Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
P3P
X-AspNet-Version
X-Pingback
Age
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Template
X-Language
X-Generator
Alt-Svc
X-Buckets
X-Request-Id
X-Drupal-Cache
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Content-Location
Host-Header
X-Runtime
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-ShardId
X-Dc
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sorting-Hat-Section
X-Alternate-Cache-Key
MS-Author-Via
X-FRAME-OPTIONS
Cartoon
X-UA-Device
X-Powered-CMS
X-IPLB-Instance
X-Served-By
Access-Control-Allow-Credentials
Status
Access-Control-Allow-Headers
X-Amz-Cf-Id
Access-Control-Allow-Methods
X-Cache-Status
P3p
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
CF-Cache-Status
X-Contextid
X-Backend
Referrer-Policy
Powered-By
X-PC-Key
X-PC-Hit
X-Mod-Pagespeed
X-DIS-Request-ID
X-ServedBy
X-PC-Date
X-PC-Host
X-PC-AppVer
X-WPE-Loopback-Upstream-Addr
Content-Encoding
X-Request-ID
X-CST
X-Logged-In
Keep-Alive
X-Rid
X-Server
X-Cache-Hit
X-Host
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Port
X-CDN
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Server-Powered-By
X-Robots-Tag
X-Endurance-Cache-Level
X-Tumblr-Pixel-2
X-Nginx-Cache-Status
X-Wix-Request-Id
X-Seen-By
X-Wix-Server-Artifact-Id
X-Accel-Version
X-Original-Date
X-Turbo-Charged-By
X-Page-Speed
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
WP-Super-Cache
X-Content-Digest
X-Proxy-Cache
X-AH-Environment
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rack-Cache
X-Tumblr-Pixel-3
X-LiteSpeed-Cache
X-Varnish-Cache
X-GitHub-Request-Id
X-Ua-Compatible
X-Request-Country
X-XRDS-Location
SPRequestGuid
X-SharePointHealthScore
Edge-Control
X-Cnection
X-MS-InvokeApp
MicrosoftSharePointTeamServices
X-Cache-Lookup
X-Node
Cf-Railgun
Timing-Allow-Origin
X-Died
X-Amz-Id-2
X-Amz-Request-Id
X-FW-Hash
X-Trace
Charset
Request-Id
X-FW-Type
X-FW-Static
X-FW-Serve
X-FullPageCaching
Edge-Cache-Tag
X-Content-Security-Policy
X-HS-Cache-Config
X-Webcom-Cache-Status
X-HS-Content-Id
X-Webserver
X-CF-Powered-By
MicrosoftOfficeWebServer
X-Safe-Firewall
X-Hits
X-PhApp
Request-Context
SPIisLatency
SPRequestDuration
X-Newrelic-App-Data
X-INKT-SITE
X-INKT-URI
X-PHP-Backend
X-BC-Stapler
Access-Control-Max-Age
Composed-By
Access-Control-Expose-Headers
Grace
Served-By
X-Swift-CacheTime
X-Tumblr-Pixel-4
X-Swift-SaveTime
EagleId
X-Hyper-Cache
X-CDN-Pop-IP
X-CDN-Pop
Liferay-Portal
X-Spip-Cache
X-Backend-Server
X-SERVER
X-Device
X-Dw-Request-Base-Id
X-Server-Name
X-Fastly-Request-ID
X-Microcache
X-LiteSpeed-Cache-Control
X-VCache
X-ServerName
X-Wix-Renderer-Server
Rating
