Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
P3P
CF-RAY
X-AspNet-Version
Age
X-Pingback
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Template
X-Language
X-Xss-Protection
X-Generator
X-Buckets
Alt-Svc
X-Drupal-Cache
X-Request-Id
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Powered-By-Plesk
X-Permitted-Cross-Domain-Policies
Content-Location
X-Download-Options
Host-Header
X-Runtime
MS-Author-Via
X-ShopId
X-Sorting-Hat-PodId-Cached
X-Dc
X-Sorting-Hat-PodId
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-ShardId
X-Alternate-Cache-Key
X-FRAME-OPTIONS
Cartoon
X-Powered-CMS
X-UA-Device
X-IPLB-Instance
X-Served-By
Access-Control-Allow-Credentials
Status
Access-Control-Allow-Headers
X-Amz-Cf-Id
Access-Control-Allow-Methods
X-Cache-Status
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Request-ID
CF-Cache-Status
X-Backend
Referrer-Policy
X-Contextid
X-DIS-Request-ID
X-Mod-Pagespeed
Powered-By
X-PC-Hit
X-PC-Key
X-PC-Host
X-PC-Date
X-PC-AppVer
X-ServedBy
Content-Encoding
X-WPE-Loopback-Upstream-Addr
X-CST
X-Logged-In
X-Server
Keep-Alive
X-Cache-Hit
X-Host
X-Port
X-Ua-Compatible
X-Rid
P3p
X-CDN
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Server-Powered-By
X-Cache-Enabled
X-Tumblr-Pixel-1
X-Robots-Tag
X-Endurance-Cache-Level
X-Nginx-Cache-Status
X-Accel-Version
X-Seen-By
X-Wix-Request-Id
X-Tumblr-Pixel-2
X-Wix-Server-Artifact-Id
X-Turbo-Charged-By
X-Original-Date
X-Page-Speed
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
X-Content-Digest
WP-Super-Cache
X-Proxy-Cache
X-AH-Environment
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rack-Cache
X-Tumblr-Pixel-3
X-Varnish-Cache
X-GitHub-Request-Id
X-LiteSpeed-Cache
X-Request-Country
X-XRDS-Location
SPRequestGuid
X-Cnection
Edge-Control
X-SharePointHealthScore
X-MS-InvokeApp
MicrosoftSharePointTeamServices
X-Cache-Lookup
X-Node
Timing-Allow-Origin
X-Died
Cf-Railgun
X-Amz-Request-Id
X-Amz-Id-2
Charset
X-FW-Hash
X-Trace
Request-Id
X-Webserver
X-FW-Type
X-FW-Serve
X-FW-Static
Edge-Cache-Tag
X-FullPageCaching
X-Webcom-Cache-Status
X-Content-Security-Policy
X-HS-Cache-Config
MicrosoftOfficeWebServer
X-HS-Content-Id
X-PhApp
X-Safe-Firewall
X-CF-Powered-By
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
X-Hits
SPIisLatency
SPRequestDuration
Access-Control-Max-Age
Request-Context
Composed-By
X-Newrelic-App-Data
X-BC-Stapler
Access-Control-Expose-Headers
X-Swift-SaveTime
X-Swift-CacheTime
EagleId
Served-By
Grace
X-CDN-Pop
X-CDN-Pop-IP
X-Spip-Cache
X-Hyper-Cache
Liferay-Portal
X-Tumblr-Pixel-4
X-Backend-Server
X-Device
X-Server-Name
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-Microcache
