Threat Level: green Handler on Duty: Remco Verhoef

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
X-AspNet-Version
Age
P3P
X-Pingback
Content-Language
Via
X-UA-Compatible
Expect-CT
Upgrade
Access-Control-Allow-Origin
X-Adblock-Key
Content-Security-Policy
X-Cacheable
X-Check
X-Language
X-Template
X-Varnish
X-Request-Id
X-Xss-Protection
Alt-Svc
X-Generator
X-Buckets
X-Drupal-Cache
P3p
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-Powered-By-Plesk
Content-Location
Host-Header
X-Runtime
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Dc
X-Sorting-Hat-Section
X-ShardId
X-Sorting-Hat-PodId-Cached
X-Alternate-Cache-Key
MS-Author-Via
Referrer-Policy
X-UA-Device
Cartoon
X-Powered-CMS
X-IPLB-Instance
X-Served-By
X-Amz-Cf-Id
Access-Control-Allow-Headers
X-Cache-Status
Status
Access-Control-Allow-Credentials
Access-Control-Allow-Methods
X-Via
X-Ua-Compatible
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Wix-Server-Artifact-Id
X-Contextid
X-ServedBy
CF-Cache-Status
X-Backend
X-PC-Key
X-PC-Hit
Powered-By
X-Mod-Pagespeed
X-Accel-Buffering
X-PC-Host
X-PC-AppVer
X-PC-Date
Content-Encoding
X-CST
X-WPE-Loopback-Upstream-Addr
X-DIS-Request-ID
X-Logged-In
X-Host
Keep-Alive
X-CDN
X-Rid
X-Cache-Hit
X-Port
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Cache-Enabled
X-Server-Powered-By
X-Tumblr-Pixel-1
X-Endurance-Cache-Level
X-Server
X-Nginx-Cache-Status
X-Robots-Tag
X-Original-Date
X-Accel-Version
X-Seen-By
X-Wix-Request-Id
X-Tumblr-Pixel-2
X-Page-Speed
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Content-Powered-By
X-Pad
X-Content-Digest
X-Forwarded-For
X-Proxy-Cache
X-Wix-Punisher
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rack-Cache
X-AH-Environment
WP-Super-Cache
X-NewRelic-App-Data
X-Sorting-Hat-PrivacyLevel
X-Forwarded-Proto
X-Varnish-Cache
X-Tumblr-Pixel-3
Content-Security-Policy-Report-Only
X-GitHub-Request-Id
X-LiteSpeed-Cache
Edge-Control
SPRequestGuid
X-Request-Country
X-SharePointHealthScore
X-MS-InvokeApp
MicrosoftSharePointTeamServices
X-XRDS-Location
Timing-Allow-Origin
X-Cache-Lookup
X-Cnection
X-SERVER
X-Node
X-Newrelic-App-Data
X-Amz-Request-Id
X-Amz-Id-2
X-FW-Hash
Cf-Railgun
X-Died
X-Trace
X-Webcom-Cache-Status
X-Content-Security-Policy
Charset
X-FW-Serve
X-FW-Static
X-FW-Type
X-FullPageCaching
X-Webserver
Request-Id
Edge-Cache-Tag
X-CF-Powered-By
X-HS-Cache-Config
X-HS-Content-Id
X-PhApp
X-Hits
MicrosoftOfficeWebServer
Request-Context
X-PHP-Backend
SPIisLatency
X-BC-Stapler
SPRequestDuration
X-Safe-Firewall
Access-Control-Max-Age
X-INKT-URI
X-INKT-SITE
EagleId
X-Swift-CacheTime
X-Swift-SaveTime
Composed-By
Grace
Access-Control-Expose-Headers
X-CDN-Pop
Served-By
X-CDN-Pop-IP
X-HS-Combine-CSS
