATION
TP-L2-Cache
TP-Cache
Identity
X-ETag
FRONT-END-SECUREBROWSER
SG
Yoncu-Errno
Content-Server
X-RDP
X-HashTwo
X-Render-Time
ViewMode
X-Viator-Tapersistentcookie
X-Bip
X-SDE-Name
Hamster
Ibf5scheme
N365rili
X-Dw-Trace-Id
X-Hosting-Env
OriginServer
X-Aramark-SID
X-Apm-Telemetry-Syncmark
X-DTC
X-Akamai-3PM-SW-Version
X-B2f-Not-Route
X-Cdn-Forward
X-SmartBan-Host
X-SmartBan-URL
X-DN-Cache-Control
X-Info
X-Proxy-Cache-Key
Proxy-Cache
X-Req-Head-Response
CLMOB
Myheader
X-Map-Context
X-FPC
X-Adnet
Il-Cl
Home
Ews
Service-Worker-Allowed
X-Origin-Server
X-Gyrobase-Publication
PagesDisplayed
Arrnode
ClientIP
F5-IpCliente
X-Session-Reinit
X-Server-Generated
X-Data-Request
X-Reflector
X-Refresh
Traffic-Origin
Gzip
Hostname
ScoreTracker
X-Highwire-RequestId
X-Highwire-SessionId
X-MSEdge-Ref
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
IISExport
WebServer
X-Varnish-Cache-Local
X-EC2-Instance-Id
X-Amcomm-Site
X-Magento-Action
SB-Site-Device
SB-Cache-Life
X-Environment-Context
X-L-Path
X-Machine
X-CacheID
X-Ser
CommunityServer
SB-Cache-Remaining
X-Sc-Cache
X-Grid-Server
X-WA-Info
X-Goog-Meta-Replace
Serverid
X-W3TC-Minify
X-Rack-CORS
X-Unique-Id
RN-Server
X-Rack-Cors
Cleartype
AsisCache
Xc
X-RAMCache
X-Header
X-HP-CAM-COLOR
X-RealServer
Url
Server-Id
X-Cocoon-Version
X-UA
X-PM-ID
NtCoent-Length
X-Protected-By
X-Goog-Meta-Policy
X-HostName
Warning
X-ProcessESI
User-Agent
X-Tag-Playlist
Ctx
SB-Site-IE-VERSION
Referer
X-Flex-Evstart
X-Application
X-Your-GrandPa-Would-Wait
X-Backend-Host
X-Magento-Lifetime
Hummingbird-Cache
X-Redirector
Edgecast
X-Flex-Tags
X-PHP-Response-Code
X-Litespeed-Tag
X-Beatles
Aoestatic
Hosted-By
X-RemovedCookies
Provided-Host
X-Streams-Distribution
X-Author
X-Flex-Tag
X-Flex-Lastmod
X-Flex-Lang
X-Cache-Via
X-DSMX-Render-MS
X-Does-He-Have-Time
X-DSMX-Rewrite-MS
X-Secret
X-Flex-Evend
ServerIP
Session-From
X-Upstream-Status
X-Cache-Time
X-Beatles-Hits
X-Cache-TTL-Current
X-Cache-TTL-Age
X-Src-Webcache
X-Upstream-Backend
X-TTL-Age
X-LBPoolMember
X-Zendesk-Origin-Server
X-Varnish-Id
X-Would-Your-GrandPa-Wait
X-Amz-Meta-S3b-Last-Modified
X-Ghost-Cache-Status
X-Old-Content-Length
X-Bcwwwid
X-Nginx
X-PBS-Fwsrvname
X-PBS-Appsvrname
X-PBS-Appsvrip
X-Cluster
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-VC-Cache
X-Instance-Id
X-Depends
DNNOutputCache
NS-VaryByCustom-Key
X-JSESSIONID
X-Gateway-Cache-Status
VServer
X-Cache-FS-Status
X-Response
X-ASAP-Age
X-CRA-DC
X-Powered-By-Home.Pl
X-Flex-Community
X-Origin-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Catalyst
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-NewsFlow-Sitename
X-Cache-Set
XX
X-We-Are-Hiring
X-IP
Accept-Language
X-Cache-Id
X-Middleton-PageSpeed
X-M
