Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
X-Cache
P3P
X-AspNet-Version
CF-RAY
Strict-Transport-Security
X-Pingback
Age
Content-Language
Via
X-UA-Compatible
Access-Control-Allow-Origin
X-Adblock-Key
X-Xss-Protection
X-Varnish
Upgrade
X-Check
X-Language
X-Template
X-Cacheable
X-Generator
Content-Security-Policy
X-Buckets
X-Drupal-Cache
P3p
X-Request-Id
X-AspNetMvc-Version
X-Type
X-Cache-Group
X-Pass-Why
X-Hacker
X-Ac
Content-Location
X-Powered-By-Plesk
X-Cache-Hits
X-Runtime
X-Permitted-Cross-Domain-Policies
MS-Author-Via
X-Download-Options
Host-Header
X-ShopId
X-IPLB-Instance
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-Dc
X-Sorting-Hat-Section
X-ShardId
X-Sorting-Hat-ShopId-Cached
X-Alternate-Cache-Key
Cartoon
Alt-Svc
X-Powered-CMS
Status
X-UA-Device
X-Served-By
WPE-Backend
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Amz-Cf-Id
X-Via
X-Request-ID
X-Iinfo
X-Backend
X-Cache-Status
X-ServedBy
X-Contextid
X-Timer
X-PC-Key
X-PC-Hit
Powered-By
X-Mod-Pagespeed
X-DIS-Request-ID
X-PC-AppVer
X-PC-Date
X-PC-Host
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
CF-Cache-Status
X-Logged-In
X-Ua-Compatible
Keep-Alive
X-Server
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cache-Hit
X-CDN
X-Port
X-Host
X-Tumblr-Pixel-1
Content-Encoding
X-Tumblr-Pixel-2
X-CST
X-Robots-Tag
X-Server-Powered-By
WP-Super-Cache
X-Pad
X-Cache-Enabled
X-Rid
Referrer-Policy
X-Nginx-Cache-Status
X-Seen-By
X-Wix-Renderer-Server
X-Wix-Request-Id
Fastly-Debug-Digest
X-Accel-Version
X-Endurance-Cache-Level
X-Turbo-Charged-By
X-Page-Speed
X-Tumblr-Pixel-3
X-Content-Powered-By
X-Wix-PunisherID
X-Rack-Cache
X-Content-Digest
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-AH-Environment
X-Forwarded-For
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Surrogate-Key-Raw
Content-Security-Policy-Report-Only
SPRequestGuid
X-SharePointHealthScore
X-Proxy-Cache
X-Cnection
MicrosoftSharePointTeamServices
X-Request-Country
X-Forwarded-Proto
X-MS-InvokeApp
X-GitHub-Request-Id
X-XRDS-Location
X-Cache-Lookup
X-Died
X-Original-Date
X-Safe-Firewall
Cf-Railgun
X-LiteSpeed-Cache
MicrosoftOfficeWebServer
Edge-Control
X-FullPageCaching
Timing-Allow-Origin
Request-Id
X-Amz-Request-Id
X-Amz-Id-2
X-Webserver
Charset
X-Node
X-PhApp
SPIisLatency
X-INKT-SITE
X-INKT-URI
SPRequestDuration
X-FW-Hash
X-Tumblr-Pixel-4
X-Content-Security-Policy
X-CF-Powered-By
X-FW-Serve
X-FW-Type
X-FW-Static
Composed-By
X-Hits
Access-Control-Max-Age
X-Swift-CacheTime
X-Swift-SaveTime
EagleId
Content-MD5
Rating
Served-By
X-Hyper-Cache
X-HS-Cache-Config
X-Firenze-Processing-Times
Edge-Cache-Tag
X-HS-Content-Id
Liferay-Portal
