Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
CF-RAY
Age
X-Cache
P3P
Expect-CT
Content-Language
X-AspNet-Version
X-Pingback
Via
X-UA-Compatible
Upgrade
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Varnish
Referrer-Policy
X-Adblock-Key
X-Request-Id
X-Check
X-Generator
X-Xss-Protection
X-Language
X-Template
X-Buckets
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-Drupal-Cache
Alt-Svc
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Ac
X-Hacker
X-Cache-Hits
Host-Header
X-AspNetMvc-Version
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-FeatureSet
X-ShardId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-ShopId
X-Dc
X-Alternate-Cache-Key
X-Via
X-Served-By
X-Powered-By-Plesk
X-Runtime
X-Contextid
X-PC-Hit
X-PC-Key
X-PC-AppVer
X-ServedBy
X-UA-Device
X-Amz-Cf-Id
MS-Author-Via
X-PC-Host
X-PC-Date
Content-Location
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-IPLB-Instance
X-Powered-CMS
X-Timer
X-Ua-Compatible
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Rid
X-Wix-Request-Id
X-Seen-By
Status
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
CF-Cache-Status
X-Tumblr-Pixel-1
X-FRAME-OPTIONS
Cartoon
X-Iinfo
X-Tumblr-Pixel-2
X-Backend
Access-Control-Allow-Credentials
X-Shopify-Stage
X-Cache-Status
X-CST
X-Host
X-WPE-Loopback-Upstream-Addr
Content-Encoding
Powered-By
X-Endurance-Cache-Level
X-Cache-Hit
X-Port
X-Mod-Pagespeed
X-Cache-Enabled
X-Request-ID
X-CDN
X-Tumblr-Pixel-3
X-Logged-In
X-Server-Powered-By
X-Server
X-Drupal-Dynamic-Cache
X-DIS-Request-ID
Keep-Alive
X-Nginx-Cache-Status
X-Robots-Tag
X-Accel-Version
X-Proxy-Cache
X-Turbo-Charged-By
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-LiteSpeed-Cache
P3p
X-Page-Speed
X-Content-Powered-By
X-Content-Digest
Content-Security-Policy-Report-Only
X-AH-Environment
Request-Context
X-GitHub-Request-Id
X-Rack-Cache
X-FW-Hash
X-FW-Server
X-Tumblr-Pixel-4
X-FW-Static
X-FW-Type
X-FW-Serve
X-Pad
X-Varnish-Cache
X-Hits
Access-Control-Expose-Headers
X-Webcom-Cache-Status
X-BC-Stapler
Edge-Control
X-XRDS-Location
SPRequestGuid
X-MS-InvokeApp
X-Trace
X-SharePointHealthScore
X-Node
X-Newrelic-App-Data
X-Request-Country
MicrosoftSharePointTeamServices
WP-Super-Cache
Cf-Railgun
Timing-Allow-Origin
Edge-Cache-Tag
X-HS-Cache-Config
X-HS-Content-Id
X-Amz-Request-Id
X-Amz-Id-2
X-CF-Powered-By
X-Content-Security-Policy
Charset
X-PHP-Backend
X-FullPageCaching
X-INKT-SITE
X-INKT-URI
X-Cache-Lookup
Request-Id
Access-Control-Max-Age
X-Fastly-Request-ID
X-HS-Combine-CSS
X-Cnection
SPIisLatency
X-Backend-Server
SPRequestDuration
X-Edge-Cache
X-Edge-Cache-Key
X-Died
Ali-Swift-Global-Savetime
X-Swift-CacheTime
X-Swift-SaveTime
Allow
EagleId
MicrosoftOfficeWebServer
X-CDN-Pop
X-CDN-Pop-IP
Composed-By
Rating
Grace
X-Tumblr-Pixel-5
X-Server-Name
X-Safe-Firewall
X-SS-Conf