X-Hyper-Cache
Liferay-Portal
X-Spip-Cache
X-Tumblr-Pixel-4
X-VCache
X-Server-Name
X-Backend-Server
X-Dw-Request-Base-Id
X-Device
X-Fastly-Request-ID
X-Microcache
X-Firenze-Processing-Times
X-RateLimit-Remaining
X-RateLimit-Limit
X-Cloud-Trace-Context
X-LiteSpeed-Cache-Control
X-Clacks-Overhead
Front-End-Https
X-FB-Debug
X-RateLimit-Reset
Rating
X-TNCMS
X-Loop
Content-Style-Type
X-Jimdo-Instance
X-Jimdo-Wid
Surrogate-Control
Xkey
X-ServerName
Content-Script-Type
X-Acc-Exp
X-DDC-Arch-Trace
X-User-Agent
Public-Key-Pins
Refresh
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Display
X-DNS-Prefetch-Control
X-Cache-Config
X-Vtex-Processado-Em
X-StackifyID
Fpc-Cache-Id
X-Frame-Option
X-XN-Trace-Token
X-XN-XNHTML
X-Age
X-Tumblr-Content-Rating
Real-Hostname
X-Hostname
X-SS-Location
X-SS-Conf
X-WebKit-CSP
X-Generated-By
X-Px
X-Request-ID
X-Cached
X-Zen-Fury
X-N-OperationId
X-Tumblr-Pixel-5
X-Topify-Platform
X-Dscp-Value
X-Correlation-Id
X-Magento-Tags
X-Request-Time
X-HOST
X-MiniProfiler-Ids
P-LB
P-WS
X-OneAgent-JS-Injection
PageSpeed
X-Amz-Version-Id
X-Url
TCN
X-CMS-Version
X-Whom
Rt-Fastcgi-Cache
X-Msg-2-Log
X-Handled-By
X-URL
X-Cached-By
X-From
X-DynaTrace-JS-Agent
X-DynaTrace
X-Outils-CS
X-Kinsta-Cache
X-B-Cache
Access-Control-Request-Method
X-Ruxit-JS-Agent
Product
X-AspNetWebPages-Version
X-Content-Options
X-Edge-Location
X-Debug-Info
X-Varnish-Cache-Hits
ServedBy
X-Cache-Rule
X-Varnish-TTL
X-Engine
X-Via-JSL
Host
Surrogate-Key
Powered
X-Cdn
Imagetoolbar
Public-Key-Pins-Report-Only
X-Upstream
Fhost
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Edge-Control-Message
DynaTrace
X-CacheServer
X-Application-Context
Alternate-Protocol
X-VTEX-Janus-Router-Backend-App
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
X-Powered-By-VTEX-Janus-ApiCache
No
X-Recruiting
X-Location-Id
X-Accel-Expires
X-LBLID
X-Developer
X-VARNISH-Cache
X-LW-Cache
X-Signature
X-Umbraco-Version
X-Track
X-Fastcgi-Cache
X-Platform
X-Goog-Hash
Pagespeed
X-Response-Time
X-Micro-Cache
X-Platform-Router
X-Hosted-By
X-Platform-Processor
X-Original-Request
X-Actual-URL
X-Passed-To
X-Returned-From-DLL
X-Passed-To-DLL
Fastcgi-Cache
X-Returned-From
X-Shop-Id
X-Defender
X-Magento-Cache-Debug
Generator
X-Platform-Cluster
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Returned-From-BeforeDispatch
X-Varnish-Beresp-Grace
X-Returned-From-PostProcessResponse
Retry-After
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Powered-By-VTEX-Janus-Edge
X-ApacheServer
X-Cache-Age
X-UD-Method
Arr-Disable-Session-Affinity
X-PERF
X-Stale
Dmn
X-Source
X-Rnd
X-Cache-TTL
X-NWS-LOG-UUID
X-TransIP-Balancer
WZWS-RAY
X-Powered-By-360WZB
X-BS
X-Loopia-Node
X-I-Sp
HTTPS
X-Instart-Request-ID