X-FB-Debug
X-RateLimit-Remaining
Content-Style-Type
X-Clacks-Overhead
X-RateLimit-Limit
X-Cloud-Trace-Context
Content-Script-Type
X-DDC-Arch-Trace
X-RateLimit-Reset
X-User-Agent
X-Jimdo-Instance
X-Jimdo-Wid
X-Loop
X-TNCMS
Real-Hostname
Surrogate-Control
X-Acc-Exp
X-Cache-Config
Front-End-Https
X-Firenze-Processing-Times
Public-Key-Pins
Refresh
X-Cdn
X-Tumblr-Content-Rating
X-XN-XNHTML
X-XN-Trace-Token
Fpc-Cache-Id
X-Middleton-Response
X-Middleton-Display
Response
Display
X-SS-Conf
X-Sol
X-SS-Location
X-StackifyID
X-Age
X-HS-Combine-CSS
X-Microcachable
X-Servedby
X-DNS-Prefetch-Control
Xkey
X-Generated-By
X-Hostname
X-Tumblr-Pixel-5
X-OneAgent-JS-Injection
X-Cached
X-Px
X-Zen-Fury
X-N-OperationId
X-Vtex-Processado-Em
PageSpeed
X-MiniProfiler-Ids
X-Topify-Platform
X-Request-Time
X-Ruxit-JS-Agent
X-Cached-By
TCN
X-Correlation-Id
X-Frame-Option
Edge-Control-Message
X-Amz-Version-Id
P-LB
P-WS
X-CMS-Version
X-Kinsta-Cache
X-WebKit-CSP
X-URL
X-Whom
X-Url
X-DynaTrace-JS-Agent
Rt-Fastcgi-Cache
X-Magento-Tags
Product
X-Handled-By
X-Outils-CS
X-Content-Options
X-B-Cache
X-Varnish-TTL
Surrogate-Key
X-AspNetWebPages-Version
X-Via-JSL
Imagetoolbar
Host
X-VARNISH-Cache
Access-Control-Request-Method
Powered
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge-Location
X-Engine
X-CacheServer
X-DynaTrace
Fhost
X-Cache-Rule
X-Forwarded-For
Fastly-Debug-Digest
X-Debug-Info
X-Track
ServedBy
X-FORWARDED-FOR
X-Umbraco-Version
X-VTEX-Janus-Router-Backend-App
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processed-At
X-Varnish-Cache-Hits
Public-Key-Pins-Report-Only
X-Powered-By-VTEX-Janus-ApiCache
X-Vtex-Remote-Cache
No
Alternate-Protocol
X-Recruiting
X-NWS-LOG-UUID
X-HOST
X-Signature
X-Application-Context
X-Platform
X-Location-Id
X-LBLID
X-Msg-2-Log
X-Goog-Hash
X-Powered-By-VTEX-Janus-Edge
X-Actual-URL
X-ApacheServer
X-Response-Time
X-PERF
X-Original-Request
X-Passed-To
X-Passed-To-DLL
X-Returned-From
X-Returned-From-DLL
X-Cache-Age
X-From
Fastcgi-Cache
WZWS-RAY
X-Powered-By-360WZB
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Developer
X-Passed-To-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Varnish-Beresp-Status
Generator
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
Akamai-IP
X-Tumblr-Pixel-6
X-Stale
X-Accel-Expires
Arr-Disable-Session-Affinity
X-Source
X-LW-Cache
Dmn
X-Rocket-Nginx-Bypass
X-Hosted-By
X-Pantheon-Site
X-Pantheon-Phpreq
DynaTrace
X-Pantheon-Environment
Surrogate-Key-Raw
HTTPS
Origin
X-Micro-Cache
X-LB
X-Upstream
X-RESOURCE
X-Platform-Processor
X-Platform-Router
X-Supported-By
X-Version
X-UD-Method
X-Cache-Info
X-I-Sp
X-BS
X-Defender
Retry-After
X-Shop-Id