X-LiteSpeed-Cache-Control
X-Wix-Renderer-Server
Content-Style-Type
Content-Script-Type
X-VCache
X-SERVER
X-ServerName
X-RateLimit-Remaining
X-FB-Debug
X-RateLimit-Limit
Rating
X-Clacks-Overhead
X-Cloud-Trace-Context
X-RateLimit-Reset
X-User-Agent
X-Jimdo-Instance
X-Jimdo-Wid
X-Firenze-Processing-Times
Surrogate-Control
Real-Hostname
X-Loop
X-TNCMS
X-DDC-Arch-Trace
X-Acc-Exp
Public-Key-Pins
Front-End-Https
X-Cache-Config
Refresh
X-XN-Trace-Token
X-XN-XNHTML
Fpc-Cache-Id
X-Servedby
X-StackifyID
X-Middleton-Response
X-Tumblr-Content-Rating
X-SS-Conf
X-Age
X-Middleton-Display
X-SS-Location
X-Sol
Response
Display
Xkey
X-HS-Combine-CSS
X-Microcachable
X-DNS-Prefetch-Control
X-Hostname
X-Generated-By
X-N-OperationId
X-Cached
X-Px
X-OneAgent-JS-Injection
X-Zen-Fury
X-Cdn
X-Tumblr-Pixel-5
PageSpeed
X-Correlation-Id
X-Vtex-Processado-Em
X-Topify-Platform
X-MiniProfiler-Ids
X-Cached-By
X-Request-Time
TCN
X-Frame-Option
X-Ruxit-JS-Agent
Edge-Control-Message
X-WebKit-CSP
X-Url
X-CMS-Version
X-Amz-Version-Id
X-Whom
X-Magento-Tags
P-LB
P-WS
Product
X-Kinsta-Cache
X-Outils-CS
Rt-Fastcgi-Cache
X-URL
X-DynaTrace-JS-Agent
X-Content-Options
X-Handled-By
Surrogate-Key
X-Via-JSL
X-Varnish-TTL
Access-Control-Request-Method
X-VARNISH-Cache
X-B-Cache
Imagetoolbar
X-AspNetWebPages-Version
X-Forwarded-For
X-Edge-Location
Host
X-Cache-Rule
X-DynaTrace
X-Recruiting
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Fastly-Debug-Digest
X-Engine
Powered
X-Debug-Info
Fhost
X-HOST
X-Varnish-Cache-Hits
ServedBy
Alternate-Protocol
X-CacheServer
X-Umbraco-Version
X-NWS-LOG-UUID
X-Track
X-LBLID
X-Msg-2-Log
X-PERF
X-Goog-Hash
X-ApacheServer
X-Application-Context
X-From
No
X-VTEX-Janus-Router-Backend-App
X-FORWARDED-FOR
Public-Key-Pins-Report-Only
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-Powered-By-VTEX-Janus-ApiCache
X-Signature
X-Response-Time
X-Platform
X-Actual-URL
Akamai-IP
Generator
X-Returned-From-DLL
X-Passed-To-DLL
X-Passed-To
X-Original-Request
X-Location-Id
X-Returned-From
X-Powered-By-360WZB
WZWS-RAY
X-Powered-By-VTEX-Janus-Edge
X-Hosted-By
X-Cache-Age
X-Developer
X-Returned-From-PostProcessResponse
X-Accel-Expires
X-Returned-From-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Director
X-Varnish-Beresp-Ttl
X-Micro-Cache
X-Varnish-Beresp-Status
Fastcgi-Cache
Dmn
X-Varnish-Beresp-Grace
X-LW-Cache
DynaTrace
Arr-Disable-Session-Affinity
X-Stale
X-Rocket-Nginx-Bypass
X-Upstream
X-Pantheon-Phpreq
Surrogate-Key-Raw
Origin
X-Pantheon-Environment
X-Pantheon-Site
X-UD-Method
X-Source
HTTPS
X-Cache-Info
X-Version
X-LB-Node
X-Varnish-Host
X-Instart-Request-ID
X-RESOURCE
X-Platform-Router