X-Cache-Info
X-Device-Type
X-Version
Origin
Akamai-IP
X-URLSCHEME
X-Microcachable
X-Litespeed-Cache
X-Varnish-Host
X-Supported-By
X-RESOURCE
X-TransIP-Backend
X-HS-Content-Campaign-Id
X-Dispatcher
Ohc-File-Size
X-FORWARDED-FOR
Cache-Provider
X-F-Cache
Content-Hash
X-Tumblr-Pixel-6
X-Storage
X-Rocket-Nginx-Bypass
Fastly-Debug-Digest
X-Cache-Key
Version
X-S
X-I
X-Varnish-Count
X-Varnish-HitMiss
X-Cache-Operation
X-Front
X-Platform-Server
X-Pantheon-Environment
USPLoggingUUID
X-Pantheon-Site
X-Cache-Tags
X-Pantheon-Phpreq
Surrogate-Key-Raw
X-Server-ID
RTSS
X-NetCat-Version
X-App-Hosting
X-Gamma-Serve
X-ATG-Version
X-Matrix-Server
X-EdgeConnect-Origin-MEX-Latency
X-Matrix-Proxy
X-Page-Cache
X-Microcache-Status
X-Translation
X-Expires-Orig
X-Powered-By-VelaWeb
Last-Published
X-Platform-Cache
X-Vcap-Request-Id
X-Director
X-ORACLE-DMS-ECID
X-Ezoic-Cdn
X-Varnish-GracePeriod
X-Shard
X-CSRF-Protection
X-Varnish-ObjectSource
X-Art-Request-Id
X-Sapient
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Varnish-RemainingLife
X-Cache-Namespace
MIME-Version
Allow
X-Cluster-Node
X-Hypernode
X-Route-Server
X-Content-Encoded-By
X-Varnish-Age
X-Server-Upstream
X-Revision
X-LB
X-Environment
X-LB-Node
X-SSL-Cipher
Wsr-Cache
X-Ttl
X-EdgeConnect-MidMile-RTT
X-SSL-Protocol
Powered-By-ChinaCache
Content-Disposition
Cache-Key
X-Flow-Powered
X-Abgroup
Pool
IBM-Web2-Location
X-IsCacheURL
X-ARC
X-Varnish-Cacheable
X-NoCache
X-Edge-IP
X-Litespeed-Cache-Control
X-Daa-Tunnel
X-Grace
X-Drupal-Cache-Tags
X-SV-Expires
X-SV-Edge
X-Cache-Debug
X-SV-FromDBCache
X-SV-Nginx-Duration
X-SV-Duration
X-SV-Pid
X-SV-CacheTags
X-Firenze-Processing-Time
X-SV-Cacheable
X-Lambda-Id
X-SV-CreatedAt
Content-MD5
X-Url-Base
Accept-Encoding
SSPAppContext
X-Xrds-Location
X-Github-Request-Id
S-Cnection
X-Dispatch
Srv
X-Nginx-Cache
X-Cache-Control-Orig
X-Magento-Cache-Control
X-CJ-Soft
FAI-W-FLOW
X-Cache-Only-Varnish
X-GeoIP-Country-Code
Lsrequestid
X-Cache-Lifetime
Cneonction
Page-Completion-Status
Section-Io-Id
ServerID
X-Servedby
Content-Encoding-Handler
X-Cache-Server
X-Varnish-Backend
X-Cache-Type
X-Varnish-Url
Backend
X-Vhost
X-Cache-Expires
X-Time
X-Generated
X-Drupal-Cache-Contexts
Pv
X-Hiawatha-Cache
X-Ss-Conf
SN
X-Varnish-Ttl
X-Ss-Location
Location
Fw-Via
X-RequestId
X-PwB-Node
X-Duration
Proxy-Connection
Node
X-Amz-Meta-S3cmd-Attrs
X-ServerID
X-Debug
PICS-Label
X-Client-IP
X-Proxy
X-AOL-HN
ServerName
Nodo
X-Speed-Cache-Key
X-Speed-Cache
X-Akamai-Transformed
X-Fastly-Request-Id
X-Middleware-Start
X-Magnolia-Registration
X-N
X-SO
AMF-Ver
X-Server-Id
X-Varnish-IP
X-FW
Use-Proxy
If-Modified-Since
X-GeoIP-Country-Name
X-Nbs
Server-Info
X-Real-Server
X-Cookie-Domain
X-Country-Code