X-Spip-Cache
Grace
Access-Control-Expose-Headers
X-CDN-Pop-IP
X-CDN-Pop
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-Server-Name
X-Device
X-Tumblr-Content-Rating
X-BC-Stapler
X-Dw-Request-Base-Id
X-Backend-Server
X-Newrelic-App-Data
X-Fastly-Request-ID
X-Microcache
Request-Context
X-RateLimit-Remaining
X-VCache
X-RateLimit-Limit
Public-Key-Pins
X-RateLimit-Reset
Content-Style-Type
X-SERVER
X-Cloud-Trace-Context
X-ServerName
X-FB-Debug
X-Jimdo-Wid
X-Jimdo-Instance
X-User-Agent
Content-Script-Type
X-Clacks-Overhead
Refresh
X-Acc-Exp
Real-Hostname
X-TNCMS
X-Loop
Xkey
X-Cache-Config
X-XN-Trace-Token
X-XN-XNHTML
X-DDC-Arch-Trace
Front-End-Https
X-Age
Fpc-Cache-Id
X-Microcachable
X-Url
Surrogate-Control
X-N-OperationId
X-Px
X-Generated-By
X-DNS-Prefetch-Control
X-Hostname
X-Tumblr-Pixel-5
X-Cached
PageSpeed
X-LiteSpeed-Cache-Control
Surrogate-Key
Response
X-Middleton-Response
X-Sol
X-Middleton-Display
Display
X-Pantheon-Site
X-Pantheon-Environment
X-Pantheon-Phpreq
X-StackifyID
X-MiniProfiler-Ids
X-Topify-Platform
X-WebKit-CSP
X-Zen-Fury
X-Cached-By
X-SS-Conf
X-SS-Location
X-CMS-Version
X-Content-Options
Rt-Fastcgi-Cache
X-Outils-CS
X-Request-Time
TCN
X-HOST
X-Whom
Product
X-Handled-By
X-PERF
Edge-Control-Message
X-ApacheServer
X-DynaTrace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-DynaTrace-JS-Agent
X-Umbraco-Version
X-AspNetWebPages-Version
X-OneAgent-JS-Injection
Access-Control-Request-Method
X-Amz-Version-Id
Imagetoolbar
X-LBLID
X-Ruxit-JS-Agent
Host
X-Varnish-Cache-Hits
Alternate-Protocol
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Cache-Rule
X-Engine
X-Tumblr-Pixel-6
X-Correlation-Id
X-Varnish-TTL
X-NWS-LOG-UUID
WZWS-RAY
ServedBy
X-Powered-By-360WZB
X-Micro-Cache
X-Recruiting
DynaTrace
Powered
X-Kinsta-Cache
X-From
X-Magento-Tags
X-Track
Fhost
X-CacheServer
X-Msg-2-Log
X-URL
X-Edge-Location
Generator
P-WS
P-LB
X-VARNISH-Cache
X-Location-Id
X-Upstream
X-Powered-By-VTEX-Janus-ApiCache
No
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-Hosted-By
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processado-Em
X-Powered-By-VTEX-Janus-Edge
X-FORWARDED-FOR
Dmn
X-Varnish-Host
X-Varnish-Backend
X-Goog-Hash
X-Instart-Request-ID
X-Cache-TTL
Origin
Fastcgi-Cache
X-Actual-URL
X-B-Cache
X-URLSCHEME
X-Cache-Age
Arr-Disable-Session-Affinity
Expect-CT
X-Returned-From-DLL
X-Returned-From
X-RESOURCE
X-Passed-To
X-Passed-To-DLL
X-LB
X-Original-Request
X-Fastcgi-Cache
X-Response-Time
X-Cdn
Akamai-IP
X-BS
X-App-Hosting
X-I-Sp
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Matrix-Proxy
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Matrix-Server
