Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
X-Cache
Strict-Transport-Security
X-AspNet-Version
P3P
CF-RAY
X-Pingback
Age
Content-Language
X-UA-Compatible
Via
Access-Control-Allow-Origin
X-Adblock-Key
Upgrade
X-Varnish
X-Cacheable
X-Check
X-Template
X-Language
P3p
Content-Security-Policy
X-Generator
X-Buckets
X-Drupal-Cache
X-Xss-Protection
X-Type
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Request-Id
X-Hacker
X-Ac
X-Powered-By-Plesk
Content-Location
X-Cache-Hits
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Download-Options
MS-Author-Via
Host-Header
Alt-Svc
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-Dc
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-Section
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-Alternate-Cache-Key
X-IPLB-Instance
X-Powered-CMS
X-Request-ID
Cartoon
X-UA-Device
Status
X-Served-By
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Via
X-Amz-Cf-Id
X-Iinfo
X-Cache-Status
X-Backend
X-Contextid
X-Timer
X-Wix-Server-Artifact-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-ServedBy
X-PC-Hit
X-PC-Key
X-PC-AppVer
X-PC-Date
X-PC-Host
CF-Cache-Status
Powered-By
X-Mod-Pagespeed
X-DIS-Request-ID
X-Logged-In
X-Rid
Content-Encoding
Keep-Alive
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Server
X-Host
X-Cache-Hit
X-CDN
X-Tumblr-Pixel-1
X-Port
Expect-CT
X-CST
X-Server-Powered-By
X-Tumblr-Pixel-2
Referrer-Policy
X-Robots-Tag
X-Pad
X-Cache-Enabled
X-Nginx-Cache-Status
WP-Super-Cache
X-Endurance-Cache-Level
X-Accel-Version
Fastly-Debug-Digest
X-Page-Speed
X-Turbo-Charged-By
X-Seen-By
X-Wix-Request-Id
X-Wix-Renderer-Server
X-Wix-PunisherID
X-Content-Powered-By
X-Tumblr-Pixel-3
X-Drupal-Dynamic-Cache
X-Content-Digest
X-Rack-Cache
X-Varnish-Cache
X-AH-Environment
X-FRAME-OPTIONS
X-Forwarded-For
Content-Security-Policy-Report-Only
X-Forwarded-Proto
X-Pantheon-Styx-Hostname
Surrogate-Key-Raw
X-Styx-Req-Id
SPRequestGuid
X-Proxy-Cache
X-SharePointHealthScore
X-GitHub-Request-Id
MicrosoftSharePointTeamServices
X-MS-InvokeApp
X-Request-Country
X-Cnection
X-XRDS-Location
X-LiteSpeed-Cache
X-Cache-Lookup
Edge-Control
X-Original-Date
Cf-Railgun
X-Safe-Firewall
Timing-Allow-Origin
X-FullPageCaching
X-Amz-Request-Id
X-Amz-Id-2
Request-Id
MicrosoftOfficeWebServer
X-Webserver
X-FW-Hash
Charset
X-Died
X-Node
X-FW-Type
X-FW-Static
X-FW-Serve
X-PhApp
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
X-INKT-URI
X-INKT-SITE
X-HS-Cache-Config
X-Hits
X-HS-Content-Id
X-Content-Security-Policy
Composed-By
X-Tumblr-Pixel-4
Access-Control-Max-Age
X-CF-Powered-By
Liferay-Portal
X-Swift-CacheTime
X-Swift-SaveTime
Grace
Content-MD5
EagleId
Served-By
Access-Control-Expose-Headers