X-Varnish-Host
X-URLSCHEME
X-Platform-Cluster
Content-Hash
X-LB-Node
X-Device-Type
X-Rnd
X-Director
X-S
Cache-Provider
X-NetCat-Version
X-Instart-Request-ID
X-Fastcgi-Cache
X-TransIP-Balancer
X-CSRF-Protection
X-Dispatcher
X-Magento-Cache-Debug
X-HS-Content-Campaign-Id
X-Powered-By-VelaWeb
X-Cache-TTL
X-Storage
X-Varnish-Count
X-Page-Cache
Last-Published
X-Varnish-HitMiss
Version
X-EdgeConnect-Origin-MEX-Latency
X-Cache-Key
X-App-Hosting
X-Daa-Tunnel
X-F-Cache
USPLoggingUUID
X-Front
Allow
X-AOL-HN
X-Matrix-Proxy
X-Matrix-Server
X-Translation
X-Art-Request-Id
X-Cache-Tags
X-Microcache-Status
X-EdgeConnect-MidMile-RTT
X-ATG-Version
IBM-Web2-Location
Ohc-File-Size
X-TransIP-Backend
X-Gamma-Serve
X-Expires-Orig
X-Hypernode
X-Drupal-Cache-Tags
X-Revision
Powered-By-ChinaCache
MIME-Version
X-I
X-Server-Upstream
X-Dispatch
X-Cache-Operation
X-ARC
X-Flow-Powered
Pool
X-Platform-Server
X-UPSTREAM
X-Content-Encoded-By
Content-MD5
RTSS
X-Cache-Debug
X-Varnish-ObjectSource
X-Varnish-RemainingLife
Cache-Key
X-Ua-Device
X-Cache-Only-Varnish
X-SSL-Protocol
X-Varnish-GracePeriod
Pagespeed
X-SSL-Cipher
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Vcap-Request-Id
Wsr-Cache
Node
X-Route-Server
X-Server-ID
SSPAppContext
X-Environment
Content-Disposition
X-Lambda-Id
X-ORACLE-DMS-ECID
X-Platform-Cache
X-Drupal-Cache-Contexts
X-Loopia-Node
X-Varnish-Cacheable
X-Cache-Lifetime
X-Abgroup
X-SV-FromDBCache
Lsrequestid
X-SV-Expires
X-SV-Nginx-Duration
X-SV-Duration
X-SV-Cacheable
X-Varnish-Age
X-SV-CacheTags
X-SV-CreatedAt
X-Cache-Control-Orig
X-SV-Edge
X-SV-Pid
X-Vhost
X-IsCacheURL
Page-Completion-Status
X-Edge-IP
X-Generated
X-Github-Request-Id
X-NoCache
X-Id
X-Cache-Engine
Accept-Encoding
X-Grace
X-Hiawatha-Cache
Fw-Via
Proxy-Connection
X-Cache-Server
X-Debug
X-Server-Id
X-Url-Base
Pv
X-Sapient
Section-Io-Id
X-CJ-Soft
Content-Encoding-Handler
X-Ttl
X-Proxy
X-Cache-Type
Cneonction
Srv
X-Correlation-ID
X-RequestId
ServerID
X-Client-IP
X-Cache-Expires
X-Nbs
X-SRCache-Key
Location
Server-Name
S-Cnection
X-Magento-Cache-Control
X-Firenze-Processing-Time
If-Modified-Since
X-GeoIP-Country-Code
X-Orig-Vary
Author
X-Sentry-ID
X-Ezoic-Cdn
X-TTL
X-Cache-Control
X-VTEX-Cache-Status-Janus-Edge
X-Akamai-Transformed
X-Duration
FAI-W-FLOW
NetMindSessionID
X-Browser
X-PwB-Node
X-Litespeed-Cache
X-Dns-Prefetch-Control
X-Geo-Country
ServerName
Backend
X-ServerID
X-Country-Code
SN
X-N
Nodo
SRV
X-Amz-Meta-S3cmd-Attrs
Server-Info
X-Content-Age
X-Processing-Time
X-Webkit-CSP
X-Discourse-Route
Req-Id
X-Speed-Cache
IM-Version
X-Speed-Cache-Key
X-Nginx-Cache
X-Location
X-Magnolia-Registration
X-Always-Cache
X-Sucuri-ID
X-FW