X-SS-Location
X-Device
Served-By
X-SERVER
X-NF-Request-ID
X-Tumblr-Content-Rating
Liferay-Portal
X-DDC-Arch-Trace
X-HeyJason
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-Dw-Request-Base-Id
X-Spip-Cache
X-VCache
Front-End-Https
X-Hyper-Cache
X-LiteSpeed-Cache-Control
P-WS
P-LB
X-Cloud-Trace-Context
X-RateLimit-Limit
X-RateLimit-Remaining
X-OneAgent-JS-Injection
Surrogate-Control
X-Original-Date
X-Cluster-Node
X-Loop
X-TNCMS
X-RateLimit-Reset
X-Sol
Display
X-Middleton-Display
X-Clacks-Overhead
X-Kinsta-Cache
X-FB-Debug
X-Jimdo-Wid
X-Jimdo-Instance
X-Webserver
X-Middleton-Response
Response
X-Acc-Exp
X-Vtex-Processado-Em
X-Firenze-Processing-Times
X-PhApp
Content-Style-Type
X-Debug-Info
X-StackifyID
Content-Script-Type
Public-Key-Pins
X-Servedby
X-Tumblr-Pixel-6
X-Ruxit-JS-Agent
Feature-Policy
X-Age
X-DNS-Prefetch-Control
X-LW-Cache
X-Magento-Tags
X-XN-Trace-Token
X-Frame-Option
X-XN-XNHTML
X-WebKit-CSP
X-Amz-Version-Id
Refresh
X-Cached
X-DynaTrace-JS-Agent
Fpc-Cache-Id
Xkey
X-User-Agent
X-Goog-Hash
X-HOST
X-Zen-Fury
X-N-OperationId
PageSpeed
X-Px
X-Cache-Config
X-Version
Retry-After
X-ARC
X-Hostname
X-Edge-Location
X-Generated-By
X-Handled-By
X-Topify-Platform
X-Upstream
X-EdgeConnect-Origin-MEX-Latency
X-FORWARDED-FOR
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Microcache
X-Goog-Generation
X-Source
X-Url
Rt-Fastcgi-Cache
Fastcgi-Cache
X-EdgeConnect-MidMile-RTT
WPX
TCN
X-Whom
Access-Control-Request-Method
Powered
X-Magento-Cache-Debug
X-MiniProfiler-Ids
X-Outils-CS
X-B-Cache
X-Loopia-Node
Last-Published
X-Dns-Prefetch-Control
X-RESOURCE
X-Cached-By
X-URLSCHEME
ServedBy
X-VTEX-Cache-Status-Janus-ApiCache
No
X-Powered-By-VTEX-Janus-ApiCache
X-Vtex-Processed-At
X-ET-API-ROOT
X-ET-API-VERSION
X-ET-API-ORIGIN
X-CMS-Version
X-Vtex-Remote-Cache
X-VTEX-Janus-Router-Backend-App
X-CacheServer
X-Accel-Expires
X-Request-Time
X-Engine
X-Varnish-HitMiss
X-Varnish-Count
X-Platform-Server
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Varnish-Cache-Hits
Product
X-NewRelic-App-Data
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-AspNetWebPages-Version
Pagespeed
X-DynaTrace
X-From
Imagetoolbar
X-Application-Context
X-URL
X-Content-Options
X-ApacheServer
X-PERF
X-Developer
Public-Key-Pins-Report-Only
X-Actual-URL
X-LBLID
Fhost
X-Cache-Info
Warning
Dmn
X-Varnish-Host
X-Returned-From-DLL
X-Original-Request
X-Returned-From
X-Passed-To
X-Passed-To-DLL
X-Fastcgi-Cache
X-S
Host
X-Location-Id
X-Ezoic-Cdn
X-Varnish-Beresp-Grace
X-Shop-Id
X-Defender
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Stale
X-Cache-Key
X-Microcachable
X-Signature
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Magento-Cache-Control
X-Returned-From-PostProcessResponse
X-F-Cache
X-Returned-From-BeforeDispatch
Cache-Provider
X-Acquia-Application-UUID
X-NWS-LOG-UUID