X-Hyper-Cache
X-Spip-Cache
X-CDN-Pop
X-CDN-Pop-IP
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-BC-Stapler
Rating
X-Device
Request-Context
X-Firenze-Processing-Times
X-Backend-Server
X-Server-Name
X-Fastly-Request-ID
X-Newrelic-App-Data
X-Dw-Request-Base-Id
X-Tumblr-Content-Rating
X-Microcachable
X-Microcache
X-SERVER
X-RateLimit-Remaining
X-RateLimit-Limit
X-VCache
X-RateLimit-Reset
Refresh
X-Jimdo-Instance
X-Jimdo-Wid
X-ServerName
X-FB-Debug
X-User-Agent
X-Clacks-Overhead
Content-Style-Type
Content-Script-Type
X-Cloud-Trace-Context
X-Loop
X-TNCMS
Real-Hostname
Public-Key-Pins
X-Cache-Config
X-Acc-Exp
Xkey
X-XN-XNHTML
X-XN-Trace-Token
Front-End-Https
X-DDC-Arch-Trace
Surrogate-Control
Fpc-Cache-Id
X-Age
X-Aspnetmvc-Version
X-Hostname
X-Generated-By
X-Tumblr-Pixel-5
X-N-OperationId
PageSpeed
X-Cached
X-Px
X-FORWARDED-FOR
X-Middleton-Display
X-Sol
X-Middleton-Response
Response
Display
X-LiteSpeed-Cache-Control
X-SS-Location
X-SS-Conf
X-DNS-Prefetch-Control
X-MiniProfiler-Ids
X-Topify-Platform
X-Cached-By
X-Outils-CS
Surrogate-Key
X-StackifyID
X-WebKit-CSP
X-URL
X-CMS-Version
X-Zen-Fury
X-Content-Options
X-Url
X-Request-Time
Rt-Fastcgi-Cache
X-Servedby
X-Pantheon-Environment
X-Pantheon-Site
X-Pantheon-Phpreq
TCN
X-OneAgent-JS-Injection
X-Cdn
X-Whom
X-HOST
X-Handled-By
X-Umbraco-Version
X-AspNetWebPages-Version
X-Varnish-Cache-Hits
X-Ruxit-JS-Agent
Access-Control-Request-Method
X-Varnish-TTL
X-ApacheServer
X-PERF
X-Amz-Version-Id
Edge-Control-Message
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-DynaTrace
Imagetoolbar
Product
X-Correlation-Id
Host
Alternate-Protocol
X-DynaTrace-JS-Agent
X-Kinsta-Cache
X-Engine
ServedBy
Powered
X-Micro-Cache
P-LB
P-WS
DynaTrace
X-NWS-LOG-UUID
Fhost
X-Powered-By-360WZB
WZWS-RAY
X-Magento-Tags
Generator
X-Track
X-From
X-Hosted-By
X-Cache-Rule
X-Msg-2-Log
X-LBLID
X-CacheServer
X-B-Cache
X-Edge-Location
X-Location-Id
X-Vtex-Processado-Em
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-VTEX-Cache-Status-Janus-ApiCache
No
X-Powered-By-VTEX-Janus-ApiCache
X-Tumblr-Pixel-6
X-VTEX-Janus-Router-Backend-App
X-Actual-URL
X-Recruiting
X-Returned-From
X-Returned-From-DLL
X-Passed-To-DLL
X-Passed-To
X-Original-Request
X-I-Sp
X-BS
X-Instart-Request-ID
X-RESOURCE
Arr-Disable-Session-Affinity
X-Powered-By-VTEX-Janus-Edge
X-Goog-Hash
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-VARNISH-Cache
X-Passed-To-PostProcessResponse
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Origin
X-Stale
X-Developer
X-Cache-Age
Fastcgi-Cache
X-URLSCHEME
X-Response-Time
X-Varnish-Host
X-LB
X-App-Hosting
X-Upstream
X-Shop-Id
X-Defender
X-Internal-ReqID
X-Cache-Info
X-Fastcgi-Cache
X-TransIP-Balancer