Retry-After
X-Platform-Processor
X-Supported-By
X-Defender
X-Shop-Id
X-S
X-LB
X-Tumblr-Pixel-6
X-Rnd
X-URLSCHEME
X-Platform-Cluster
X-Fastcgi-Cache
X-Device-Type
X-CSRF-Protection
X-TransIP-Balancer
X-Cache-TTL
Content-Hash
X-NetCat-Version
X-Magento-Cache-Debug
X-BS
X-EdgeConnect-Origin-MEX-Latency
X-I-Sp
X-Storage
X-HS-Content-Campaign-Id
X-AOL-HN
X-Powered-By-VelaWeb
X-Dispatcher
Cache-Provider
X-Front
X-Varnish-Count
X-Varnish-HitMiss
X-Matrix-Proxy
X-Matrix-Server
X-App-Hosting
X-EdgeConnect-MidMile-RTT
X-Cache-Tags
X-TransIP-Backend
X-Art-Request-Id
X-I
X-Daa-Tunnel
Version
X-F-Cache
Powered-By-ChinaCache
X-Cache-Key
X-ATG-Version
X-Gamma-Serve
Ohc-File-Size
X-Microcache-Status
X-Translation
MIME-Version
USPLoggingUUID
X-Platform-Server
X-Drupal-Cache-Tags
Last-Published
IBM-Web2-Location
X-Expires-Orig
X-Page-Cache
Allow
Pool
X-Cache-Operation
X-Server-ID
Node
X-Hypernode
RTSS
X-Content-Encoded-By
X-Cache-Debug
Pagespeed
X-Varnish-ObjectSource
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Varnish-RemainingLife
X-Flow-Powered
X-Ua-Device
X-Varnish-GracePeriod
X-Revision
SSPAppContext
X-Server-Upstream
X-ARC
X-UPSTREAM
Cache-Key
X-Route-Server
Content-Disposition
X-SSL-Protocol
X-SSL-Cipher
Content-MD5
X-Edge-IP
X-Loopia-Node
Wsr-Cache
X-Dispatch
X-Platform-Cache
X-ORACLE-DMS-ECID
X-Drupal-Cache-Contexts
X-Lambda-Id
Lsrequestid
X-Varnish-Age
X-SV-Expires
X-SV-FromDBCache
X-SV-Edge
X-SV-Nginx-Duration
X-SV-Pid
X-Environment
X-SV-CreatedAt
X-SV-Duration
X-SV-Cacheable
X-SV-CacheTags
X-Cache-Only-Varnish
Section-Io-Id
X-Abgroup
X-Vcap-Request-Id
X-Varnish-Cacheable
X-NoCache
X-Id
X-Debug
X-Generated
X-Grace
X-Cache-Control-Orig
X-Hiawatha-Cache
Accept-Encoding
Page-Completion-Status
ServerID
X-Cache-Expires
X-Cache-Lifetime
X-Url-Base
X-IsCacheURL
Content-Encoding-Handler
X-CJ-Soft
X-Ttl
Location
S-Cnection
Srv
X-Client-IP
Fw-Via
X-RequestId
X-TTL
X-Firenze-Processing-Time
X-Ezoic-Cdn
Proxy-Connection
X-GeoIP-Country-Code
X-Cache-Server
FAI-W-FLOW
Pv
X-Orig-Vary
If-Modified-Since
X-Sapient
X-Vhost
Cneonction
X-Sentry-ID
X-VTEX-Cache-Status-Janus-Edge
X-Cache-Engine
X-ServerID
X-Proxy
X-Cache-Type
X-Magento-Cache-Control
Author
X-Litespeed-Cache-Control
X-Duration
Server-Name
X-PwB-Node
X-Country-Code
X-Akamai-Transformed
X-Always-Cache
X-Dns-Prefetch-Control
X-Content-Age
Backend
ServerName
X-Geo-Country
X-Litespeed-Cache
X-Browser
X-Nbs
X-N
SN
X-Nginx-Cache
NetMindSessionID
X-Amz-Meta-S3cmd-Attrs
PICS-Label
X-Discourse-Route
X-Processing-Time
Cm-Server
X-Magnolia-Registration
IM-Version
X-Sucuri-ID
X-Speed-Cache
X-Speed-Cache-Key
X-Location
Nodo
Req-Id