X-Dynatrace-Js-Agent
X-Cookie-Domain
X-Cache-CFC
X-Time
X-Yadis-Location
X-Middleware-Start
X-GeoIP-Country-Name
AMF-Ver
X-Akamai-Device-Model
X-NB-Cached-Page
X-Akamai-Device-Characteristics
HCVer
X-DealerOn
HAVer
Cm-Server
X-Varnish-Url
Qs-Cache
X-Goog-Storage-Class
X-Goog-Metageneration
NnCoection
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Cache-Level
X-Varnish-Backend
X-Goog-Generation
X-Goog-Stored-Content-Encoding
PICS-Label
X-Worker
X-Shield-Request-Id
X-Real-Server
SVR
X-SERVER-NAME
X-Cache-Namespace
X-Pressidium-NinukisWP-Ver
X-Framework
X-Cache-Device-Type
X-Drectory-Script
X-BKSrc
X-Cache-Fix
Use-Proxy
X-Varnish-IP
X-Cache-PageType
X-ACMCache
X-Processed-By
X-Frontend
X-Sucuri-Cache
X-BackendServer
Pics-Label
Cached
Accept-Charset
X-App-Server
X-SRV
X-Cluster-Node
X-Litespeed-Cache-Control
X-Fastly-Request-Id
X-Origin
X-Config-Blacklist-Version
X-SO
S
MC
Cache
X-Purge-URL
Xc-Version
X-LB-Server
Magicmarker
Thanks
X-Ss-Location
X-Ss-Conf
X-DataDome
X-Abuse
Content_type
X-Forwarded-Proto
X-Srv
Pf.Web.Request.Id
A-Powered-By
X-Session-ID
X-CDN-Forward
SiteSpeed
X-NginX-Cache
Tracecode
X-JG-Page-Cache
X-ID
Local-Info
X-Rocket-Nginx-Serving-Static
X-Runtime-Rack
X-Sys-Req-ID
X-PF-Uncompressing
Nitro-Cache
X-Server-IP
X-Amz-Storage-Class
X-LP
X-ARRServer
X-Last-Modified
X-Traffic
X-Route-To
X-Purge-Host
Server-Timing
SEOMOZ
X-Cache-Handler
X-Disney-Akamai-Rule
X-App-Status
X-RiS-UFDI
X-Pagename
X-Cache-TTL-Remaining
X-Domain-Checked
X-WN-ClientGroup
X-High-Performance
WN
X-CF-Passed-Proto
MJ12bot
X-Varnish-Retries
X-Hit-Cache
X-Provisioner-Version
X-Content-Security-Policy-Report-Only
W
From-Origin
X-Content-Type-Option
X-Cf-Powered-By
X-Mobilized-By
Dis-Env
X-OpenCart-Lightning
X-FastCGI-Cache
X-ClientSide-Caching
Cache-Tag
X-Empowered-By
X-WR-Flags
Nginx-Cache
WWW-Authenticate
X-Unique-ID
X-Jphone-Copyright
NODE
X-AEM
X-Varnish-Debug-TTL
X-Balanceador
X-VARITI-CCR
Eomportal-Instance
ServerTokens
ServerSignature
X-Sorting-Hat-Expire-Cache
X-SDS
X-Varnish-Debug-Age
EagleEye-TraceId
X-FTR-Request-ID
X-AF-Userserver
Frame-Options
X-Rq
HitType
P-ID
Keywords
X-Runtime-Memory
X-Webstats-RespID
X-Resty-Request-Id
X-Yottaa-Metrics
X-Fedora-School-Id
X-Generated-Time
X-Yottaa-Optimizations
Content-Transfer-Encoding
X-Esi
CacheControlHeader
X-Connection-Hash
SERVER-ID
AC-ELC
XDomainRequestAllowed
X-Varnish-ID
X-Transaction
X-Twitter-Response-Tags
X-Cache-Doesi
X-MCB-Server
X-Debug-Token
X-ASAP-Cache
Ufe-Result
Description
X-HTML-Minification-Powered-By
X-Clara-ASAP
X-Client-Image-Vid
Cache-Tags
X-CacheResult
X-EPiphany-Vid
X-Client-Vid
X-Directory-Script
X-HW
VANITY-HOST
X-Avg-Cookie-Expires