X-Application-Context
X-Source
X-Matrix-Proxy
Akamai-IP
X-Accel-Expires
X-Matrix-Server
X-UD-Method
Dmn
X-Varnish-Seen-By
X-Cache-TTL
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-Varnish-RemainingLife
X-Varnish-ObjectSource
X-Akamai-Transformed
X-Platform-Processor
X-Platform-Router
X-Platform-Cluster
Content-Hash
X-Device-Type
X-HS-Content-Campaign-Id
X-TransIP-Backend
X-Varnish-Count
IBM-Web2-Location
X-Varnish-HitMiss
X-NetCat-Version
X-Storage
X-Gamma-Serve
X-Version
Ohc-File-Size
X-I
Pool
X-Cache-Tags
Version
X-VTEX-Cache-Status-Janus-Edge
X-Powered-By-VelaWeb
X-Front
X-Varnish-Cacheable
HTTPS
Last-Published
X-Supported-By
X-Origin
Srv
X-Signature
X-Rocket-Nginx-Bypass
X-Revision
USPLoggingUUID
X-Content-Encoded-By
X-Platform
X-Cache-Debug
X-S
X-Translation
X-Microcache-Status
X-Cache-Key
Powered-By-ChinaCache
X-Cache-Operation
X-Expires-Orig
X-UPSTREAM
Public-Key-Pins-Report-Only
X-Route-Server
X-Dispatcher
Content-Disposition
X-Server-Upstream
X-ATG-Version
X-NoCache
X-Server-Id
X-Daa-Tunnel
MIME-Version
X-SSL-Protocol
X-EdgeConnect-Origin-MEX-Latency
X-NewRelic-App-Data
ServerName
X-SSL-Cipher
X-Firenze-Processing-Time
X-Debug-Info
X-Dispatch
X-Page-Cache
X-Cache-Lifetime
X-Art-Request-Id
X-Vcap-Request-Id
Node
X-EdgeConnect-MidMile-RTT
X-Duration
X-Varnish-Age
X-Varnish-Backend
X-SV-Edge
X-SV-Expires
X-SV-Duration
X-SV-Cacheable
X-SV-CacheTags
X-SV-CreatedAt
X-SV-FromDBCache
X-SV-Pid
X-Sapient
SSPAppContext
X-SV-Nginx-Duration
X-CJ-Soft
X-AOL-HN
Cache-Tag
Page-Completion-Status
X-TTL
X-Dns-Prefetch-Control
X-Platform-Cache
X-F-Cache
X-LB-Node
Cache-Key
X-Cache-Only-Varnish
X-Hypernode
FAI-W-FLOW
X-Flow-Powered
X-Last-Modified
Proxy-Connection
X-Server-ID
X-Platform-Server
X-Abuse
X-SDS
X-PwB-Node
ServerID
X-Geo-Country
X-Cookie-Domain
X-Abgroup
SN
X-LW-Cache
X-Cache-Control-Orig
Req-Id
Lsrequestid
Allow
Edge-Content-Tag
X-Director
Cneonction
X-Edge-IP
X-Url-Base
IM-Version
X-Grace
X-GeoIP-Country-Code
X-Country-Code
X-Client-IP
X-Debug
Location
X-Speed-Cache-Key
WSR-Cache
X-Speed-Cache
X-Cache-Expires
Accept-Encoding
X-Magento-Cache-Debug
X-Amz-Meta-S3cmd-Attrs
X-ORACLE-DMS-ECID
X-Cache-CFC
X-GeoIP-Country-Name
Section-Io-Id
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
Pv
Author
Cache-Provider
X-Cache-Server
X-BackendServer
X-ServerID
X-Akamai-Device-Characteristics
PICS-Label
X-Processing-Time
X-Frontend
X-Content-Age
X-ARC
X-Cache-Engine
NnCoection
Cached
X-Nbs
X-Purge-URL
X-Time
X-SERVER-NAME
X-Browser
A-Powered-By
X-Akamai-Device-Model
X-RequestId
X-IsCacheURL
X-Loopia-Node
Content-Encoding-Handler
Fw-Via
X-Id
X-Proxy
X-N
X-Sucuri-ID
If-Modified-Since
X-FW
X-Yadis-Location
X-NB-Cached-Page