X-Discourse-Route
X-Cache-CFC
X-Geo-Country
X-DealerOn
X-Processing-Time
X-Pressidium-NinukisWP-Ver
X-Location
X-ID
X-Purge-URL
Req-Id
X-Cache-Level
X-Frontend
NnCoection
X-Akamai-Device-Model
Server-Name
X-Empowered-By
X-Goog-Generation
X-GUploader-UploadID
X-Worker
X-Oneagent-Js-Injection
X-Akamai-Device-Characteristics
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-UPSTREAM
X-Always-Cache
X-Goog-Metageneration
X-Cache-Handler
X-Goog-Stored-Content-Encoding
X-Cache-Engine
X-Cache-Device-Type
X-SRCache-Key
Cache
X-Cache-Fix
X-Config-Blacklist-Version
IM-Version
X-Dynatrace-Js-Agent
X-Cache-PageType
X-ORACLE-DMS-RID
X-Content-Age
X-Purge-Host
P-ID
X-Yadis-Location
Local-Info
SEOMOZ
Pf.Web.Request.Id
MJ12bot
Xc-Version
X-Browser
X-Cache-Control
Accept-Charset
Nitro-Cache
X-BackendServer
X-PF-Uncompressing
Author
X-Varnish-Retries
X-CF-Passed-Proto
X-High-Performance
X-Content-Type-Option
X-App-Server
Cached
X-Runtime-Rack
X-Correlation-ID
X-ACMCache
Qs-Cache
X-Sentry-ID
X-Amz-Storage-Class
X-WR-Flags
X-Server-Instance
Content-Transfer-Encoding
X-Esi
X-Srv
X-Unbounce-PageId
X-Unbounce-Variant
X-Unbounce-VisitorID
X-Rocket-Nginx-Serving-Static
X-Id
X-Last-Modified
X-BKSrc
X-Framework
X-Hit-Cache
X-Abuse
X-Pagename
X-JG-Page-Cache
X-CDN-Forward
SRV
X-OpenCart-Lightning
Front
X-SDS
Thanks
X-TTL
HCVer
HAVer
X-Server-IP
Cteonnt-Length
Adm-Server
X-Runtime-Memory
NODE
Server-Timing
X-Origin
S
X-AF-Userserver
X-ClientSide-Caching
CacheControlHeader
Cm-Server
X-Content-Security-Policy-Report-Only
X-NB-Cached-Page
X-Mobilized-By
Eomportal-Instance
Custom-Header
Frame-Options
X-VARITI-CCR
NtCoent-Length
X-Ruxit-Js-Agent
MC
X-Sucuri-ID
X-Dns-Prefetch-Control
X-FTR-Request-ID
Cache-Tags
X-WPL-DATA
X-Rq
X-Session-ID
X-CAPServer
ServerTokens
X-AEM
ServerSignature
X-HTML-Minification-Powered-By
X-Varnish-Hits
Magicmarker
X-HW
X-Adobe-Content
X-Adobe-Loc
SiteSpeed
WWW-Authenticate
X-Processed-By
X-DEBUG
X-Shield-Request-Id
NetMindSessionID
X-VTEX-Cache-Status-Janus-Edge
X-LB-Server
X-Fedora-School-Id
X-Resty-Request-Id
Cache-Tag
Ufe-Result
X-WN-ClientGroup
X-Orig-Vary
X-Page
WN
Tracecode
X-SRV
SVR
X-LP
X-Cache-Dispatchercachecontrol
Content_type
X-Env
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Cache-Dispatcherpragma
X-Trace-Id
W
X-Sys-Req-ID
X-Gateway-Skip-Cache
X-LW-Web-Server
X-Jphone-Copyright
Contao-Page-Layout
EagleEye-TraceId
X-Garden-Version
Yoncu-Errno
X-Route-To
VServer
X-Webkit-CSP
X-HydroSheep
X-CB-Server
Proxy-Agent
X-Traffic
X-Smartcache-Keys
X-WP
X-Smartcache-Timeout
X-Transaction
X-Twitter-Response-Tags
X-Varnish-Hostname
Keywords
X-Yottaa-Optimizations
Description
Smug-CDN
BALANCEDTO
X-A
Web-App-Origin-Name
X-ASAP-Cache