X-Acquia-Application-Trace
Cache-Key
X-HS-Content-Campaign-Id
Alternate-Protocol
X-SSLProxy
X-Platform
X-SSLUpstream
X-Cache-Rule
X-Response-Time
X-Device-Type
Generator
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
Origin
Arr-Disable-Session-Affinity
X-Umbraco-Version
X-Sapient
X-Cache-Age
X-Powered-By-360WZB
Version
X-Via-JSL
X-SVR-IIS
X-Svr-Proxy
X-Hosted-By
X-Forwarded-For
X-Translation
X-Microcache-Status
X-Msg-2-Log
X-Cache-Tags
Content-Hash
X-Platform-Cache
X-Environment
X-Rnd
X-Dispatcher
X-Varnish-TTL
X-Akam-SW-Version
X-Guploader-Uploadid
X-Micro-Cache
X-Instart-Request-ID
X-I-Sp
X-BS
DynaTrace
X-Track
X-SO
X-CSRF-Protection
Content-Disposition
X-GUploader-UploadID
X-DealerOn
Surrogate-Key
USPLoggingUUID
X-Dealeron-Backend
S-Cnection
X-ORACLE-DMS-ECID
X-Dealeron-Original-Url
X-Supported-By
X-App-Status
X-Cache-Namespace
X-SSL-Cipher
WZWS-RAY
X-Lambda-Id
SSPAppContext
X-Server-Upstream
X-Server-ID
X-Gamma-Serve
X-Abgroup
MIME-Version
X-SSL-Protocol
X-Powered-By-VTEX-Janus-Edge
X-Drupal-Cache-Tags
X-Correlation-ID
X-Expires-Orig
X-Director
X-Correlation-Id
X-Duration
X-Cache-TTL
RTSS
X-Powered-By-VelaWeb
X-NetCat-Version
X-Client-IP
X-I
X-VARITI-CCR
X-Cache-Control-Orig
X-TransIP-Balancer
Wsr-Cache
X-Sucuri-ID
X-Debug
FAI-W-FLOW
X-Art-Request-Id
Cache
X-UD-Method
X-Cache-Server
X-Generated
X-Varnish-ObjectSource
X-App-Hosting
X-Matrix-Server
X-Varnish-Seen-By
X-Varnish-RemainingLife
X-Matrix-Proxy
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-Vcap-Request-Id
X-Front
X-TransIP-Backend
X-Edge-IP
X-Hypernode
SN
X-ATG-Version
Node
Pool
X-Sucuri-Cache
X-Helper-Autoassign-All
X-Grace
X-Daa-Tunnel
X-Route-Server
X-Geo-Country
Src-Update
Powered-By-ChinaCache
Update-Time
X-Now-Id
Req-Id
X-Github-Request-Id
X-Cache-Lifetime
X-Page-Cache
X-Storage
X-Amz-Meta-S3cmd-Attrs
Edge-Control-Message
X-Vhost
X-Url-Base
X-Server-Id
X-Env
X-SmugMug-Values
X-ServerName
Cneonction
X-SmugMug-Hiring
X-TTFB
X-Content-Encoded-By
X-Forwarded-Proto
CF-Worker-Script
X-Rocket-Nginx-Bypass
Smug-CDN
X-TTFB-L
ServerID
X-Cache-Debug
X-SV-Expires
X-SV-Duration
X-SV-CreatedAt
X-SV-Edge
X-Revision
X-Last-Modified
X-Rocket-Nginx-Serving-Static
Service-Worker-Allowed
X-UPSTREAM
X-Varnish-Cacheable
X-Drupal-Cache-Contexts
X-SV-CacheTags
Content-Encoding-Handler
X-SV-Nginx-Duration
X-Esi
X-SV-Pid
X-SV-Cacheable
X-Varnish-Url
X-SV-FromDBCache
X-Pressidium-NinukisWP-Ver
X-Cache-Level
X-Recruiting
Cache-Tags
Author
X-SRV
X-NoCache
X-Cache-Handler
X-ORACLE-DMS-RID
X-Flow-Powered
Contao-Page-Layout
X-Varnish-Age
X-Locale
X-LB-Server
X-CJ-Soft
Akamai-IP
X-Country-Code
X-Firenze-Processing-Time
CF-Worker-Version
Accept-Encoding
X-TTL
X-FTR-Request-ID
X-Cache-Engine
X-PwB-Node
Lsrequestid
X-Trace-Id
If-Modified-Since
X-N
X-Cache-Control
X-Cache-Type
X-IsCacheURL
X-Cache-Operation