X-Server-Id
X-Cache-Control
SRV
X-Time
X-Dynatrace-Js-Agent
X-SRCache-Key
X-Cache-Level
X-Cookie-Domain
X-Yadis-Location
X-Middleware-Start
X-Akamai-Device-Characteristics
X-Shield-Request-Id
X-NB-Cached-Page
X-Akamai-Device-Model
X-FW
X-GeoIP-Country-Name
X-Pressidium-NinukisWP-Ver
X-Goog-Stored-Content-Length
Qs-Cache
X-Goog-Metageneration
NnCoection
X-Goog-Generation
X-Worker
X-Goog-Stored-Content-Encoding
X-Varnish-Url
X-Cache-CFC
X-Goog-Storage-Class
X-GUploader-UploadID
Server-Info
X-SERVER-NAME
AMF-Ver
X-Cache-Namespace
X-Real-Server
X-ACMCache
X-Framework
Use-Proxy
X-Forwarded-Proto
X-Cluster-Node
S
X-Cache-Fix
X-Cache-PageType
X-Frontend
Accept-Charset
X-Purge-URL
Pics-Label
X-Sucuri-Cache
X-App-Server
HAVer
X-BackendServer
X-Webkit-CSP
X-Processed-By
HCVer
Cached
X-Srv
X-Varnish-Backend
X-SO
X-Cache-Device-Type
X-Config-Blacklist-Version
X-Varnish-IP
X-Abuse
X-BKSrc
X-Purge-Host
Xc-Version
Cache
X-Ss-Conf
Pf.Web.Request.Id
X-Ss-Location
Thanks
X-SRV
X-DealerOn
X-Server-IP
SiteSpeed
X-Amz-Storage-Class
A-Powered-By
X-Sys-Req-ID
X-JG-Page-Cache
Local-Info
Tracecode
X-CDN-Forward
X-Session-ID
X-Runtime-Rack
X-Last-Modified
X-Traffic
SVR
Server-Timing
X-Route-To
X-ARRServer
MJ12bot
X-Origin
SEOMOZ
X-PF-Uncompressing
X-Balanceador
X-Varnish-Retries
X-High-Performance
X-CF-Passed-Proto
X-Webstats-RespID
X-Mobilized-By
X-Empowered-By
W
X-FastCGI-Cache
X-WR-Flags
CacheControlHeader
Content_type
X-Content-Type-Option
X-Connection-Hash
X-DataDome
X-Drectory-Script
X-Cf-Powered-By
X-Transaction
Cache-Tag
X-ClientSide-Caching
X-Twitter-Response-Tags
X-LB-Server
Eomportal-Instance
Nitro-Cache
WWW-Authenticate
X-Rocket-Nginx-Serving-Static
ServerTokens
ServerSignature
Magicmarker
X-RiS-UFDI
X-FTR-Request-ID
HitType
X-VARITI-CCR
Frame-Options
X-Content-Security-Policy-Report-Only
Keywords
X-SDS
X-Unique-ID
MC
P-ID
EagleEye-TraceId
X-ORACLE-DMS-RID
X-Sorting-Hat-Expire-Cache
X-AF-Userserver
XDomainRequestAllowed
X-Generated-Time
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-LP
X-ID
Content-Transfer-Encoding
X-Runtime-Memory
X-Disney-Akamai-Rule
X-Varnish-ID
AC-ELC
X-Cache-TTL-Remaining
X-Domain-Checked
X-Pagename
Description
Ufe-Result
X-HTML-Minification-Powered-By
X-Hit-Cache
X-Varnish-Debug-Age
X-Varnish-Debug-TTL
X-Debug-Token
X-ASAP-Cache
Cache-Tags
X-Client-Image-Vid
X-Client-Vid
X-Directory-Script
X-EPiphany-Vid
X-Clara-ASAP
X-Provisioner-Version
X-App-Status
X-Cache-Doesi
X-HW
X-Avg-Cookie-Expires
Adm-Server
X-AVG-Country-Code
X-Akamai-Edgescape
VANITY-HOST
X-NginX-Cache
X-Adobe-Loc
X-Redman-Backend
X-Varnish-Hits
WN
X-Amz-Meta-Cb-Modifiedtime
X-VNode
X-WN-ClientGroup