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Pool
X-Internal-ReqID
X-Cache-Info
X-Stale
X-Source
X-TransIP-Balancer
X-Application-Context
X-UD-Method
X-Developer
X-NetCat-Version
Powered-By-ChinaCache
X-Device-Type
X-Varnish-Cacheable
X-Defender
X-S
X-Shop-Id
X-Art-Request-Id
X-Version
X-I
X-Origin
X-Platform
Content-Hash
X-Content-Encoded-By
HTTPS
X-Powered-By-VelaWeb
X-VTEX-Cache-Status-Janus-Edge
X-Daa-Tunnel
X-Expires-Orig
X-TransIP-Backend
X-TTL
IBM-Web2-Location
X-Front
X-Accel-Expires
X-Platform-Router
X-Gamma-Serve
X-Platform-Processor
X-Storage
X-Rocket-Nginx-Bypass
X-Revision
X-Platform-Cluster
X-Cache-Operation
X-Cache-Tags
X-HS-Content-Campaign-Id
X-Firenze-Processing-Time
X-Cache-Debug
Ohc-File-Size
X-Microcache-Status
X-Translation
Cache-Tag
USPLoggingUUID
Version
X-LB-Node
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Varnish-Seen-By
X-Supported-By
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-NoCache
Node
X-EdgeConnect-Origin-MEX-Latency
X-Route-Server
X-Varnish-HitMiss
X-Varnish-Count
X-Page-Cache
X-Signature
X-Server-ID
X-Dispatcher
X-Dispatch
Last-Published
X-EdgeConnect-MidMile-RTT
MIME-Version
X-Platform-Server
SSPAppContext
X-Akamai-Transformed
X-Akamai-Device-Characteristics
X-Duration
X-Cache-Only-Varnish
Content-Disposition
X-Cache-Key
X-Server-Upstream
X-Cache-Control-Orig
X-Hypernode
X-ATG-Version
ServerID
X-Abuse
X-SV-FromDBCache
X-Flow-Powered
X-SV-Nginx-Duration
X-SV-Pid
Page-Completion-Status
X-SV-Expires
X-SV-Edge
X-Github-Request-Id
X-Varnish-Age
X-SV-Duration
X-SV-Cacheable
X-SV-CreatedAt
X-SV-CacheTags
X-Director
ServerName
Lsrequestid
X-SSL-Protocol
Srv
X-Cache-Lifetime
Content-Encoding-Handler
Cneonction
X-ARC
X-CJ-Soft
X-Cookie-Domain
X-NewRelic-App-Data
Cache-Key
X-SSL-Cipher
X-F-Cache
X-Magento-Cache-Debug
PICS-Label
X-Edge-IP
FAI-W-FLOW
X-Last-Modified
X-PwB-Node
X-Grace
X-Amz-Meta-S3cmd-Attrs
X-SE-Debug
X-SDS
X-Country-Code
X-Geo-Country
X-Content-Age
IM-Version
X-GeoIP-Country-Code
SN
S-Cnection
X-Debug
X-Akamai-Device-Model
X-Nbs
X-Url-Base
Proxy-Connection
X-Platform-Cache
X-ServerID
X-Speed-Cache-Key
X-Speed-Cache
X-Cache-Server
Allow
X-Client-IP
X-ORACLE-DMS-ECID
X-UPSTREAM
X-Abgroup
X-Vcap-Request-Id
Accept-Encoding
X-GeoIP-Country-Name
X-Sapient
X-AOL-HN
X-Internal-UserID
X-Frontend
X-Cache-Engine
If-Modified-Since
X-Lambda-Id
Location
X-CDN-Cache-Status
X-CDN-Node
X-Proxy
X-Time
Qs-Cache
X-Orig-Vary
X-Shield-Request-Id
X-Processing-Time
X-RequestId
X-NB-Cached-Page
Magicmarker
X-Server-Id
X-Processed-By
X-Middleware-Start
A-Powered-By
X-Varnish-Url
Cached
AMF-Ver
Section-Io-Id
Req-Id
X-Real-Server