X-AVG-Country-Code
SBGI-RenderTime
SBGI-RealPath
SBGI-9
SBGI-Device
X-Redman-Backend
X-Redman-Final-Url
X-Amz-Meta-Cb-Modifiedtime
X-ORACLE-DMS-RID
X-CACHE-TTL
X-Detected-Device
X-VNode
X-Varnish-Hits
SBGI-7
X-Akamai-Edgescape
X-Adobe-Content
Web-App-Origin-Name
X-Adobe-Loc
SBGI-1
Adm-Server
SBGI-5
X-Cache-Keep
SBGI-10
X-Cms-Mode
X-Dev
X-Garden-Version
Worker
X-Server-Instance
X-Analytics
Backend-Timing
X-LW-Web-Server
Proxy-Agent
X-Unbounce-Variant
X-Unbounce-PageId
X-Unbounce-VisitorID
X-WPL-DATA
X-FireWall-Port
X-Varnish-Ttl
X-CAPServer
BALANCEDTO
Front
X-Webkit-Csp
X-Hstore
Noq
Ram
X-HOSTNAME
Ramp
X-HP-Trace-ID
X-HP-Trace-Project
X-Varnish-Hostname
X-Mobile-URL
X-ServerIndex
COMMERCE-SERVER-SOFTWARE
X-Env
X-GSL-Server
Max-Age
X-GeoIP
X-Rewrite
Smug-CDN
X-SmugMug-Hiring
X-GoCache-CacheStatus
X-Page
Cteonnt-Length
X-WebKit-CSP-Report-Only
X-TTFB-L
X-SmugMug-Values
X-TTFB
X-Key
X-Hrouter
X-Atraveo-Cache-Control
X-Force
X-Atraveo-ETag
X-Atraveo-Expires
X-Atraveo-From-Varnish-Cache
X-Atraveo-Zone
Dispatcher
X-Atraveo-Varnish-Server-Id
X-Atraveo-TTL
X-Remote-Addr
X-Atraveo-Set-Cookie
X-Atraveo-Param-Rm
X-Source-ID
X-CB-Server
Play-Detected-Device
X-PRAM
Play-Detected-UserAgent
X-Cache-Node
X-App-Runtime
Device
Contao-Page-Layout
X-A
X-Reflector
Cmsid
X-Culture
X-Runtime-Affili
BackendServer
X-Backend-Status
Cmstype
X-Nginx-Host
Machine
AMP-Access-Control-Allow-Source-Origin
Beyond-Iis
X-Reflector-Cache
X-SH-Cache-Status
NLCacheNote
X-OPNET-Transaction-Trace
X-Confluence-Request-Time
X-Akamai-3PM-SW-Version
X-Amcomm-Site
X-Resolver-IP
X-E
X-Smartcache-Keys
X-Frames-Options
X-WP
TC-Cache
TC-Cache-IC
TC-S-Cache
TC-Cache-U
X-Forwarded-Host
X-Varnish-Server
Og
Resin-Trace
X-NginX-Server
X-Plat
X-App
TC-S-Cache-M
Disablevcache
X-Real-IP
X-Symfony-Cache
X-CacheID
X-CDN-COMPRESS
X-Webcelerate
X-Trace-Id
X-Machine
X-Smartcache-Timeout
X-Wikidot-Static-Cache
From
X-Wikidot-Backend
Access-Control-Allow-Header
X-CDN-RULE
X-TB-M
X-Distributor
X-Magento-Action
Strikingly-Cached-Version
Strikingly-Cache-Region
X-HydroSheep
Strikingly-Cached
MS-CV
X-Fstrz
X-V
X-Airee-Node
X-VC-TTL
X-Varnish-Ip
X-HP-CAM-COLOR
X-AutoRu-App-Id
Bios
Web
X-Autoru-Host
Lb
X-Autoru-LB
X-Dynamic-Cache
X-Rack-CORS
Id
Fastly-Backend-Name
X-Stage
X-VC-Enabled
X-Proto
X-IIJ-Cache
Hname
SG
X-Cache-Dispatchercachecontrol
X-Cache-Dispatcherpragma
X-FPC
Traffic-Origin
SHInfo
X-Viator-Tapersistentcookie
OriginServer
X-Gateway-Cache-Status
X-Batcache-Reason
X-Hosting-Env
WebServer
Myheader
X-PBS-Fwsrvname
X-MSEdge-Ref
X-Highwire-SessionId
X-Captured
X-Origin-Server
X-SmartBan-Host
PagesDisplayed
X-NewsFlow-Sitename
X-Highwire-RequestId