X-Detected-Device
X-Cache-Handler
X-Redman-Final-Url
X-Adobe-Content
Web-App-Origin-Name
X-AEM
Dis-Env
NODE
X-Unbounce-VisitorID
X-LW-Web-Server
X-Unbounce-Variant
X-Garden-Version
X-Unbounce-PageId
X-Analytics
X-OpenCart-Lightning
Backend-Timing
X-Server-Instance
X-Varnish-Ttl
X-WPL-DATA
X-FireWall-Port
X-Jphone-Copyright
Proxy-Agent
X-Atraveo-Expires
X-Atraveo-ETag
Front
X-Atraveo-From-Varnish-Cache
X-HP-Trace-ID
Play-Detected-Device
X-Source-ID
X-Atraveo-Cache-Control
Play-Detected-UserAgent
X-Key
X-HP-Trace-Project
X-CAPServer
X-Atraveo-Param-Rm
X-GoCache-CacheStatus
X-PRAM
X-HOSTNAME
X-Force
X-ServerIndex
X-GeoIP
X-Atraveo-Zone
X-A
X-Atraveo-Set-Cookie
X-Atraveo-TTL
X-Mobile-URL
X-Atraveo-Varnish-Server-Id
X-Webkit-Csp
X-Remote-Addr
X-Distributor
X-Env
X-OPNET-Transaction-Trace
Max-Age
From-Origin
Dispatcher
X-Rewrite
Cteonnt-Length
X-SmugMug-Hiring
X-SmugMug-Values
X-WebKit-CSP-Report-Only
X-Correlation-ID
X-Cache-Node
X-Webcelerate
BALANCEDTO
X-TTFB
X-TTFB-L
X-CB-Server
Smug-CDN
Ramp
Ram
Noq
X-Page
X-Rq
X-Varnish-Hostname
SBGI-RenderTime
Contao-Page-Layout
SBGI-10
X-Nginx-Host
Cmstype
SBGI-9
SBGI-RealPath
SBGI-Device
X-App-Runtime
X-Runtime-Affili
X-Backend-Status
SBGI-1
X-Fedora-School-Id
X-Cms-Mode
X-Dev
SBGI-5
SBGI-7
X-Resty-Request-Id
Machine
Cmsid
Nginx-Cache
Worker
X-Esi
X-Culture
Beyond-Iis
X-Dynamic-Cache
NLCacheNote
Device
SERVER-ID
X-WP
X-Compressed-By
X-Smartcache-Timeout
X-Resolver-IP
X-E
Disablevcache
X-GSL-Server
X-Smartcache-Keys
X-Amcomm-Site
X-Symfony-Cache
OriginServer
X-App
BackendServer
X-Akamai-3PM-SW-Version
Og
X-Confluence-Request-Time
X-HydroSheep
Resin-Trace
CommunityServer
X-Real-IP
X-CDN-RULE
X-Trace-Id
X-CacheResult
Strikingly-Cached-Version
Strikingly-Cached
Access-Control-Allow-Header
From
X-Hrouter
X-Hstore
X-MCB-Server
X-Frames-Options
X-Wikidot-Backend
X-CDN-COMPRESS
Strikingly-Cache-Region
X-TB-M
X-Cache-Keep
X-Ser
X-NginX-Server
Service-Worker-Allowed
X-Wikidot-Static-Cache
X-Plat
X-Varnish-Server
X-Stage
X-Cocoon-Version
Fastly-Backend-Name
X-VC-TTL
Lb
X-Proto
Web
X-V
MS-CV
AMP-Access-Control-Allow-Source-Origin
X-Autoru-LB
X-Autoru-Host
X-VC-Enabled
X-Airee-Node
Id
X-Varnish-Ip
X-RAMCache
X-Rack-CORS
Bios
X-Fstrz
X-IIJ-Cache
X-AutoRu-App-Id
Hname
TC-Cache-U
X-EC2-Instance-Id
X-DTC
TC-Cache
X-Highwire-SessionId
X-Dw-Trace-Id
TC-Cache-IC
TC-S-Cache-M
X-Req-Head-Response
X-Cache-Dispatchercachecontrol
X-Captured
SG
X-Proxy-Cache-Key
WebServer
TC-S-Cache
X-Map-Context
X-Refresh
CLMOB
F5-IpCliente
ClientIP
Arrnode
X-Highwire-RequestId
X-Session-Reinit
X-Upstream-Backend
X-RDP
X-Adnet
X-DN-Cache-Control
X-Info
X-FPC
Myheader