X-Goog-Meta-Goog-Reserved-File-Mtime
Access-Control-Request-Headers
PServer
X-Cache-Me-Harder
X-Zendesk-User-Id
SS
X-Timestamp
Viewport
Provider
X-Resource
X-SV
X-HAProxy
X-Server-Addr
X-Dynatrace
Mime-Version
X-Lw-Cache
X-HS-Status
X-Varnish-Action
NZSpeedy
VC-NoCache
X-ACCELERATE
X-CSRF-Token
X-ReqId
X-Pagely-Cache
X-DB-Content-Length
X-FORWARDED-PROTO
X-Serv
X-Netrix-ID
X-Served-Server
Server-Ip
X-4ormat-Cacheable
X-DEBUG
X-Pixelsilk-Server
X-Max-Age
X-Turpentine-Esi
X-VC-Hash
Ec-CorrId
X-Full-Url
Ec-Machine
Ttl
X-VC-Debug
X-SCM-Server-Number
X-Amz-Meta-Content-Md5
X-Search-Id
X-VC-Cacheable
X-Pixelsilk-Version
Control-Cache
X-Az
X-AppVersion
X-Nginx-Request-Time
X-Instart-Cache-Id
X-Debug-Message
X-Cache-Detail
X-Activity-Id
Uuri
Fastly-Restarts
PB-PID
PB-RID
Quri
Tesla.Performance
X-DynamicCache
X-FastCGI-Cache-Status
RequestId
X-Say-TTL
X-Amz-Id-1
X-CH-Device
X-Say-Cacheable
X-Hosting
Note
X-SayCDN-TTL
Session-Id
WP-AdvCache-MemCached
X-HA
X-Mobile-Rewrite
X-UT-Cache
Generate-Time
X-Server-Ip
X-Router
X-Route
X-Domino-CacheValidationWithETagReason
!~Request-OOB-Work
AR-CACHE
AR-ATIME
X-Header-Treatment
X-Domino-CacheValidationWithETagResult
X-DevSrv-CMS
X-Custom-Header
X-Enabled1
X-Enabled2
X-Enabled3
AR-PoweredBy
AR-SID
X-Via-NSCOPI
X-Deity
X-Made-On
X-MidCOM-Meta-Cache
X-Served
X-Cname-TryFiles
Upgrade-Insecure-Requests
Microcache
EQ-Cache
X-FIRSTBase
RSB-LINK
Tempo
X-CCM
Access-Control-Allow-Method
X-Cache-Varnish
X-AppServer-Cache-Rule
X-Config-By
X-D-Time
X-Generation-Time
Progma
Kanooh-Host
X-DDM-SERVER-UPDATED
X-Hash
X-SuperCache
X-Uncacheable
X-Node-Name
X-S-Misc
X-AISO-Cacheable
X-AISO-Server
X-Cache-V
X-Node-ID
X-AISO-Cache
StatusCode
X-Time-Microsecs
X-XHR-Current-Location
Cache-Status
EN-User
X-DDM-SERVER
X-7d-Trace-Id
X-MainProfileCategory
X-LOCATION
X-MainProfileID
X-MainProfileName
X-MainProfileURL
X-Cjtype
ReqUrl
AccessControlAllowOrigin
X-BeResp-Ttl
XDisk
DrivedBy
X-Not-Cacheable
INFO
X-REDIRECTSERVER
X-Skip-Cache
X-Upgrade-Enabled
X-7d-Instance-Id
X-Geo-IP
X-Container
X-Agent
X-Box
X-Cache-Extended
X-Client-Ip
Debug-Status
Services
X-Blog
Www.Aujourdhui.Com
X-Distil-CS
X-RequesterIP
X-Nginx-Request-Processing-Time
X-Enhanced-By
X-Gannett-Site-Version
Expiries
X-SilverStripe-Cache
X-Status
CDCHOST
X-Instance
ServerNode
X-AMAZEEIO
X-UnsetCookies
MwpReleaseVersion
Cacheid
X-Test-Debug
X-XHTML-Minification-Powered-By
X-Backend-Name
MachineName
X-Artvisual-Server
X-Rewritten-By
X-Cache-Original-TTL
X-ManagedFusion-Rewriter-Version
X-DS1D
Server-ID
X-Pubstack
X-NodeID
X-Ssl-Cipher
X-Cache-Ttl
Dynatrace
X-Oneagent-Js-Injection
X-Lb
X-Ruxit-Js-Agent
X-Oracle-DMS-ECID
X-ESI
CpuTime
X-Built-By
X-Cache-Served
GranicusServer