X-PBS-Appsvrname
X-SmartBan-URL
X-Dw-Trace-Id
X-PBS-Appsvrip
Identity
X-DN-Cache-Control
Hostname
X-Varnish-Cache-Local
X-EC2-Instance-Id
CLMOB
N365rili
Ibf5scheme
Content-Server
Hamster
X-Bip
X-Cache-On
X-Gateway-Skip-Cache
X-ETag
X-Pj-Cache-Status
X-Refresh
X-SDE-Name
X-Session-Reinit
X-Render-Time
ViewMode
Yoncu-Errno
X-ENV
IISExport
F5-IpCliente
X-Desc
Gzip
X-Data-Request
X-Compressed-By
X-HashTwo
X-Machine-Name
Arrnode
X-WR-MODIFICATION
ClientIP
X-Gyrobase-Publication
X-MAT-GEO
X-Catalyst
X-RDP
X-Instance-Id
X-Ser
Home
CommunityServer
ScoreTracker
X-Ghost-Cache-Status
X-Depends
X-Gateway-Cache-Key
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Redirector
X-L-Path
X-Proxy-Cache-Key
X-Batcache
X-Info
Proxy-Cache
X-Map-Context
SB-Site-Device
SB-Cache-Life
SB-Cache-Remaining
X-Environment-Context
Il-Cl
X-Adnet
VC-NoCache
Ews
Paypal-Debug-Id
X-B2f-Not-Route
X-Cache-FS-Status
X-Req-Head-Response
X-Aramark-SID
NS-VaryByCustom-Key
X-DTC
X-Cdn-Forward
X-Apm-Telemetry-Syncmark
Service-Worker-Allowed
Access-Control-Request-Headers
X-Protected-By
X-Grid-Server
X-Goog-Meta-Policy
X-PM-ID
Custom-Header
X-FORWARDED-PROTO
X-Goog-Meta-Replace
X-UA
AsisCache
RN-Server
X-Cocoon-Version
X-Rack-Cors
X-Header
Serverid
X-WA-Info
X-KoobooCMS-Version
Server-Id
Xc
Url
X-Resource
Cleartype
X-HostName
X-Unique-Id
X-RealServer
X-RAMCache
MW-Webserver
X-W3TC-Minify
Warning
NtCoent-Length
X-VC-Cache
X-Server-Generated
X-PHP-Response-Code
X-Origin-Cache
Hummingbird-Cache
X-Zendesk-User-Id
X-Zendesk-Origin-Server
Edgecast
X-ProcessESI
X-RemovedCookies
X-Secret
X-Flex-Lang
X-Cache-TTL-Age
X-Flex-Evstart
X-Cache-TTL-Current
X-DSMX-Rewrite-MS
X-DSMX-Render-MS
X-Does-He-Have-Time
Session-From
X-Cache-Set
X-Cache-Time
X-Beatles-Hits
X-Old-Content-Length
ServerIP
X-Amz-Meta-S3b-Last-Modified
User-Agent
X-Powered-By-Home.Pl
Accept-Language
X-Src-Webcache
X-TTL-Age
X-Cache-Via
X-Your-GrandPa-Would-Wait
X-Would-Your-GrandPa-Wait
Ctx
X-Flex-Tags
X-Flex-Community
X-Flex-Evend
X-Flex-Lastmod
X-Flex-Tag
Hosted-By
X-Streams-Distribution
X-JSESSIONID
X-Nginx-Request-Time
X-Nginx
VServer
X-Timestamp
X-Upstream-Backend
X-Sc-Cache
X-MainProfileURL
X-Middleton-PageSpeed
X-Litespeed-Tag
Session-Id
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-Varnish-Id
DrivedBy
Provided-Host
X-Backend-Host
X-IP
X-We-Are-Hiring
X-Cluster
Note
X-ASAP-Age
X-Avvio-Cms-Cacheload
X-Via-NSCOPI
PServer
X-CRA-DC
Aoestatic
SB-Site-IE-VERSION
X-M
X-MainProfileCategory
X-CH-Device
X-Beatles
X-Bcwwwid
SS
X-Cache-Id
DNNOutputCache
X-Response
X-MainProfileID
X-Magento-Lifetime
X-Tag-Playlist
X-LBPoolMember
RequestId
X-MainProfileName