X-Middleware-Start
X-Discourse-Route
X-Ttl
Section-Io-Id
Strikingly-Cached-Version
X-SDS
Strikingly-Cache-Region
X-Magnolia-Registration
X-NA-CachePolicy
X-GeoIP-Country-Code
SiteSpeed
X-Content-Type-Option
Strikingly-Cached
X-Akamai-Device-Characteristics
X-Akamai-Device-Model
X-FIRSTBase
Server-Name
Srv
W
X-Unbounce-PageId
X-Server-Instance
X-Dispatch
X-Unbounce-VisitorID
X-Unbounce-Variant
Server-Timing
X-Rq
AMF-Ver
X-Time
X-NginX-Cache
X-LB
Https
X-Speed-Cache
Proxy-Connection
X-Speed-Cache-Key
Page-Completion-Status
X-Hiawatha-Cache
X-TransIP-Reserved
X-Dynamic-Cache
Use-Proxy
X-GeoIP-Country-Name
X-Varnish-Retries
Content-MD5
Custom-Header
X-Varnish-IP
X-Cache-Expires
X-High-Performance
Nodo
Pv
Dtk-Cache-Check-0
X-Now-Cache
X-CF-Passed-Proto
X-Fastly-Request-Id
X-Cache-Only-Varnish
PICS-Label
X-Nginx-Cache
X-Empowered-By
SEOMOZ
Backend
From-Origin
Accept-Charset
X-Service-Id
X-Varnish-Backend
X-Storage-Cache-Expires
S
X-Storage-Cache
MJ12bot
X-Cache-Device-Type
X-Storage-Cache-Date
X-BKSrc
X-FW
X-PF-Uncompressing
FindLaw
NnCoection
Location
Qs-Cache
X-Twitter-Response-Tags
X-Transaction
X-Srv
X-Connection-Hash
X-TB-M
X-Amz-Rid
X-SRCache-Key
X-Litespeed-Cache-Control
X-Frontend
X-Processing-Time
MC
Prama
X-Real-Server
X-Analytics
IBM-Web2-Location
X-CacheFROM
Local-Info
X-Content-Age
X-Config-Blacklist-Version
X-Wikidot-Backend
X-Content-Security-Policy-Report-Only
X-Wikidot-Static-Cache
X-Cache-Fix
X-Cache-PageType
X-Sedo-Request-Id
X-ServerID
X-Cache-Miss-From
ServerName
X-Cookie-Domain
X-Worker
X-Browser
Ohc-File-Size
X-WR-MODIFICATION
X-HW
X-Amz-Storage-Class
Backend-Timing
X-Disney-Akamai-Rule
Edit
X-Key
Xc-Version
X-Shard
X-Adobe-Content
X-ACMCache
X-Adobe-Loc
X-BackendServer
X-A
X-Orig-Vary
X-ID
X-WR-Flags
Content-Transfer-Encoding
X-Webkit-CSP
Tracecode
X-Server-IP
X-Symfony-Cache
X-ARRServer
X-4ormat-Cacheable
Swift-Performance
X-SP-Farm
X-SP-UniqueName
Pics-Label
X-Nitro-Cache
X-Amz-Meta-Content-Md5
X-Ruxit-Js-Agent
X-WEBSERVER
X-RequestId
X-RealServer
X-App-Server
HCVer
HAVer
CacheControlHeader
A-Powered-By
Front
X-LB-Node
X-CB-Server
Cached
Accept-CH
X-Varnish-Server
X-Cache-TTL-Remaining
X-Cache-2
X-Nbs
Drupal-Pagecache-Memcache
X-Distributor
NetMindSessionID
Adm-Server
RequestId
X-Forwarded-Host
X-Hstore
Pf.Web.Request.Id
X-Origin
X-Processed-By
Server-Info
Cm-Server
Referer
X-Stage
Frame-Options
X-AEM
X-Drectory-Script
X-Akamai-Edgescape
X-Hrouter
X-Redman-Final-Url
X-Redman-Backend
X-AVG-Country-Code
X-Avg-Cookie-Expires
X-Remote-Addr
X-FireWall-Port
X-Client-Vid
X-EPiphany-Vid
X-LP
X-Client-Image-Vid
X-Akamai-Transformed
SHInfo
X-CLOUD-TRACE-CONTEXT
X-LW-Web-Server
X-Hit-Cache
Url
X-Cache-Ttl
X-HydroSheep
Content_type
X-Pagename
Lookup-Cache-Hit
X-Path-Route
X-ClientSide-Caching
X-Yadis-Location
X-PRAM
X-Force