X-Browser
X-BackendServer
Retry-After
X-Srv
NnCoection
X-Sucuri-ID
CacheControlHeader
X-Goog-Metageneration
X-Cache-Expires
MJ12bot
X-Goog-Generation
X-AF-Userserver
X-N
X-Goog-Stored-Content-Encoding
Content-Transfer-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
S
X-Worker
X-Goog-Storage-Class
Accept-Charset
X-Always-Cache
WSR-Cache
SEOMOZ
X-VC-Enabled
X-EC-Security-Audit
X-FW
Backend
X-VC-TTL
Pv
Server-Info
X-IsCacheURL
X-Sucuri-Cache
Author
X-Discourse-Route
X-Cache-Control
RTSS
X-SRCache-Key
Use-Proxy
Fw-Via
SRV
X-Id
X-Ttl
Cm-Server
MC
X-DealerOn
X-Loopia-Node
X-Config-Blacklist-Version
HCVer
X-BKSrc
X-Hiawatha-Cache
HAVer
X-Pressidium-NinukisWP-Ver
Nodo
X-Framework
X-Cache-TTL-Remaining
Cteonnt-Length
X-PF-Uncompressing
NetMindSessionID
EagleEye-TraceId
Cache
X-Cache-Level
Local-Info
X-Dns-Prefetch-Control
X-Nginx-Cache
X-Drectory-Script
X-Magnolia-Registration
X-WR-MODIFICATION
X-TB-M
Tracecode
X-Cache-Type
X-Vhost
X-Nginx-Host
SVR
X-Cache-Handler
X-Varnish-Hostname
X-Powered-By-Server
Server-Name
X-Varnish-Hits
Buuteeq-Source
X-Empowered-By
X-Served-Server
X-Correlation-ID
X-Directory-Script
X-Purge-URL
X-ACMCache
X-Varnish-Ttl
X-ID
X-Server-Instance
X-Unbounce-VisitorID
X-Unbounce-PageId
X-Healthy
WWW-Authenticate
X-Environment
Nitro-Cache
X-Generated
X-Amz-Storage-Class
Thanks
X-Litespeed-Cache
X-Unbounce-Variant
X-Traffic
X-Route-To
X-Trace
X-Cache-PageType
X-Cache-Fix
Cache-Provider
Identity
X-Adobe-Content
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-IP
X-Runtime-Rack
X-Yadis-Location
X-JG-Page-Cache
X-Adobe-Loc
X-OpenCart-Lightning
X-Cocoon-Version
SS
Keywords
X-FireWall-Port
X-Fastly-Request-Id
X-Resolver-IP
X-Connection-Hash
X-Purge-Host
X-Twitter-Response-Tags
Xc-Version
Eomportal-Instance
X-Unique-ID
X-Site-Name
Ufe-Result
BALANCEDTO
X-Pagename
X-Hit-Cache
X-Magento-Cache-Control
X-LB-Server
X-Transaction
X-Sys-Req-ID
Front
X-ClientSide-Caching
X-WR-Flags
X-Session-ID
X-HW
Frame-Options
X-Garden-Version
X-Content-Security-Policy-Report-Only
X-TTFB
X-LP
Smug-CDN
X-SmugMug-Hiring
NODE
IISExport
HitType
X-TTFB-L
X-Cache-Doesi
X-SmugMug-Values
X-High-Performance
X-Runtime-Memory
X-Varnish-Retries
X-CF-Passed-Proto
X-NginX-Cache
X-Mobilized-By
Description
X-EPiphany-Vid
X-Cache-Source
X-Author
X-CB-Server
X-Litespeed-Cache-Control
X-Cache-Node
X-Location
X-HOSTNAME
X-Client-Vid
X-Client-Image-Vid
X-Cache-Provider
X-LW-Web-Server
X-Nginx
X-We-Are-Hiring
X-Drupal-Cache-Tags
X-Cache-Device-Type
X-Session-Reinit
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Dispatcherpragma
X-Debug-Token
Disablevcache
X-Cache-Dispatchercachecontrol