X-Author
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Referer
ReqUrl
X-4ormat-Cacheable
Viewport
X-Lw-Cache
X-Varnish-Action
X-Pagely-Cache
X-HS-Status
X-Netrix-ID
X-CSRF-Token
X-Served-Server
X-HAProxy
X-SV
X-Server-Addr
NZSpeedy
X-Dynatrace
X-DEBUG
X-ACCELERATE
X-ReqId
Mime-Version
Server-Ip
X-DB-Content-Length
X-Serv
Provider
X-MidCOM-Meta-Cache
X-Search-Id
Fastly-Restarts
X-Full-Url
X-Max-Age
X-Cjtype
X-Cache-Original-TTL
Www.Aujourdhui.Com
X-Backend-Name
X-Pixelsilk-Server
X-Pixelsilk-Version
X-FIRSTBase
X-VC-Debug
X-VC-Hash
X-VC-Cacheable
X-Turpentine-Esi
X-Instart-Cache-Id
X-SCM-Server-Number
WP-AdvCache-MemCached
X-Say-TTL
Generate-Time
PB-PID
!~Request-OOB-Work
AR-ATIME
AR-CACHE
PB-RID
Quri
X-Router
X-Activity-Id
Uuri
Tesla.Performance
X-Server-Ip
X-Served
Microcache
X-Cname-TryFiles
Upgrade-Insecure-Requests
Tempo
X-Deity
EQ-Cache
X-Made-On
AR-PoweredBy
AR-SID
Control-Cache
X-Route
X-Header-Treatment
X-DevSrv-CMS
X-Custom-Header
X-Say-Cacheable
X-Hosting
X-Amz-Id-1
X-CCM
RSB-LINK
Ttl
X-Amz-Meta-Content-Md5
X-Domino-CacheValidationWithETagResult
X-SayCDN-TTL
X-Enabled1
X-Enabled2
X-Debug-Message
X-Cache-Detail
X-Az
X-AppVersion
X-DynamicCache
X-Enabled3
X-UT-Cache
X-Mobile-Rewrite
X-HA
X-FastCGI-Cache-Status
X-Domino-CacheValidationWithETagReason
Kanooh-Host
X-Uncacheable
X-SuperCache
Progma
X-AppServer-Cache-Rule
X-Cache-Varnish
X-Healthy
ServerNode
X-7d-Trace-Id
X-7d-Instance-Id
X-Middleton-Pagespeed
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-Config-By
X-D-Time
StatusCode
EN-User
X-AISO-Cache
X-AISO-Cacheable
X-AISO-Server
Cache-Status
X-XHR-Current-Location
X-Generation-Time
X-Node-Name
X-S-Misc
X-Time-Microsecs
X-MyName
X-UPSTREAM-Address
X-Not-Cacheable
X-LOCATION
X-Upstream-Status
FRONT-END-SECUREBROWSER
INFO
Services
XDisk
X-WebServer
AMFplus-Ver
AccessControlAllowOrigin
X-BeResp-Ttl
TP-Cache
TP-L2-Cache
X-REDIRECTSERVER
X-Geo-IP
X-Skip-Cache
X-Upgrade-Enabled
X-WebNode
X-Container
X-Client-Ip
X-Agent
X-Application
X-Box
X-Cache-Extended
X-Cache-V
X-Hash
X-Artvisual-Server
X-DS1D
X-Distil-CS
Server-ID
Ec-CorrId
Ec-Machine
X-Nginx-Request-Processing-Time
X-AMAZEEIO
X-Blog
CDCHOST
X-Instance
X-SilverStripe-Cache
X-Status
X-Enhanced-By
Cacheid
X-ManagedFusion-Rewriter-Version
X-Pubstack
Debug-Status
Access-Control-Allow-Method
X-XHTML-Minification-Powered-By
X-RequesterIP
X-UnsetCookies
X-Node-ID
X-Gannett-Site-Version
Expiries
X-Rewritten-By
MwpReleaseVersion
X-NodeID
X-PROCESSED-BY
MachineName
X-Test-Debug
X-ESI
X-Oracle-DMS-ECID
X-Lb
X-Ssl-Cipher
Dynatrace
X-Cache-Ttl
X-Oneagent-Js-Injection
X-Ruxit-Js-Agent
Powered-By-VeryCDN
X-AWS
MageStack-Config