X-Webstats-RespID
Report-To
X-Request-Uri
Cteonnt-Length
X-Cache-Dispatchercachecontrol
SRV
X-VC-Enabled
X-CDN-Forward
Request-Country
X-Cache-Dispatcherpragma
Proxy-Agent
IISExport
Environment
Request-EU
X-Span
X-Role
SVR
X-Varnish-Hostname
X-RiS-PX
X-Source-ID
X-E
X-Yottaa-Metrics
X-NginX-Server
X-Yottaa-Optimizations
X-CAPServer
X-Appmachine-Environment
X-HTML-Minification-Powered-By
X-VCS-Ttl
X-VCS-Cacheable
X-Generated-Timestamp
X-Distil-CS
X-UnsetCookies
X-Varnish-Ttl
X-JG-Page-Cache
X-Runtime-Memory
X-Framework
Hummingbird-Cache
CDN-Cache
IM-Version
X-Via-NSCOPI
X-Oneagent-Js-Injection
Accept-Language
Access-Control-Allow-Method
X-Cacheable-TTL
X-GeoIP
X-Plat
X-M-Reqid
CDN-RequestId
CDN-Uid
CDN-PullZone
CDN-CachedAt
X-Varnish-Hits
X-ZSITES-DNS
X-Proxy
Beyond-Iis
X-Proxy-Cache-Key
X-App-Runtime
X-Qnm-Cache
X-Proxy-Backend
X-M-Log
X-Runtime-Affili
Eomportal-Instance
X-SDE-Name
Ramp
X-Akamai-ERRuleID
AsisCache
Ram
Noq
NODE
X-CACHE-TTL
X-Cache-CFC
X-Envoy-Upstream-Service-Time
RN-Server
X-Unique-Id
Nginx-Cache
Copyright
X-Sys-Req-ID
X-Balanceador
X-Hosting-Env
ScoreTracker
X-SERVER-ID
X-Akamai-ERPolicy
X-Pantheon-Environment
X-Pantheon-Az
X-Pantheon-Phpreq
X-Vcache
X-FastCGI-Cache
X-Real-IP
X-Backend-Status
X-Detected-Device
X-Atraveo-Zone
X-HeBS-Cache-Status
X-Atraveo-Varnish-Server-Id
X-Atraveo-TTL
X-Atraveo-Set-Cookie
Surrogate-Key-Raw
X-Atraveo-Param-Rm
X-Shield-Request-Id
Pramga
X-Atraveo-Cache-Control
Identity
X-Cache-Doesi
X-Unique-ID
X-Resource
X-AOL-HN
X-Atraveo-ETag
WWW-Authenticate
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
Disablevcache
Server-ID
X-Consent-Required
X-Pantheon-Site
X-NginX-Upstream
X-Nginx-Host
X-Debug-Token
Machine
X-Soro
X-FPC
X-Via-S
X-Provisioner-Version
X-Domain-Checked
X-Garden-Version
Access-Control-Request-Headers
X-RiS-UFDI
X-Adnet
X-Compress-Hint
X-Desc
X-MAT-GEO
Firespring-Website-Id
X-Actindo-Thread-Id
X-Location
X-WebNode
Max-Age
Paypal-Debug-Id
X-Amzn-Trace-Id
X-Amzn-RequestId
X-Country
X-GSL-Server
X-JSESSIONID
X-NWS-UUID-VERIFY
X-Confluence-Request-Time
CS-SERVER
AETN-State-Code
AKA-DEVICE
WP-FROM-CACHE
X-Secret
X-Session-Reinit
Access-Control
X-Amz-Apigw-Id
X-Varnish-Debug-TTL
YF-ID
Nitro-Cache
X-Origin-Date
*
X-WPL-DATA
X-PBY
AMP-Redirect-To
X-Highwire-SessionId
X-Purge-Host
X-Purge-URL
TC-Cache
X-Highwire-RequestId
Access-Control-Allow-Header
X-Cache-Varnish
AETN-Postal-Code
X-Refresh
X-SmartBan-Host
X-Proxy-Cache-Control
Filters
X-HostName
XX
BALANCEDTO
X-SmartBan-URL
Locale
X-SAPP
TC-Cache-U
X-Response
X-Cache-On
X-CRA-DC
VANITY-HOST
X-Actindo-Request-Id
X-Actindo-Rs
Yoncu-Errno
Arrnode
X-Varnish-Debug-Age
X-Amz-Meta-S3b-Last-Modified
Myheader
X-ACCELERATE
TC-S-Cache-M
TC-S-Cache
X-AF-Userserver
X-Rebelmouse-Cache-Control
X-Timestamp
Resin-Trace
X-Resolver-IP
X-Upgrade-Enabled
TC-Cache-IC