X-VARITI-CCR
X-Atraveo-TTL
X-Balanceador
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
X-Atraveo-Set-Cookie
WN
X-Atraveo-ETag
X-Atraveo-Cache-Control
X-Atraveo-Expires
X-Atraveo-From-Varnish-Cache
X-Atraveo-Param-Rm
X-Highwire-RequestId
X-WN-ClientGroup
Strikingly-Cached
Beyond-Iis
From-Origin
X-Env
X-Distributor
X-SmartBan-Host
X-SmartBan-URL
Strikingly-Cached-Version
X-Highwire-SessionId
X-Grid-Server
Dispatcher
X-NginX-Server
X-Varnish-Debug-TTL
X-Varnish-Debug-Age
X-Force
NLCacheNote
X-App-Server
X-Source-ID
X-PRAM
Content_type
X-HydroSheep
X-Webcelerate
X-OPNET-Transaction-Trace
Max-Age
X-HTML-Minification-Powered-By
ServerSignature
ServerTokens
X-ARRServer
X-RiS-UFDI
X-Disney-Akamai-Rule
X-DEBUG
X-CAPServer
X-ORACLE-DMS-RID
Public-Key-Pins-Report-Only
Web-App-Origin-Name
X-App-Status
X-App
X-ServerIndex
X-Rack-Cors
X-Generated-Time
X-Optimization
X-WebKit-CSP-Report-Only
X-HITS
X-Provisioner-Version
X-Domain-Checked
X-GeoIP
X-HP-Trace-ID
X-This-Proto
X-HP-Trace-Project
X-Server-Generated
X-Config-By
X-Jphone-Copyright
X-Symfony-Cache
X-IIJ-Cache
X-Trace-Id
SiteSpeed
X-Runtime-Affili
Dis-Env
X-Remote-Addr
X-Time-Microsecs
Ohc-Upstream-Trace
Yoncu-Errno
X-AEM
X-Client-Ip
X-App-Runtime
X-Machine
X-Site
X-Node-Name
X-Cache-CFC
Access-Control-Allow-Method
X-Dynatrace-Js-Agent
AsisCache
X-WP
X-Varnish-Server
X-Cf-Powered-By
X-Smartcache-Timeout
X-Hosting-Env
X-Server-IP
X-SDE-Name
X-Culture
X-Cache-Keep
X-Smartcache-Keys
X-Cache-Detail
X-AutoRu-App-Id
X-Autoru-Host
X-C2M-Server
X-Render-Time
Url
MW-Webserver
X-C2M-Runtime
X-Blog
X-CDN-Forward
OriginServer
Id
Ctx
X-DataDome
X-Varnish-ID
X-Autoru-LB
Set-Cookie2
XDomainRequestAllowed
Machine
Fastly-Backend-Name
X-Esi
Og
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Resource
X-Batcache
X-Cluster-Node
X-Map-Context
Cmstype
Cmsid
ScoreTracker
X-Ser
WP-AdvCache-MemCached
X-Req-Head-Response
X-CacheResult
X-Fedora-School-Id
X-Resty-Request-Id
X-A
X-ASAP-Cache
RN-Server
X-Powered-By-Home.Pl
X-Pageid
X-HP-Redirect
Paypal-Debug-Id
From
SG
X-Dw-Trace-Id
X-Clara-ASAP
X-Bcwwwid
X-MAT-GEO
X-Desc
X-Server-Instance-Name
X-Data-Request
Xc
X-Hstore
X-HA-Backend
X-Page
X-Detected-Device
X-HashTwo
X-HA-Frontend
X-Magento-Action
Hname
Backend-Timing
X-DTC
X-E
X-GSL-Server
X-SCM-Server-Number
X-Analytics
X-Adnet
Myheader
Nginx-Cache
Ttl
Pics-Label
X-Distil-CS
X-Search-Id
Cluster-ID
Strikingly-Cache-Region
X-Ezoic-Cdn
X-Lb
X-Rewrite
X-Amcomm-Site
X-Rq
Expect-Ct
CLMOB
ViewMode
X-Fpc
X-RDP
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Response
X-Phpwcms-Page-Processed-In
X-Cdn-Forward
X-CRA-DC
X-Machine-Name
X-MidCOM-Meta-Cache