Server-ID
Max-Age
X-ServerIndex
X-Yottaa-Metrics
X-Connection-Hash
RN-Server
X-Drectory-Script
X-Clara-ASAP
X-Unique-ID
X-Generated-Time
X-TTFB
X-Client-Vid
X-TTFB-L
X-SmugMug-Values
X-EPiphany-Vid
X-Client-Image-Vid
X-SmugMug-Hiring
A-Powered-By
Environment
From-Origin
ScoreTracker
VANITY-HOST
Noq
X-Redman-Backend
X-Symfony-Cache
X-Redman-Final-Url
Ramp
AsisCache
X-Akamai-Edgescape
X-WA-Info
X-AVG-Country-Code
Ram
X-Compress-Hint
X-Sorting-Hat-Expire-Cache
X-Cache-Doesi
X-Avg-Cookie-Expires
X-SDE-Name
MW-Webserver
X-Hosting-Env
X-Plat
X-Response
X-Webstats-RespID
X-Varnish-Debug-TTL
Og
Pics-Label
SG
X-Disney-Akamai-Rule
X-ARRServer
X-Varnish-Debug-Age
X-Rebelmouse-Cache-Control
X-Application
X-RDP
X-GeoIP
X-Environment-Context
X-L-Path
X-Rebelmouse-Surrogate-Control
X-Force
X-Cache-On
IISExport
X-PRAM
X-CRA-DC
SBGI-RealPath
Play-Detected-UserAgent
Play-Detected-Device
X-Cache-Node
Service-Worker-Allowed
Access-Control-Allow-Header
X-Sucuri-Cache
Ibf5scheme
Cmsid
Cmstype
SBGI-RenderTime
Machine
X-VC-Enabled
SBGI-Device
SBGI-9
SBGI-10
X-WebKit-CSP-Report-Only
SBGI-5
SBGI-1
X-Varnish-Id
X-Stage
N365rili
X-VNode
SBGI-7
Fastly-Backend-Name
X-RiS-UFDI
X-Viator-Tapersistentcookie
X-SV
HitType
X-Cache-Varnish
X-Proto
X-Magento-Action
X-Resource
X-VC-TTL
X-NginX-Server
X-GoCache-CacheStatus
X-Bip
X-Backend-Status
X-CacheResult
X-Vcache
Dispatcher
Beyond-Iis
Url
X-Forwarded-Host
X-Cdn-Forward
AC-ELC
X-AutoRu-App-Id
X-Autoru-Host
X-Autoru-LB
X-Frames-Options
X-Cocoon-Version
X-Amz-Meta-Cb-Modifiedtime
X-Airee-Node
X-App-Status
X-Amz-Meta-Content-Md5
X-App-Runtime
X-Lb
RequestId
X-Fstrz
SHInfo
X-Culture
XX
X-Desc
X-Varnish-ID
X-Amz-Meta-S3b-Last-Modified
X-Secret
X-Key
Dis-Env
X-Directory-Script
X-Detected-Device
X-Src-Webcache
X-Acquia-Debug-Password
Ctx
X-Cms-Mode
X-Dev
X-Goog-Meta-Goog-Reserved-File-Mtime
Worker
X-PHP-Response-Code
X-Analytics
X-Varnish-Server
From
X-Rack-CORS
X-Balanceador
X-Runtime-Affili
XDomainRequestAllowed
X-FireWall-Port
X-Highwire-SessionId
X-Highwire-RequestId
X-Varnish-Action
X-Redirector
X-Provisioner-Version
X-Real-IP
X-Request-Uri
X-IIJ-Cache
X-TB-M
X-WHOIS-Cached
X-Domain-Checked
X-Time-Microsecs
X-SmartBan-URL
X-Dw-Trace-Id
Home
X-Session-Reinit
X-SmartBan-Host
Backend-Timing
X-E
Hostname
X-Origin-Server
Nginx-Cache
WP-AdvCache-MemCached
Accept-Language
X-Source-ID
Identity
X-EC2-Instance-Id
COMMERCE-SERVER-SOFTWARE
X-Atraveo-Cache-Control
Bios
X-Atraveo-ETag
Access-Control-Allow-Method
X-Atraveo-Expires
X-Atraveo-From-Varnish-Cache
SS
X-Atraveo-Zone
X-Atraveo-TTL
X-Atraveo-Varnish-Server-Id
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
Web
X-Info
X-AISO-Cache
X-Wikidot-Static-Cache
X-MCB-Server
X-Flex-Community