AETN-Country-Name
X-ServerIndex
X-GoCache-CacheStatus
X-Server-Addr
AETN-Country-Code
X-Ms-Request-Id
AETN-City
AETN-Area-Code
AETN-Continent-Code
VServer
AETN-Longitude
XDomainRequestAllowed
DNNOutputCache
AETN-DEVICE
Load-Balancer
IES-Server
AETN-Latitude
Cmstype
Cmsid
AETN-EU
X-Smartcache-Timeout
X-WP
X-IIJ-Cache
X-Smartcache-Keys
Serverid
X-Cocoon-Version
Web-App-Origin-Name
X-Goog-Meta-Replace
X-Always-Cache
Nopic
Magicmarker
NLCacheNote
X-Goog-Meta-Policy
X-Fstrz
Dis-Env
Prot
X-Session-ID
X-Bip
MICROSOFTOFFICEWEBSERVER
X-Dw-Trace-Id
X-Origin-Cache
X-Depends
X-Dynatrace-Js-Agent
X-Id
X-Varnish-Id
DrivedBy
X-WebServer
Pragrma
X-Culture
X-Mobilized-By
X-Route
X-SERVER-NAME
X-Amcomm-Site
X-Appid
X-Varnish-Backend-Beresp-Backend
X-Amz-Id-1
X-Client-Id
X-Status
X-Varnish-Grace
X-ETag
X-7d-Trace-Id
X-Cdn-Forward
Xc
X-7d-Instance-Id
OracleCommerceCloud-Version
CommercePlatform-Version
Lb
OracleCommerceCloud-Sandiego
N365rili
X-Autoru-App-Id
X-Captured
X-Rule
X-MCB-Server
X-Batcache
X-UA-Bot
X-Autoru-Host
X-PHP-Response-Code
X-Hit
X-Upstream-Backend
X-Vol-Mrp
X-Wodby-Node
Cf-Ipcountry
X-Vol-Correlation
X-Served-Server
X-Instance
X-Mobile-Rewrite
X-Origin-Upstream-Status
Home
NGX
Aurora-Node
AC-ELC
X-Nginx-Dummy
X-Varnish-Cache-Local
X-B2f-Not-Route
Play-Detected-Device
Play-Detected-UserAgent
X-Fedora-School-Id
PB-RID
Upgrade-Insecure-Requests
X-Flex-Community
X-Flex-Evend
Thanks
Srv-Name
X-Upstream-Status
Edgecast
Fastly-Backend-Name
X-Flex-Evstart
X-Flex-Lang
X-Req-Head-Response
X-WEBMGR-CACHE
PB-PID
X-Map-Context
X-Flex-Tags
X-Flex-Lastmod
X-Flex-Tag
X-Middleton-PageSpeed
X-Custom-Name
X-Static
X-Jphone-Copyright
X-Proxy-Skip
X-VC-TTL
FRONT-END-SECUREBROWSER
Actual-Object-TTL
X-Reflector-Cache
X-Reflector
IP-Addr
X-Webcelerate
X-Lb
X-App
X-CacheID
X-Geo
X-Instance-Id
X-Varnish-Action
X-SH-Cache-Status
X-We-Are-Hiring
TP-L2-Cache
Og
X-Nginx
Keywords
X-Xml-Http-Blocked
TP-Cache
X-Varnish-ID
X-CacheDebug
Dispatcher
X-V
Description
X-Cache-Extended
X-IP
X-DataDome
CommunityServer
X-ESI
X-UUID
Bios
X-ReqId
Worker
X-DevSrv-CMS
X-Gateway-Rate-Limit-Delayed
X-Directory-Script
X-Proto
Provider
NZSpeedy
X-Dev
X-Cms-Mode
X-Airee-Node
Proxy-Cache
X-Blog
X-BPool-Back
X-BServer
X-Rack-Cors
X-Render-Time
From
X-Aramark-CSID
HitType
X-FastCGI-Cache-Status
X-Built-By
X-Vid
ClientIP
X-Protected-By
X-NodeID
F5-IpCliente
Il-Cl
X-Netrix-ID
X-MyName
X-Gannett-Site-Version
X-Aramark-SID
X-Layout
X-ManagedFusion-Rewriter-Version
Gzip
X-Zendesk-Origin-Server
REFRESH
X-Highwire-Smart-Code
X-Nginx-Request-Processing-Time
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
X-Highwire-Sitecode
X-Generated-Time
X-SV
X-Gyrobase-Publication
X-Cache-Via
X-SilverStripe-Cache
X-GeoIP-Country
X-Domino-CacheValidationWithETagResult
X-Origin-Server
X-PBS-Fwsrvname
X-Sid
X-PBS-Appsvrname