X-PageType
X-SV
TC-S-Cache
TC-Cache
TC-Cache-IC
TC-Cache-U
DNNOutputCache
TC-S-Cache-M
X-ACCELERATE
X-Stage
X-Viator-Tapersistentcookie
X-Cache-On
X-Phpwcms-Release
Ibf5scheme
X-Key
N365rili
Sophnep-Edge-FX
X-Turpentine-Esi
W
X-Refresh
Traffic-Origin
X-Proto
Content-Server
CP
X-CACHE-KEY
X-Atg-Version
X-Mobile-URL
X-UA
NS-VaryByCustom-Key
Resin-Trace
Debug-Status
X-SERVER-NAME
VANITY-HOST
MS-CV
X-Info
X-Captured
X-WA-Info
X-Beresp-Ttl
Bios
X-RealServer
X-Airee-Node
X-Vary-Options
X-Obj.Ttl
Worker
X-Cms-Mode
X-Layout
X-Webapp
X-Webstats-RespID
X-Title
X-SO
X-Header
NtCoent-Length
X-Cache-Warmer
X-7d-Instance-Id
Warning
X-Avvio-Cms-Cacheload
X-7d-Trace-Id
X-Agent
X-Application
X-W3TC-Minify
SINA-TS
X-Hrouter
X-Sc-Cache
X-Unique-Id
SINA-LB
SHInfo
X-Actindo-RS
X-Ghost-Cache-Status
X-Cached-Status
X-Backend-Status
Mime-Version
Webluker-Edge
X-AWS
Edgecast
X-OCTOPOD
Response-Time
X-Fstrz
Actual-Object-TTL
X-Pagely-Cache
Access-Control-Request-Headers
X-EC-Lua
X-Dev
X-EC2-Instance-Id
VServer
X-M
X-Flex-Tags
X-Flex-Lastmod
X-Frame-Option
SBMCLOUD
X-Test
X-Hosting
X-MCB-Server
X-Compressed-By
Lb
X-B2f-Not-Route
X-Flex-Lang
X-Flex-Evstart
F5-IpCliente
Gzip
ClientIP
X-Artvisual-Server
DrivedBy
X-Varnish-Cache-Local
Server-Ip
X-Flex-Community
X-Flex-Evend
X-Real-IP
X-Svr
X-Cache-Action
X-V
X-Flex-Tag
X-Depends
X-CDN-RULE
COMMERCE-SERVER-SOFTWARE
RequestId
X-Cacheable-TTL
X-CDN-COMPRESS
X-Cache-Via
X-CACHE-TTL
X-Amz-Id-1
X-Gyrobase-Publication
X-RSL
X-Tag-Playlist
X-Ssl-Cipher
Ibm-Web2-Location
X-ChromeLogger-Data
X-RPM
X-RPS
X-DSS
X-DW
X-PBY
X-KoobooCMS-Version
X-Varnish-URL
X-Middleton-PageSpeed
SERVER-ID
X-Webkit-CSP
X-Drupal-Cache-Contexts
X-Nginx-Request-Time
X-RAMCache
X-Cache-Extended
X-Webkit-Csp
X-APP
Device
X-ReqId
Provider
Ews
X-Varnish-Action
X-Cache-Varnish
PagesDisplayed
X-Sid
X-DB
X-Reflector
Web
X-Reflector-Cache
X-Forwarded-Host
MageStack-Web-Node
X-Cache-TTL-Current
X-Cache-TTL-Age
X-ProcessESI
X-Ezpublish-Installationid
MageStack-Cache-Status
X-RemovedCookies
MageStack-Tag
MageStack-Cache-Lifetime
X-ACLR-Version
X-Plat
X-Frames-Options
X-Domino-CacheValidationWithETagResult
X-Instance-Name
X-Src-Webcache
X-Backend-Name
X-Cache-Time
MageStack-Cache-Hits
X-AMAZEEIO
X-Amz-Meta-Content-Md5
V-Age
X-UnsetCookies
X-Built-With
X-Nginx-Request-Processing-Time
X-MSEdge-Ref
MageStack-Magento-Version
Cache-Tags
X-Proxy-Cache-Key
X-Varnish-VCL
X-VLoc
MageStack-Debug
MageStack-Loadbalancer
Language
X-Node-ID
StatusCode
X-FIRSTBase
MageStack-Cacheable
X-Ezpublish-Nodeid
MSThemeCompatible
MSSmartTagsPreventParsing
X-XHR-Current-Location
X-Varnish-Instance
Httpd-Identifier