X-Flex-Evstart
X-Grid-Server
X-Flex-Evend
Ec-CorrId
X-Wikidot-Backend
X-Data-Request
X-Bcwwwid
X-AISO-Server
X-Hosting
X-ACCELERATE
X-AISO-Cacheable
X-Compressed-By
Disablevcache
Id
Myheader
X-Rewrite
X-MAT-GEO
X-Adnet
TC-S-Cache-M
X-RealServer
X-LDNR-NOT-ROOT-HL-NOTSET
X-Resolver-IP
X-Sites
Hname
X-Confluence-Request-Time
X-Origin-Cache
X-Distributor
X-Debug-Token
X-HAProxy
X-Machine
X-GSL-Server
TC-Cache
X-Streams-Distribution
X-DTC
X-Depends
X-FPC
X-Node-Name
X-Pubstack
X-Cache-Via
TC-S-Cache
Paypal-Debug-Id
TC-Cache-IC
NLCacheNote
TC-Cache-U
Ec-Machine
X-Flex-Tag
X-B2f-Not-Route
F5-IpCliente
X-HashTwo
X-Flex-Lang
X-Aramark-SID
X-Mobile-URL
Xc
Il-Cl
Proxy-Cache
X-Cluster
X-DB-Content-Length
X-Render-Time
X-Varnish-Cache-Local
X-MidCOM-Meta-Cache
X-HP-Trace-Project
ClientIP
X-Ghost-Cache-Status
X-Goog-Meta-Policy
X-Goog-Meta-Replace
X-OPNET-Transaction-Trace
Gzip
X-Req-Head-Response
X-Search-Id
X-NginX-Cache
X-Dealeron-Backend
X-Nginx-Host
X-Map-Context
X-Flex-Lastmod
X-Flex-Tags
Device
X-Amcomm-Site
SERVER-ID
X-HP-Trace-ID
X-Remote-Addr
X-Refresh
Traffic-Origin
X-Dealeron-Original-Url
AMP-Access-Control-Allow-Source-Origin
OriginServer
X-ETag
X-Magento-Lifetime
X-Cache-TTL-Remaining
X-Akamai-3PM-SW-Version
VC-NoCache
X-Distil-CS
X-SERVER-NAME
X-Pagely-Cache
X-NID
X-Avvio-Cms-Cacheload
X-KoobooCMS-Version
X-SH-Cache-Status
CLMOB
TP-L2-Cache
Hummingbird-Cache
TP-Cache
X-ESI
X-Cache-Extended
Strikingly-Cached-Version
X-Author
Strikingly-Cached
Strikingly-Cache-Region
X-Batcache
Aoestatic
X-4ormat-Cacheable
X-DataDome
X-ASAP-Age
X-Protected-By
Server-Id
X-HS-Status
Lb
X-Powered-By-Home.Pl
Upgrade-Insecure-Requests
X-App
X-V
X-DN-Cache-Control
X-DSMX-Render-MS
NS-VaryByCustom-Key
PagesDisplayed
Content-Generator
X-Gyrobase-Publication
X-DSMX-Rewrite-MS
X-DynamicCache
X-Node-App
OracleCommerceCloud-Version
Ohc-Response-Time
X-CACHE-TTL
X-Omnis-SiteID
X-Amz-Id-1
OracleCommerceCloud-Sandiego
X-IP
CommercePlatform-Version
Accept-CH
Ez
X-Proxy-Cache-Key
X-NodeID
X-Gannett-Site-Version
X-Proxy-Skip
X-Country
X-LBPoolMember
Copyright
X-CacheID
X-Agent
X-Header
X-Nitro-Cache
X-OCTOPOD
X-Served-Server
X-PM-ID
Ews
X-ServiceProvider
Cleartype
X-Tag-Playlist
Progma
BackendServer
X-7d-Trace-Id
X-Client-Ip
X-7d-Instance-Id
X-Box
FRONT-END-SECUREBROWSER
X-Backend-Host
X-Sid
X-DDM-SERVER
X-Rack-Cors
Kanooh-Host
Actual-Object-TTL
X-Captured
X-DDM-SERVER-UPDATED
X-SuperCache
Response-Time
X-Config-By
X-Zendesk-User-Id
PServer
X-Hit
X-Zendesk-Origin-Server
Server-Ip
X-Nginx-Request-Processing-Time
X-Pj-Cache-Status
X-Batcache-Reason
X-ManagedFusion-Rewriter-Version
X-Serv
Ttl
X-HP-CAM-COLOR
X-Cache-Keep
X-Server-Addr
NZSpeedy
X-Cache-Detail
X-Reflector-Cache