X-Middleware-Start
Backend
Server-Info
S
X-Goog-Stored-Content-Encoding
X-Discourse-Route
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
X-GUploader-UploadID
AMF-Ver
X-Varnish-Url
X-DealerOn
X-Pressidium-NinukisWP-Ver
X-Sucuri-Cache
X-SE-Debug
X-Ttl
X-Cache-Level
X-Varnish-IP
X-SRCache-Key
S-Cnection
Use-Proxy
X-Purge-Host
RTSS
X-Content-Type-Option
X-BKSrc
X-Cache-Handler
X-PF-Uncompressing
X-Worker
X-Vhost
Accept-Charset
X-Real-Server
X-Shield-Request-Id
X-Lambda-Id
X-Processed-By
X-Nginx-Cache
Identity
Cteonnt-Length
Access-Control-Allow-Header
X-Config-Blacklist-Version
Cache
Nodo
X-ID
Nitro-Cache
SEOMOZ
MJ12bot
X-Cache-Control
X-Hiawatha-Cache
Frame-Options
X-Generated
X-CDN-Cache-Status
Xc-Version
X-CDN-Node
X-Orig-Vary
X-Empowered-By
X-Cache-TTL-Remaining
X-Trace
X-Framework
X-Cf-Powered-By
X-Cache-Type
X-Healthy
X-Amz-Storage-Class
X-SO
X-WR-Flags
Local-Info
Tracecode
X-Cache-Fix
X-Cache-PageType
X-Always-Cache
CacheControlHeader
X-CDN-Forward
HitType
Qs-Cache
SVR
X-Mobilized-By
NetMindSessionID
Retry-After
X-HP-Trace-ID
X-HP-Trace-Project
X-Drupal-Cache-Tags
X-ClientSide-Caching
BALANCEDTO
Content-Transfer-Encoding
EagleEye-TraceId
MC
Eomportal-Instance
X-Adobe-Content
X-Varnish-Server
Cm-Server
X-Adobe-Loc
X-Pagename
X-Hit-Cache
Thanks
X-Varnish-Hits
WWW-Authenticate
X-JG-Page-Cache
X-Unique-ID
X-Srv
X-Generated-Time
X-Site-Name
X-Twitter-Response-Tags
X-AF-Userserver
X-Environment
X-Transaction
X-App-Server
X-Connection-Hash
Front
X-ORACLE-DMS-RID
X-CB-Server
X-VC-TTL
X-Powered-By-Server
X-Drectory-Script
X-Yottaa-Metrics
X-Varnish-Ttl
X-TB-M
X-Content-Security-Policy-Report-Only
X-Magnolia-Registration
X-Symfony-Cache
RATING
X-LB-Server
X-Yottaa-Optimizations
X-Client-Vid
X-Cache-Dispatchercachecontrol
Ufe-Result
X-EPiphany-Vid
X-Fedora-School-Id
X-Cache-Device-Type
X-Magento-Cache-Control
X-Varnish-Hostname
X-Sys-Req-ID
X-Resty-Request-Id
X-Varnish-ID
X-Server-IP
X-LW-Web-Server
Keywords
X-Client-Image-Vid
X-Cache-Dispatcherpragma
HCVer
HAVer
X-OPNET-Transaction-Trace
X-Location
From-Origin
Buuteeq-Source
X-Directory-Script
X-Static
X-Traffic
Content_type
NODE
X-Route-To
X-ACMCache
X-Runtime-Memory
X-Disney-Akamai-Rule
SBGI-7
SBGI-10
SRV
SBGI-1
X-Session-Reinit
SBGI-5
X-CAPServer
SBGI-Device
X-Varnish-Retries
ServerSignature
SBGI-RenderTime
Disablevcache
X-High-Performance
X-CF-Passed-Proto
Max-Age
SBGI-RealPath
SBGI-9
ServerTokens
X-FireWall-Port
X-Cache-Doesi
X-GeoIP
Fastly-Backend-Name
X-FORWARDED-PROTO
X-Mobile-URL
X-Proto
Server-Name
X-Remote-Addr
X-LP
MW-Webserver
X-VC-Enabled
X-Cocoon-Version
X-DataDome
X-VARITI-CCR
Pics-Label
Description
X-SmugMug-Hiring
X-OpenCart-Lightning
X-SmugMug-Values
X-TTFB-L
X-TTFB