X-Debug-Serve
X-PBY
X-Server-App
X-Request-Processing-Time
Language
X-AWS
X-Cache-Date
Powered-By-VeryCDN
X-Request-Received
X-Archive-Guessed-Charset
X-Instance-Name
X-Cache-Warmer
X-LB-Backend
X-LB-Frontend
X-Meta-MSSmartTagsPreventParsing
X-Meta-Imagetoolbar
WP-FROM-CACHE
Realaction
CS-SERVER
Actioncode
Httpd-Identifier
MSSmartTagsPreventParsing
MSThemeCompatible
X-Meta-MSThemeCompatible
X-Restarts
X-Archive-Orig-Connection
Memento-Datetime
X-Archive-Orig-Content-Length
X-Archive-Orig-Date
X-Archive-Orig-ETag
X-WHO
TTL
X-Wm-1
X-Server-Vrn
X-Wm-VIP
Actual-Object-TTL
CD4
X-Archive-Orig-Server
MageStack-Cache-Hits
X-Mw-Workerstats
X-M-V
X-Nocache
X-Pageid
X-Pool-Info
X-M-T
X-M-P
X-Beresp-Ttl
X-B
X-Cachable
X-Cacheable-TTL
X-I-V
X-Q-S
X-S-C
X-UPSTREAM-Address
X-OCTOPOD
X-WebNode
X-Compress-Hint
X-Server-Instance-Name
X-MyName
X-Middleton-Pagespeed
X-S-V
X-T
X-Transaction-Name
X-Healthy
OracleCommerceCloud-Version
OracleCommerceCloud-Sandiego
MageStack-Cache-Status
MageStack-Cache-Lifetime
MageStack-Cacheable
MageStack-Config
MageStack-Debug
X-Varnish-Cached-TTL
MageStack-Cache
X-Varnish-Esi-Access
X-Varnish-Currency
X-Varnish-Esi-Method
X-Varnish-Store
MageStack-Area
MageStack-Loadbalancer
MageStack-Magento-Version
X-Serverid
X-ProBase-Server
AMFplus-Ver
CommercePlatform-Version
Key
X-Origin-Upstream-Status
X-NewCloud-V-Cache
MageStack-PageSpeed
MageStack-Tag
MageStack-Web-Node
X-Backend-TTL
X-Fastly-Backend-Reqs
Cookie
X-Clx-Request
X-Who
X-ZSITES-DNS
Accept-CH
SINA-TS
X-Varnish-Grace
X-MSU-SOURCE
X-VG-WebCache
X-PROCESSED-BY
X-SID
X-SE-Debug
SINA-LB
Requested-Host
X-This-Proto
X-Accel-Cache-Control
X-Svr
X-Czt
X-BC
Copyright
Cache-Ctrol
Aurora-Node
X-Ants-Host
X-Ants-Machine-Id
Apple-Itunes-App
X-ACLR-Version
Response-Time
X-Varnish-URL
Head
X-EBAY-C-REQUEST-ID
Countrycode
RlogId
Page-Template
X-Powered-Developer
X-Nginx-Page-Cache
X-CO-Host
X-Cache-Bypass
CmsfirstPublishTimestamp
X-FG-RequestId
X-ELB
WSCLoggingUUID
X-Country
UrlWatchModule-Time
X-PG
X-Server-FQDN
X-VLoc
X-Varnish-Instance
X-Time-Zone
X-ServiceProvider
X-9XB-Server
X-Layout
X-Service-Id
X-Proxy-Id
DB-Nickname
IES-Server
Load-Balancer
X-Distributed-By
Webserver
Content-Cache
DbServerName
FindLaw
Rewriter
Request-Time
X-B3-Spanid
X-Script
X-ServerAddr
X-Sn-Servicetimems
X-UPServer
X-Nitro-Cache
X-MCF-ID
X-B3-Traceid
X-Built-With
X-CPU-Time
X-Fpc
X-Sid
X-Rocket-Nginx-Reason
OutputRewritten
Fw-Cache-Status
X-Cache-2
X-IP-Address
X-COUNTRY-CODE
Yola-ID
Y-Trace
X-Memcached
X-Server-Ident
X-Title
X-ZORequestID
X-VCS-Cacheable
X-VCS-Ttl
X-Config-Version
X-DeliveryServer
X-Dynamic
X-Rocket-Nginx-File
X-Brought-To-You-By
VAR-Cache
X-WAF-Proxy
X-Ar-Debug
ATI-Server-Id
E-TAG
X-Varnish-Cached