MageStack-PageSpeed
X-Meta-Imagetoolbar
X-Domino-CacheValidationWithETagReason
NZSpeedy
X-Enhanced-By
Server-ID
X-Cjtype
X-ManagedFusion-Rewriter-Version
GP-Version
MageStack-Area
X-Rewritten-By
X-Batcache-Reason
MwpReleaseVersion
X-Rocket-Nginx-Serving-Static
X-4ormat-Cacheable
X-Pixelsilk-Server
X-Origin-Cache
X-ASAP-Age
X-NID
X-Pixelsilk-Version
X-PM-ID
GP-Remote-Addr
Hostname
X-AG-MIPS
Container
AGI-Request-ID
Il-Cl
Home
Accept-Language
X-Server-Addr
Proxy-Cache
X-XHTML-Minification-Powered-By
X-DS1D
X-Meta-MSThemeCompatible
X-Sites
X-Apm-Telemetry-Syncmark
X-Serv
X-Restarts
X-Wm-VIP
X-WPL-DATA
X-DN-Cache-Control
MageStack-Config
MageStack-Cache
X-Forwarded-By
X-Cache-Id
X-Generated-Date
X-Wm-1
X-Meta-MSSmartTagsPreventParsing
X-Cms-Server
X-Serendipity-InterfaceLangSource
X-Serendipity-InterfaceLang
X-UseReverse-Proxy
X-Zendesk-Origin-Server
X-Zendesk-User-Id
X-Secret
X-Router-Backend
AR-ATIME
X-FreeTag-Count
X-Provided-By
X-RiS-PX
X-Router
BackendServer
SB-Cache-Life
X-Obj-Ttl
X-NewsFlow-Sitename
X-PBS-Appsvrip
X-PBS-Appsvrname
X-PBS-Fwsrvname
X-Len
X-Catalyst
SB-Site-Device
SB-Cache-Remaining
RSB-LINK
X-Cache-FS-Status
X-CacheID
AR-CACHE
AR-PoweredBy
X-Varnish-Mode
Drupal-Pagecache-Memcache
X-JSESSIONID
X-LBPoolMember
X-WHOIS-Cached
ENV
X-Varnish-Auto-Cache-Miss
X-Deity
X-Cname-TryFiles
X-Made-On
X-Served
X-UPSTREAM-Address
Brightspot-Id
Cleartype
FastCGI-Cache-Status
AMFplus-Ver
Note
Provided-Host
Server-Hostname
X-VID
X-NewCloud-V-Cache
Content-Legth
X-Backend-TTL
X-DI
X-Goog-Meta-Goog-Reserved-File-Mtime
AR-SID
X-PHP-Response-Code
Session-Id
X-PoweredBy
X-MSU-SOURCE
X-SuperCache
X-Uncacheable
Content-Cache
X-VG-WebCache
X-Serverid
X-DDM-SERVER-UPDATED
Hamster
Cache-Ctrol
Requested-Host
Server-Id
X-DDM-SERVER
Kanooh-Host
Progma
X-Server-FQDN
X-PG
X-ServiceProvider
X-Streams-Distribution
X-Nocache
X-Time-Zone
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-HAProxy
X-AppServer-Cache-Rule
UrlWatchModule-Time
X-Country
X-ELB
X-FastCGI-Cache
X-Upgrade-Enabled
X-Clx-Request
X-SH-Cache-Status
VAR-Cache
TP-Cache
X-REDIRECTSERVER
Vserver
X-Container
X-Cluster
X-Box
X-WebNode
TP-L2-Cache
X-DB-Content-Length
X-Srcache-Fetch-Status
X-Lima-Id
X-CSRF-Token
X-Srcache-Store-Status
X-FF
PServer
X-ENV
X-Oracle-DMS-ECID
X-Not-Cacheable
XDisk
X-DSMX-Render-MS
FindLaw
Lookup-Cache-Hit
HA-Ipaddr
X-Obvious-Info
X-Obvious-Tid
Tk
HA-Urlpath
X-Dynamic-Cache
VC-NoCache
X-VC-Debug
HA-Servedtime
Ez
HA-Geolon
X-Dynamic
X-DSMX-Rewrite-MS
X-MainProfileID
X-SRV
X-DeliveryServer
X-Grow-Cache
Apple-Itunes-App
X-HASH
X-Grow-Guest
X-SilverStripe-Cache
X-Tt-Dbg
X-MainProfileName
BlockPHPCallEnd
DB-Nickname