X-Nginx-Host
X-NginX-Cache
Magicmarker
X-Esi
X-Frame-Option
Smug-CDN
X-RiS-UFDI
X-HW
X-Key
X-HydroSheep
AsisCache
X-Resolver-IP
Provider
Machine
RN-Server
X-Page
X-Smartcache-Keys
CLMOB
X-Dynatrace-Js-Agent
AC-ELC
NtCoent-Length
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Detail
X-WP
X-Runtime-Rack
X-Smartcache-Timeout
X-WHOIS-Cached
Ctx
X-Cache-Source
X-A
X-Server-Instance
Response-Time
Home
X-Cached-Status
X-NginX-Server
X-Machine
X-Unbounce-PageId
X-WN-ClientGroup
WN
X-Cache-Provider
X-Served-Server
X-Garden-Version
X-Backend-Status
Id
X-Webcelerate
IISExport
X-Debug-Token
X-Unbounce-Variant
W
X-Middleton-PageSpeed
X-Unbounce-VisitorID
X-Env
X-App-Status
X-Jphone-Copyright
X-WR-MODIFICATION
X-AEM
ScoreTracker
X-Author
X-Balanceador
X-App
Yoncu-Errno
X-Oracle-DMS-ECID
Strikingly-Cache-Region
X-UA
Web-App-Origin-Name
X-ServerIndex
X-Cache-Node
From
Strikingly-Cached
Strikingly-Cached-Version
X-ARRServer
X-Src-Webcache
X-PageType
X-Drupal-Cache-Contexts
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Cache-Keep
X-HP-Redirect
Og
X-Blog
X-MAT-GEO
X-Highwire-SessionId
X-RemovedCookies
X-Time-Microsecs
X-Rebelmouse-Surrogate-Control
X-Plat
X-SmartBan-URL
X-SmartBan-Host
X-Trace-Id
X-Highwire-RequestId
Sophnep-Edge-FX
X-Info
X-Cache-On
X-RDP
DNNOutputCache
X-Captured
X-Rebelmouse-Cache-Control
X-ProcessESI
Hname
Paypal-Debug-Id
X-E
X-Clara-ASAP
NLCacheNote
X-ETag
X-Application
X-ASAP-Cache
X-Machine-Name
X-RealServer
X-Desc
Access-Control-Request-Headers
SG
X-Actindo-RS
X-SV
Server-ID
Cmsid
X-Force
X-Atraveo-Param-Rm
X-Atraveo-TTL
X-Atraveo-Varnish-Server-Id
X-Distributor
X-Domain-Checked
X-Atraveo-Set-Cookie
X-Provisioner-Version
X-Atraveo-From-Varnish-Cache
X-Atraveo-Expires
X-Atraveo-Zone
X-Atraveo-Cache-Control
Cmstype
Dis-Env
Bios
X-Source-ID
X-Grid-Server
X-PRAM
Dispatcher
X-Atraveo-ETag
X-Hosting-Env
X-SDE-Name
Backend-Timing
X-PM-ID
X-Session-ID
X-Goog-Meta-Replace
X-AutoRu-App-Id
X-Rq
X-Autoru-Host
X-Goog-Meta-Policy
X-CacheResult
X-Autoru-LB
NZSpeedy
X-Culture
X-Analytics
VServer
Resin-Trace
X-Map-Context
X-Ser
X-App-Runtime
X-Runtime-Affili
X-Correlation-ID
X-Render-Time
X-4ormat-Cacheable
X-Req-Head-Response
Xc
X-Cdn-Forward
X-SH-Cache-Status
Beyond-Iis
X-Webkit-CSP
VANITY-HOST
X-ReqId
X-Rewrite
X-L-Path
SS
X-GSL-Server
X-Environment-Context
X-SilverStripe-Cache
X-Cache-TTL-Age
X-MSEdge-Ref
X-Cache-TTL-Current
X-Frames-Options
X-FRUIT
TC-S-Cache-M
TC-S-Cache
X-Cluster-Node
TC-Cache
TC-Cache-IC
TC-Cache-U
X-Airee-Node
X-Viator-Tapersistentcookie
Content-Server
X-Distil-CS
X-IIJ-Cache
X-Secret
Web
Ibf5scheme
N365rili
X-Response
X-Proxy-Cache-Key
X-CRA-DC
X-Config-By
Cluster-ID
CommunityServer
XDomainRequestAllowed