X-PBS-Appsvrip
X-Rewritten-By
X-Server-Generated
X-Serv
X-ProcessESI
X-Domino-CacheValidationWithETagReason
X-Proxy-Server
X-RemovedCookies
X-DN-Cache-Control
X-Zendesk-User-Id
COMMERCE-SERVER-SOFTWARE
X-PM-ID
X-Optimization
X-Podname
X-Firefox-Spdy
X-Beget-Proxy
X-Mighty-Proxy
X-FromPodPressCache
X-Cache-FS-Status
X-Phpwcms-Page-Processed-In
X-Grid-Server
X-GZip
X-Global-Transaction-ID
Apachenode
X-WA-Info
Now
GranicusServer
D
X-HS-Status
PBS
CLMOB
X-Ghost-Cache-Status
X-Src-Webcache
X-Header
X-Backside-Transport
X-Avvio-Cms-Cacheload
Amfplus-Ver
X-Catalyst
X-Phpwcms-Release
X-Reqid
SINA-TS
Content
X-Now-Trace
Response-Time
X-Vary-Options
X-W3TC-Minify
X-Title
ProxiaInstanceId
X-Middleton-Pagespeed
Session-Id
SINA-LB
VC-NoCache
Ssl-Proxy-Server
X-Cache-HT
Origin-Vm
X-InDy-Memory
X-FORWARDED-PROTO
X-DynamicCache
X-ENV
X-InDy-Query
X-InDy-Time
CF-Cache-Key
ViewMode
VSID
Provided-Host
X-NoIndex
X-Frames-Options
Cleartype
Webserver
HSTS
Hosted-By
X-Amzn-Remapped-Date
X-AppServer-Cache-Exception
X-Data-Request
Web
X-Node-App
Httpd-Identifier
Id
Server-Ip
ServerIP
Session-From
StatusCode
SBSS
Content-Sn
UrlWatchModule-Time
MSSmartTagsPreventParsing
MSThemeCompatible
X-Fastly-Backend-Reqs
X-AppServer-Cache-Rule
X-Application
X-Batcache-Reason
X-SE-Debug
X-Agent
Backend-Powered-By
TYPO3-Sitename
X-Cache-Date
ModuleCacheType
TYPO3-Pid
X-Cdn-Origin
X-EC2-Instance-Id
X-Streams-Distribution
X-UPServer
X-Varnish-Cached
X-Varnish-Cached-TTL
X-HA-Backend
X-HA-Frontend
X-Rack-CORS
X-MCF-ID
X-AppServer-Status
X-Compressed-By
X-HashTwo
X-Scheme
X-Info
X-RAMCache
X-Meta-MSThemeCompatible
X-Nx-All
X-Firewall
X-Instance-Name
X-Policy
X-Meta-MSSmartTagsPreventParsing
X-Cache-Action
X-Meta-Imagetoolbar
X-Proxy-Id
MwpReleaseVersion
MachineName
Num
Traffic-Origin
X-Pageid
X-Served-From
X-Beresp-Ttl
X-CH-Device
SS
X-Box
X-Cache-Node
X-Server-Hostname
X-Cache-TTL-Age
X-Cache-TTL-Current
X-Nx
X-TKP-SRV-ID
X-Cluster
X-SSL-Host
X-Appversion
X-VERSION
MageStack-Cache-Lifetime
X-Cache-Warmer
MageStack-Cache
MageStack-Cache-Hits
X-CACHE-KEY
Viewport
MageStack-Web-Node
X-Clx-Request
MageStack-Area
MageStack-Config
MageStack-Loadbalancer
MageStack-PageSpeed
MageStack-Debug
X-Cache-Cfc
PServer
X-WHO
X-LBPoolMember
MageStack-Magento-Version
X-MSU-SOURCE
X-Ms-Version
AMP-Access-Control-Allow-Source-Origin
Z
MageStack-Cache-Status
MageStack-Cacheable
X-OpenCart-Lightning
X-Serverid
MageStack-Tag
Device
X-Cache-Me-Harder
X-B
X-Az
X-ZORequestID
X-Time-Spent
X-Processed
X-Pj-Cache-Status
WN
X-Access-Control-Allow-Origin
MageStack-Last-Modified
X-Resty-Request-Id
MageStack-Cache-Lifetime-Sent
Generate-Time
X-This-Proto
X-Served
X-Oferteo-Domain
X-ProBase-Server
X-V-Cache
X-WN-ClientGroup
X-Cname-TryFiles
X-Cache-LB
X-UT-Cache
X-Debug-Message
X-Requestid
X-HA
X-Deity
MageStack-Cache-Warning