X-Archive-Orig-Server
X-Cache-Date
MageStack-Debug
X-Request-Received
X-PBY
X-Built-By
X-Request-Processing-Time
X-Archive-Orig-ETag
X-Server-App
Language
X-Archive-Guessed-Charset
X-Cache-Warmer
WP-FROM-CACHE
X-Instance-Name
X-LB-Backend
X-LB-Frontend
Realaction
MSThemeCompatible
Actioncode
X-Varnish-Cached-TTL
CS-SERVER
Httpd-Identifier
MSSmartTagsPreventParsing
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
X-WHO
TTL
Memento-Datetime
X-Archive-Orig-Connection
X-Archive-Orig-Content-Length
CD4
Actual-Object-TTL
X-Restarts
X-Meta-MSThemeCompatible
X-Server-Vrn
X-Wm-1
X-Wm-VIP
X-Archive-Orig-Date
X-Varnish-Esi-Method
MageStack-Cache-Hits
CommercePlatform-Version
X-Pool-Info
X-Pageid
X-Nocache
X-Q-S
X-Serverid
X-T
X-S-V
X-S-C
X-Varnish-Cached
X-Mw-Workerstats
X-M-V
X-Beresp-Ttl
Key
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
X-Cachable
X-Cacheable-TTL
X-M-T
MageStack-Cache
X-M-P
X-I-V
X-Transaction-Name
X-ProBase-Server
X-Varnish-Esi-Access
X-Varnish-Currency
X-B
X-Varnish-Store
MageStack-Area
X-SSLUpstream
X-Fastly-Backend-Reqs
CpuTime
GranicusServer
MageStack-Cacheable
X-Svr-Proxy
MageStack-Loadbalancer
MageStack-Magento-Version
X-Origin-Upstream-Status
MageStack-Cache-Status
MageStack-Cache-Lifetime
X-OCTOPOD
X-NewCloud-V-Cache
X-Backend-TTL
X-SSLProxy
MageStack-PageSpeed
MageStack-Tag
MageStack-Web-Node
X-Debug-Serve
Head
X-FG-RequestId
X-EBAY-C-REQUEST-ID
WSCLoggingUUID
X-Varnish-Grace
X-Who
RlogId
Page-Template
X-Cache-Bypass
X-CO-Host
X-Nginx-Page-Cache
X-Powered-Developer
X-ZSITES-DNS
Accept-CH
X-Svr
X-Cache-Served
X-This-Proto
X-ACLR-Version
X-Varnish-URL
X-Ar-Debug
OutputRewritten
Aurora-Node
X-Ants-Host
X-Ants-Machine-Id
X-BC
Response-Time
Countrycode
X-Clx-Request
SINA-TS
X-MSU-SOURCE
X-SE-Debug
X-SID
SINA-LB
Requested-Host
ATI-Server-Id
X-COUNTRY-CODE
X-9XB-Server
Cache-Ctrol
X-VG-WebCache
Apple-Itunes-App
X-Time-Zone
X-Varnish-Instance
X-VLoc
CmsfirstPublishTimestamp
X-ServiceProvider
X-Server-FQDN
UrlWatchModule-Time
X-Country
X-ELB
X-PG
Copyright
X-Accel-Cache-Control
XX
X-Service-Id
Cookie
DB-Nickname
IES-Server
X-Proxy-Id
X-Distributed-By
DbServerName
FindLaw
Rewriter
Webserver
Load-Balancer
Request-Time
X-Nitro-Cache
X-Script
X-ServerAddr
X-Sn-Servicetimems
X-MCF-ID
X-Fpc
X-B3-Spanid
X-B3-Traceid
X-Built-With
X-CPU-Time
Content-Cache
X-Sid
Yola-ID
Y-Trace
Fw-Cache-Status
X-Cache-2
X-IP-Address
X-ZORequestID
X-Title
X-Czt
X-Layout
X-Memcached
X-Server-Ident
X-VCS-Cacheable
X-VCS-Ttl
X-DeliveryServer
X-Dynamic
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
X-Config-Version
X-Cache-Me-Harder
X-WAF-Proxy
E-TAG
VAR-Cache
X-Brought-To-You-By
X-UPServer