X-Varnish-Debug-TTL
X-Rocket-Nginx-Serving-Static
X-Site
X-Batcache
X-Varnish-Debug-Age
X-KoobooCMS-Version
X-Lb
X-EC2-Instance-Id
Device
X-Varnish-Info
Ttl
X-ACCELERATE
X-Varnish-Action
X-Nginx
X-ENV
X-Rack-Cors
X-Hstore
X-Dw-Trace-Id
X-We-Are-Hiring
X-Optimization
X-Hrouter
X-This-Proto
X-Batcache-Reason
X-Stage
Debug-Status
X-Rack-CORS
Expect-Ct
X-Amcomm-Site
X-CDN-COMPRESS
X-Detected-Device
X-DTC
Worker
X-Gannett-Site-Version
X-DS1D
X-Reflector
X-Reflector-Cache
AccessControlAllowOrigin
X-Varnish-Cache-Local
X-Server-Addr
X-AISO-Server
X-Enhanced-By
Gzip
Set-Cookie2
X-Magento-Action
X-Catalyst
X-AISO-Cache
X-AISO-Cacheable
X-Cms-Mode
X-CDN-RULE
X-Adnet
X-Ghost-Cache-Status
ClientIP
NS-VaryByCustom-Key
WP-AdvCache-MemCached
SHInfo
F5-IpCliente
ViewMode
X-Avvio-Cms-Cacheload
OriginServer
Lb
X-Pageid
X-HashTwo
Tempo
X-7d-Instance-Id
X-HA-Frontend
X-V
Proxy-Cache
ServerIP
X-Amz-Id-1
Il-Cl
X-HTML-Minification-Powered-By
X-Node-Name
X-Pagely-Cache
X-7d-Trace-Id
NCache
X-Forwarded-Host
X-Sc-Cache
X-Data-Request
X-MidCOM-Meta-Cache
X-Old-Content-Length
Session-From
X-Ezoic-Cdn
X-Refresh
X-HA-Backend
X-Cache-Warmer
X-Hosting
X-Dev
X-Webapp
X-Powered-By-Home.Pl
X-DB-Content-Length
SERVER-ID
BackendServer
X-HAProxy
SBMCLOUD
Server-Ip
X-MCB-Server
X-Header
X-APP
Nginx-Cache
PagesDisplayed
StatusCode
X-CACHE-TTL
X-Dynamic-Cache
VAR-Cache
X-HostName
X-Wm-VIP
FastCGI-Cache-Status
X-Unique-Id
X-Gyrobase-Publication
X-Fstrz
Actual-Object-TTL
X-Wm-1
SB-Site-IE-VERSION
X-ACLR-Version
RequestId
X-Compressed-By
X-DSMX-Render-MS
X-DevSrv-CMS
X-Apm-Telemetry-Syncmark
X-Test
X-SCM-Server-Number
X-B2f-Not-Route
Myheader
X-DSMX-Rewrite-MS
COMMERCE-SERVER-SOFTWARE
X-Flex-Tag
X-Flex-Tags
X-Svr
X-Search-Id
X-Flex-Lastmod
X-Flex-Lang
X-Flex-Community
X-Flex-Evend
X-Flex-Evstart
X-CCM
X-Obj.Ttl
X-Cache-Time
X-Cache-Via
X-Forwarded-By
X-Upstream-Backend
X-Session-Id
X-AG-MIPS
X-WebKit-CSP-Report-Only
MwpReleaseVersion
Progma
Traffic-Origin
X-Server-Generated
SB-Site-Device
SB-Cache-Remaining
SB-Cache-Life
X-DN-Cache-Control
X-Cacheable-TTL
X-Depends
X-WA-Info
X-Zendesk-Origin-Server
X-Zendesk-User-Id
AGI-Request-ID
Cache-Status
FindLaw
X-Generated-Date
Rewriter
X-FG-RequestId
DbServerName
Content-Cache
X-REDIRECTSERVER
X-Sid
X-Upgrade-Enabled
SINA-LB
SINA-TS
X-Country
X-D-Time
X-ELB
X-AppServer-Cache-Rule
X-Amzn-Trace-Id
UrlWatchModule-Time
Webserver
X-Amzn-RequestId
X-PHP-Response-Code
X-DeliveryServer
X-CacheID
X-PBS-Appsvrip
X-PBS-Appsvrname
X-Cache-FS-Status
Note
SiteSpeed
PServer
Ews
X-PBS-Fwsrvname
X-EC-Security-Audit
X-Brought-To-You-By
X-Cache-Extended
X-DEBUG
X-Box
DrivedBy
X-VC-Debug
X-Artvisual-Server
Url
X-Generation-Time
X-Dynamic