X-Cache-Detail
No-Cache
X-Beluga-Response-Time-X
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Status
X-Beluga-Trace
HitInfo
X-Request-Received
X-Request-Processing-Time
X-Beluga-Node
X-Beluga-Cache-Status
Page-Template
X-TNCMS-Bot-Tier
X-Built-With
X-ASAP-Age
X-ASAP-Cache
X-LAKANA-AB
X-Enhanced-By
X-Clara-ASAP
Language
Www.Aujourdhui.Com
EagleEye-TraceId
X-HS-Content-Group-Id
NEL
LB
X-Cache-Id
X-Svr
X-PageCache
X-Flash-Messages
CINC-Endpoint
X-VC-Hash
X-InstanceId
X-UD-METHOD
X-Cjtype
X-Page
X-Pool
X-VC-Debug
X-VC-Cacheable
X-VC-Cache
NtCoent-Length
Apple-Itunes-App
262prline
259pxline
196prxHost
316pxxline
X-Tradeindia-SMgmt
X-Container
X-Author
Powered-By-115
135prxHost
129prxHost
X-Transaction-Name
X-T
X-Req-Counter
NB-Cache
X-Dispatcher-Number
X-UPSTREAM-Address
X-Stiffia-Cache
X-OCTOPOD
Xxline
AR-ATIME
Progma
X-VG-WebCache
X-Thanos
X-AWS
X-Croise-Owner
AddDefaultCharset
X-ServiceProvider
X-Activity-Id
X-SuperCache
X-Varnish-Cache-Control
AR-SID
AR-PoweredBy
AR-CACHE
Requested-Host
X-Amz-Meta-Cb-Modifiedtime
X-Newrelic-Synthetics
X-DDM-SERVER-UPDATED
X-DDM-SERVER
X-Goog-Meta-Goog-Reserved-File-Mtime
X-APIVERSION
X-Obvious-Tid
X-Obvious-Info
X-Page-Cacheable
X-RequesterIP
X-User-Agent-Tier
X-SATserver
X-Nginx-VM-RT
X-Machine
TTL
Tk
X-AMAZEEIO
X-Apache2-RT-MicroSec
X-Client-Ip
X-Skip-Cache
CDCHOST
X-Powered-By-ADS
X-Pass-Through
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
X-Test-Debug
X-SCM-Server-Number
X-Node-Id
X-NMT-Proxy
Ohc-Response-Time
HA-Status
X-Abuse
X-NewsFlow-Sitename
X-Dck
ServerTokens
ServerSignature
X-Fpc
X-CacheLoc
WP-AdvCache-MemCached
X-Sn-Servicetimems
SERVER-NAME
X-Cache-Bypass
X-Block-RuleID
X-Block-Rule
Ibf5scheme
X-No-Session
X-Front-Cache
DB-Nickname
X-B3-Sampled
Debug-Status
Expiries
Origin-Edge-Control
Origin-Cache-Control
SB-Cache-Life
SB-Cache-Remaining
SB-Site-IE-VERSION
SB-Site-Device
X-UA
X-Old-Content-Length
X-DODN-Id
X-Geo-IP
X-DODN-Region
X-LB-Backend
X-LB-Frontend
X-MainProfileURL
X-Varnish-Cache-Ttl
X-Nws-Log-Uuid
X-Custom-Header
X-Shopware-Allow-Nocache
X-Shopware-Cache-Id
X-TLS-Version
X-Test
X-Beatles
X-Tradeindia-Request-GUID
Fastly-Debug-Digest
X-Varnish-URL
TestCC
Ttl
VAR-Cache
X-Varnish-Ip
EQ-Cache
X-RunCloud-Cache
X-Expires
X-Tag-Playlist
HTTPS
Tempo
MS-CV
X-DB-Content-Length
X-CSRF-Token
ID
Ews
NS-VaryByCustom-Key
X-Cache-ID
X-Cache-Time
X-Telligent-Evolution
X-Router
X-MainProfileCategory
Purge-Cache-Tags
X-Healthy
Value-Of-Url
X-ENDPOINT
X-APIAUTH-VAL
Hit-Count
Fastly-Restarts
RSL-Trace-ID
X-WebKit-CSP-Report-Only
X-XHTML-Minification-Powered-By
X-MainProfileName
X-MainProfileID
Fw-Via
X-Bitrix-Composite
Cache-Ctrol
BackendServer
PROGMA
Sl-Pgid
X-From-Cache
X-Varnish-Debug-Hits
Fastly-Drupal-Html
X-ORIKEY
X-Max-Age
X-PressLabs-Stats
X-ROUTING
X-Search-Id
Tesla.Performance