X-Reflector
X-Rewritten-By
X-D-Time
Y-Trace
MS-CV
X-Generation-Time
X-Served
Tesla.Performance
Generate-Time
Z-Tpl
Viewport
X-RAMCache
X-Phpwcms-Release
X-REDIRECTSERVER
X-Phpwcms-Page-Processed-In
X-Hash
X-Amz-Meta-Version-Id
Swift-Performance
X-SE-Debug
X-VG-WebCache
ViewMode
UrlWatchModule-Time
No-Cache
Content-Cache
X-Via-NSCOPI
X-Activity-Id
X-AppServer-Cache-Rule
X-S-C
X-CloudBurst-WordPress
X-S-V
X-Cname-TryFiles
Amp-Access-Control-Allow-Source-Origin
Hamster
X-CSRF-Token
X-CloudBurst-Frontend
X-CloudBurst-Cache
X-Transaction-Name
X-Cache-ID
X-Cache-Time
X-CloudBurst-Backend
X-Beatles
X-Debug-Token-Link
X-Deity
X-Built-With
X-HEAD
X-Q-S
X-Header-Treatment
Cache-Status
X-Made-On
X-Catalyst
X-Domino-CacheValidationWithETagResult
X-CDN-RULE
X-Domino-CacheValidationWithETagReason
X-CDN-COMPRESS
ID
TZ-Server
X-S-Misc
Requested-Host
MageStack-Web-Node
MageStack-Tag
MageStack-PageSpeed
X-Cache-Me-Harder
Tk
AR-PoweredBy
AR-CACHE
MageStack-Magento-Version
MageStack-Loadbalancer
X-Hstore
MageStack-Cacheable
MageStack-Cache-Warning
X-Hrouter
X-Container
MageStack-Debug
MageStack-Config
AR-SID
Provided-Host
X-Middleton-Pagespeed
X-CH-Device
X-Nginx-Request-Time
X-Instance-Id
Session-Id
CommunityServer
ProxiaInstanceId
X-Cachable
X-RiS-PX
X-WebNode
Fastly-Restarts
X-UPSTREAM-Address
X-HeBS-Cache-Status
X-Beresp-Ttl
X-B
MageStack-Cache-Status
X-I-V
X-JSESSIONID
X-Obvious-Tid
X-HA
X-Middleton-PageSpeed
X-Obvious-Info
X-M-V
X-Mw-Workerstats
X-FastCGI-Cache-Status
FindLaw
AR-ATIME
X-Az
X-FIRSTBase
X-Debug-Message
X-Pageid
X-Pool-Info
X-Serverid
X-UA
X-MainProfileCategory
MageStack-Area
Key
X-Instart-Cache-Id
MageStack-Cache
MageStack-Cache-Lifetime
MageStack-Cache-Hits
X-MainProfileID
X-M-P
X-T
X-UT-Cache
X-M-T
X-MainProfileURL
X-MainProfileName
Amfplus-Ver
X-AppVersion
Cacheid
X-FG-RequestId
X-Enhanced-By
X-NO-BREACH
X-ReqId
X-Timestamp
X-SilverStripe-Cache
X-DS1D
SB-Site-Device
Debug-Status
X-Unique-Id
MachineName
Page-Template
SB-Cache-Remaining
SB-Cache-Life
DeleGate-Ver
Provider
X-UnsetCookies
X-SCM-Server-Number
X-Varnish-Grace
X-Webcelerate
X-ZSITES-DNS
X-Who
X-PROCESSED-BY
X-PBY
X-Artvisual-Server
X-AMAZEEIO
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-Pass-Through
X-Secure
X-Nginx-Page-Cache
X-Time-Zone
X-ServerAddr
X-UPServer
X-Varnish-Cached
X-Varnish-Instance
X-Varnish-Cached-TTL
X-Server-FQDN
X-Script
Warning
X-Machine-Name
Webserver
X-Proxy-Id
X-MCF-ID
X-ELB
X-VLoc
X-Apm-Telemetry-Syncmark
X-Cache-Bypass
StatusCode
X-CO-Host
X-Meta-Imagetoolbar
X-Meta-MSThemeCompatible
X-Meta-MSSmartTagsPreventParsing
Session-From
ServerIP
CmsfirstPublishTimestamp
Arrnode
EN-User
MSSmartTagsPreventParsing
MSThemeCompatible
DrivedBy