X-M
X-Varnish-Instance
X-Uncacheable
X-Node-ID
X-Time-Zone
X-VLoc
X-XHR-Current-Location
X-Cache-Varnish
X-Farm-Server
X-Built-With
X-Bcwwwid
Accept-Language
Expiries
X-LOCATION
X-ServiceProvider
X-W3TC-Minify
X-Server-FQDN
X-Proxy-Id
X-Streams-Distribution
X-S-Misc
X-Cache-HT
X-Pixelsilk-Version
X-Tag-Playlist
Warning
X-LBPoolMember
X-ChromeLogger-Data
X-IP
X-Resource
Swift-Performance
Cleartype
X-Cache-BE
MS-CV
X-Ocache
X-Turpentine-Esi
X-Nocache
X-Lima-Id
X-PBY
X-RAMCache
X-Nginx-Request-Time
X-Pixelsilk-Server
MageStack-PageSpeed
X-ASAP-Age
Contao-Page-Layout
MageStack-Cache-Lifetime
MageStack-Cache-Hits
MageStack-Cacheable
X-CM-FE
MageStack-Loadbalancer
MageStack-Debug
MageStack-Config
MageStack-Cache-Status
MageStack-Magento-Version
X-MainProfileID
X-Made-On
X-MainProfileCategory
X-Beatles
X-Cname-TryFiles
X-HP-CAM-COLOR
RSB-LINK
Access-Control-Allow-Method
X-Serv
ENV
X-Debug-Message
X-Deity
AMP-Access-Control-Allow-Source-Origin
Brightspot-Id
MageStack-Area
X-Served
X-WPL-DATA
MageStack-Tag
X-Rocket-Nginx-Reason
Page-Template
MageStack-Cache
X-Aramark-SID
X-Webstats-RespID
WFE
X-CACHE-KEY
X-WebNode
X-EBAY-C-REQUEST-ID
Session-Id
X-Config-Version
XDisk
Provided-Host
!~Request-OOB-Work
RSL-Trace-ID
X-Front-Cache
X-IP-Address
X-Tradeindia-SMgmt
X-Tradeindia-Request-GUID
X-UseReverse-Proxy
X-Cache-Bypass
X-9XB-Server
No-Cache
M
X-Provided-By
X-RiS-PX
X-Router
X-Router-Backend
AMFplus-Ver
PLCDN
X-Origin-Server
X-App-Version
X-Backend-TTL
X-Cache-Me-Harder
X-CH-Device
Server-Id
Apple-Itunes-App
X-Agent
X-MainProfileURL
MageStack-Web-Node
X-NewsFlow-Sitename
X-Cms-Server
X-GoCache-CacheStatus
X-Faeria
TP-Cache
X-Server-Instance-Name
X-Title
X-NewCloud-V-Cache
X-Layout
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Not-Cacheable
X-JSESSIONID
TP-L2-Cache
X-MainProfileName
X-Who
X-RequesterIP
X-Nginx-Request-Processing-Time
Aurora-Node
CDCHOST
Edgecast
Debug-Expires
Debug-Cache-Control
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
X-Restarts
Container
X-Container
X-AMAZEEIO
X-XHTML-Minification-Powered-By
Cache-Tags
FrontEnd
X-Backend-Name
X-Test-Debug
X-Rewritten-By
X-AppVersion
X-AWS
X-ManagedFusion-Rewriter-Version
X-Pubstack
X-Meta-Imagetoolbar
X-Backend-Host
X-Webkit-Csp
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-NodeID
X-CSRF-Token
X-Ss-Conf
X-HASH
GP-Remote-Addr
GP-Version
X-Ss-Location
Ibm-Web2-Location
X-SuperCache
X-Varnish-Cached
X-Varnish-Cached-TTL
MSSmartTagsPreventParsing
MSThemeCompatible
X-MCF-ID
X-Fpc
X-UnsetCookies
D
Kanooh-Host
Kp-EeAlive
X-Cjtype
X-FIRSTBase
X-Origin-Cache
X-OCTOPOD
X-UPSTREAM-Address
X-Amz-Meta-Content-Md5
X-Phpwcms-Page-Processed-In
X-Phpwcms-Release
X-Header-Treatment