HA-Geolat
X-Bip
X-MainProfileURL
HA-Georegion
X-Faeria
X-Brought-To-You-By
HA-Geocountry
X-DEBUG-TTL
HA-Cloudapp
X-MainProfileCategory
HA-Geocity
HA-Host
X-Archive-Orig-Server
X-AISO-Cache
X-Archive-Guessed-Charset
X-ACache
Server-Node
DeleGate-Ver
Memento-Datetime
WebServer
Type
Accept-CH
X-Varnish-Cached-TTL
X-Archive-Orig-Connection
Origin-Content-Encoding
Session-From
Proxy-Agent
X-Vol-Mrp
X-Vol-Correlation
X-AISO-Server
Debug-Cache-Control
CD4
X-PvInfo
X-ETag
X-Cache-V
Debug-Expires
LCache
X-Requestid
X-Varnish-Grace
X-RequesterIP
Returned-Status
X-AISO-Cacheable
X-Archive-Orig-Content-Length
X-Archive-Orig-Date
Redkiwi-Cloud
NKBVHEADER
X-UUID
X-Request-Received
X-B3-Spanid
X-Request-Processing-Time
Www.Aujourdhui.Com
Load-Balancer
L5d-Success-Class
X-Varnish-Max-Age
X-Max-Age
X-AppVersion
X-W-Cache-Hits
X-Pubstack
X-IP
X-Hcom-Origin-Id
X-Group
X-Hcom-Styx-Info
X-MCF-ID
X-Varnish-Cached
X-Sn-Servicetimems
X-Archive-Orig-ETag
X-CGP
X-Built-By
X-Content-Parsed-By
X-B3-Traceid
X-Nginx-Page-Cache
X-Cache-Origin
IES-Server
X-TargSmaku
X-Varnish-Store
X-Varnish-Set-Cookie
Cache-Status
X-FORWARDED-PROTO
X-Highwire-Sitecode
X-Cache-Why
X-Varnish-Esi-Method
X-Varnish-Esi-Access
X-UType
X-GRACE
X-Netrix-ID
X-Turpentine-Cache
X-Varnish-Currency
X-Highwire-Smart-Code
X-Instance
X-BPool-Back
X-BPool
X-BPool-Bx-Cache
X-BPool-Fx-Cache
X-BServer
X-BC
TheAnswer
X-Origin-Server
X-NodeID
X-Pass-Through
AC-ELC
Aurora-Node
Unique-Request-Id
Copyright
X-Cachable
PB-RID
X-CH-Device
X-Count
X-Pool-Info
PB-PID
LB
EQ-Cache
Aoestatic
X-Magento-Lifetime
X-Varnish-Debug-Hits
X-Xrds-Location
X-Powered-Developer
X-Rack-CORS
Referer-Policy
XX
X-Geo-IP
X-Scache
X-Skip-Cache
X-Status
X-LOCATION
Developer
X-Transaction-Name
MachineName
ReqUrl
X-COUNTRY-CODE
X-Gannett-Site-Version
X-NMT-Proxy
X-Processed
X-Pj-Cache-Status
X-SCProxy
Application
Prototype-RootPath
IsMobile
X-Ocache
X-Imforza-Hosted
X-Cache-HT
X-Cache-BE
X-Cache-LB
X-Csrf-Token
X-Debug-Message
X-Accel-Cache-Control
X-App-Version
X-IP-Address
X-Front-Cache
X-No-Session
X-Tradeindia-Request-GUID
X-Tradeindia-SMgmt
WFE
SB-Site-IE-VERSION
X-FRUIT
X-Cache-Me-Harder
CommunityServer
Fw-Cache-Status
RSL-Trace-ID
X-Amz-Meta-Version-Id
Tempo
EagleEye-TraceId-Daily
X-Reason-Bp
INFO
X-Beatles
X-Beatles-Hits
X-Name
MageStack-Response-Ttl
X-Static
X-Protected-By
Ina-Bwaf
MageStack-Cache-Warning
MageStack-Cacheable-Reason
X-Cache-ID
X-Cache-Set
X-TTL-Age
X-Ss-Location
X-Would-Your-GrandPa-Wait
X-Your-GrandPa-Would-Wait
GranicusServer
X-Ss-Conf
X-NO-BREACH
X-Content-Type-Option
X-CCM
X-Does-He-Have-Time
X-Goog-Meta-Policy
X-Goog-Meta-Replace
X-W-Cache