X-XHR-Current-Location
X-Turpentine-Esi
GranicusServer
X-VC-Cache
EQ-Cache
X-VC-Cacheable
HostName
X-Title
X-BServer
X-BPool-Fx-Cache
X-Cacheable-TTL
X-Layout
X-Static
X-VC-Debug
Control-Cache
X-Custom-Header
X-Cache-Original-TTL
X-Full-Url
X-Svr
X-Route
X-Cache-Id
X-ACLR-Version
X-VC-Hash
X-W3TC-Minify
CpuTime
User-Agent
X-BPool-Bx-Cache
X-Cjtype
X-BPool-Back
X-BPool
RSB-LINK
TheAnswer
Language
X-Blog
FastCGI-Cache
X-Pixelsilk-Server
X-FORWARDED-PROTO
X-Pixelsilk-Version
X-Akam-SW-Version
X-HOSTNAME
X-Site
X-Uncacheable
CDCHOST
X-Theme
Xcache
X-Member
X-Ants-Machine-Id
HA-Cloudapp
HA-Geocity
X-NMT-Proxy
DNNOutputCache
DB-Nickname
X-PG
X-RequesterIP
BlockPHPCallEnd
X-Ants-Host
Head
X-Test-Debug
X-CPU-Time
X-Dynamic-Cache
X-Cache-TTL-Current
X-SH-Cache-Disabled
Expiries
WP-FROM-CACHE
X-Cache-TTL-Age
X-Old-Content-Length
WSCLoggingUUID
Serverid
CS-SERVER
Countrycode
X-RemovedCookies
X-ProcessESI
X-Instance
X-MSEdge-Ref
X-Distributed-By
X-Backend-Name
X-Prerender-Token
X-SSLProxy
X-SSLUpstream
X-Svr-Proxy
X-PBS-Fwsrvname
X-PBS-Appsvrname
X-MyName
X-NewsFlow-Sitename
X-PBS-Appsvrip
X-WR-MODIFICATION
X-Geo-IP
DbServerName
Rewriter
X-Server-Hostname
X-BackendProxy
CD4
X-Locale
X-Skip-Cache
X-Beatles-Hits
X-CACHE-KEY
X-Healthy
X-Cache-FS-Status
X-ClusterID
X-Prerendered
X-Reason-Bp
X-Ao-Cache-Key
HA-Geocountry
V-Age
X-XHTML-Minification-Powered-By
TestCC
X-Cache-Set
X-Gateway-Rate-Limit-Conn
X-Gateway-Rate-Limit-Delayed
Referer
Powered-By-115
ReqUrl
X-Proxy-Backend
Request-Filtered-By
X-M
X-Origin-Date
X-Varnish-Debug-Hits
X-Varnish-Cache-Ttl
X-DEBUG-TTL
X-Max-Age
X-Optimization
Returned-Status
X-This-Proto
SB-Site-IE-VERSION
X-Fastly-Backend-Reqs
X-Cache-LB
X-Session-Id
X-Restarts
MwpReleaseVersion
PB-RID
X-Cache-V
X-TTL-Age
X-TLS-Version
X-Would-Your-GrandPa-Wait
X-Your-GrandPa-Would-Wait
Container
PB-PID
X-Test
X-Status
Note
X-Processed
X-Request-Received
X-Request-Processing-Time
X-Mobile-Rewrite
X-Ssl-Cipher
X-Say-Cacheable
X-SCProxy
X-SayCDN-TTL
X-Say-TTL
SINA-LB
SINA-TS
Www.Aujourdhui.Com
X-ACache
User-Cache-Control
X-BIT-Node
X-Built-By
X-K8s
V-TTL
X-Cache-ASPX
Realaction
Actioncode
Load-Balancer
X-MSU-SOURCE
L5d-Success-Class
IES-Server
X-ENV
X-DeliveryServer
X-Clx-Request
X-DEBUG-HOST
Edgecast
X-PoweredBy
HA-Urlpath
HA-Georegion
HA-Geolon
Apple-Itunes-App
HA-Host
X-Upgrade-Enabled
HA-Servedtime
HA-Ipaddr
X-Tt-Dbg
NKBVHEADER
Server-Hostname
X-Sn-Servicetimems
Resin-Trace
VAR-Cache
X-Server-Instance-Name
Be
Arrow-RequestId
X-Does-He-Have-Time
X-DevSrv-CMS
Access-Control-Request-Headers
X-Server-Generated
X-Homeaway-Requestmarker
X-Olaf
X-Upstream-Status
X-B3-Spanid
X-B3-Traceid
X-Cacheable-By-Varnish
X-Fpc
Redirect-Reason
X-CGP
HA-Geolat