X-Custom-Header
X-Route
X-Real-IP
X-NID
X-Cache-Id
INFO
X-COUNTRY-CODE
X-C2M-Runtime
X-Ssl-Cipher
X-C2M-Server
X-Webkit-CSP-Report-Only
X-Varnish-URL
X-Beresp-Ttl
E-TAG
Language
X-PG
X-Theme
Accept-CH
Lookup-Cache-Hit
CD4
X-Skip-Cache
X-BPool
X-Geo-IP
X-BC
X-Varnish-VCL
X-Client-Ip
X-Tt-Dbg
X-Ants-Host
X-Ants-Machine-Id
TheAnswer
X-CO-Host
RlogId
X-Ezpublish-Nodeid
X-FPC
X-Highwire-Sitecode
Returned-Status
X-JoinUs
X-ESI
X-Ezpublish-Installationid
X-SERVER-IP
X-Highwire-Smart-Code
X-Obvious-Info
X-PROCESSED-BY
Serverid
X-SVR
Head
X-Pass-Through
X-BPool-Back
X-Obvious-Tid
X-Nginx-Page-Cache
X-FastCGI-Cache
Countrycode
X-BPool-Fx-Cache
X-HEAD
X-Cache-ID
X-Magento-Lifetime
X-Support
X-Varnish-Debug-Hits
WP-Cache
Upgrade-Insecure-Requests
HostName
Microcache
WSCLoggingUUID
X-Obj-Ttl
Generate-Time
IsMobile
X-Vary-Options
X-Cachable
X-VNode
Fw-Cache-Status
X-FreeTag-Count
X-UT-Cache
Tesla.Performance
User-Cache-Control
X-DynamicCache
X-Serverid
X-Pool-Info
EQ-Cache
X-BServer
X-NMT-Proxy
Server-Tuning
Resource
Session
X-Instance-Id
X-SRV
X-Netrix-ID
X-BPool-Bx-Cache
X-Build-Id
ReqUrl
X-Protected-By
X-Cluster
X-Prerendered
Aoestatic
Be
Vserver
V-Age
CpuTime
X-Transaction-Name
X-Serendipity-InterfaceLangSource
X-Serendipity-InterfaceLang
X-Stiffia-Cache
X-B3-Spanid
X-Varnish-Currency
X-Varnish-Esi-Access
X-Turpentine-Cache
X-Max-Age
X-Hash
X-Varnish-Esi-Method
Copyright
X-Varnish-Store
0
X-Varnish-Set-Cookie
X-Varnish-Max-Age
X-Debug-Serve
Prototype-RootPath
ServerNode
X-Count
X-Czt
X-FCMS-Cache
WebServer
Www.Aujourdhui.Com
X-Accel-Cache-Control
X-Debug-Out
X-Cache-Served
X-Ar-Debug
X-SCProxy
Content-Legth
GranicusServer
ProxiaInstanceId
X-Enabled3
X-Enabled2
X-TTL-Age
AR-SID
X-Would-Your-GrandPa-Wait
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Enabled1
X-Amz-Meta-Version-Id
ResourceTag
Public-Extension
X-Pj-Cache-Status
X-Processed
X-Imforza-Hosted
X-Beatles-Hits
X-Does-He-Have-Time
X-Cache-LB
X-Csrf-Token
X-Cache-Set
OutputRewritten
X-HS-Status
X-CPU-Time
X-B3-Traceid
X-Your-GrandPa-Would-Wait
CD1
X-Sn-Servicetimems
Hosted-By
Ez
X-Instance-Name
VC-NoCache
Httpd-Identifier
Url-Hash
X-Jcms-Ajax-Id
B-Rlogid
Rlogid
Content-Generator
DB-Nickname
X-UPServer
X-ServerAddr
X-Auto-Login
X-Diazo-Applied
X-EC-Custom-Error
X-Script
X-W-Cache-Hits
X-W-Cache
X-Request-Processing-Time
X-Content-Parsed-By
X-Built-By
X-Archive-Orig-Server
Yola-ID
X-ZORequestID
X-UUID
X-Op-Benvironment
X-Server-App
X-Request-Received
X-Archive-Orig-ETag
X-Archive-Orig-Date
Memento-Datetime
EXT-CACHEEXPIRE
X-Vol-Mrp
X-Vol-Correlation
Server-Node
X-Archive-Guessed-Charset
X-Archive-Orig-Content-Length
X-BeResp-Ttl
X-Cache-Action
X-Archive-Orig-Connection
Tk