X-Varnish-Cache-Local
Gzip
Hostname
ViewMode
Proxy-Cache
X-Cache-On
X-Viator-Tapersistentcookie
Il-Cl
Home
X-Pj-Cache-Status
X-HashTwo
X-SmartBan-URL
X-Render-Time
X-Bip
X-Gyrobase-Publication
X-Origin-Server
Traffic-Origin
X-MSEdge-Ref
PagesDisplayed
X-SmartBan-Host
X-Aramark-SID
X-B2f-Not-Route
X-Machine-Name
X-Data-Request
X-Batcache
X-ENV
X-Desc
X-Apm-Telemetry-Syncmark
X-Batcache-Reason
X-MAT-GEO
Ews
Ibf5scheme
X-Cache-Dispatcherpragma
N365rili
Hamster
Content-Server
X-WR-MODIFICATION
Yoncu-Errno
SHInfo
COMMERCE-SERVER-SOFTWARE
Identity
SB-Cache-Remaining
Referer
SB-Site-Device
X-ETag
X-L-Path
X-Environment-Context
SB-Site-IE-VERSION
IISExport
Provided-Host
ScoreTracker
X-CACHE-TTL
X-Cdn-Forward
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Redirector
X-Ghost-Cache-Status
X-Depends
X-Litespeed-Tag
SB-Cache-Life
X-Hosting-Env
X-SDE-Name
Paypal-Debug-Id
X-UA
Cleartype
Custom-Header
X-Header
X-WA-Info
RN-Server
MW-Webserver
X-W3TC-Minify
X-SH-Cache-Status
X-Grid-Server
X-HostName
X-PM-ID
X-KoobooCMS-Version
X-Rack-Cors
Warning
X-Goog-Meta-Policy
NtCoent-Length
X-RealServer
X-Protected-By
X-Goog-Meta-Replace
Server-Id
X-Unique-Id
X-Resource
AsisCache
Serverid
Xc
Ctx
X-FIRSTBase
Aoestatic
X-Does-He-Have-Time
Edgecast
X-Tag-Playlist
X-TTL-Age
X-Server-Generated
VServer
X-CacheID
X-Your-GrandPa-Would-Wait
X-LBPoolMember
X-Streams-Distribution
X-Author
X-DSMX-Rewrite-MS
X-Magento-Action
X-Magento-Lifetime
X-RemovedCookies
X-DSMX-Render-MS
SS
X-Zendesk-User-Id
X-Cache-TTL-Age
X-Zendesk-Origin-Server
Session-From
ServerIP
X-Flex-Lastmod
X-Bcwwwid
X-Flex-Tag
X-Cache-TTL-Current
X-Src-Webcache
X-Cache-Via
X-Secret
X-VC-Cache
X-Flex-Tags
Accept-Language
Hosted-By
User-Agent
X-Cache-Set
X-Beatles-Hits
X-Origin-Cache
X-Cache-Time
X-Powered-By-Home.Pl
PServer
X-IP
X-ProcessESI
X-Flex-Evstart
X-Flex-Lang
X-Flex-Evend
X-Old-Content-Length
X-Amz-Meta-S3b-Last-Modified
X-Flex-Community
X-Cache-Id
X-Would-Your-GrandPa-Wait
X-Cluster
X-Response
X-Forwarded-Host
X-Backend-Host
X-ASAP-Age
X-Varnish-Id
X-CRA-DC
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-M
Note
X-Beatles
RequestId
X-Timestamp
X-CH-Device
XDisk
X-BeResp-Ttl
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
Hummingbird-Cache
DNNOutputCache
X-Middleton-PageSpeed
X-Nginx
X-JSESSIONID
WP-AdvCache-MemCached
X-We-Are-Hiring
X-Machine
X-Avvio-Cms-Cacheload
X-Sc-Cache
X-DB-Content-Length
X-Served-Server
Viewport
X-Reflector-Cache
X-HAProxy
X-DEBUG
X-Lw-Cache
X-HS-Status
X-Reflector
X-Serv
X-4ormat-Cacheable
X-Server-Addr
X-SV
Server-Ip
X-ReqId
X-HP-CAM-COLOR
NZSpeedy
Url
X-Pagely-Cache
Provider
X-Varnish-Action
X-CSRF-Token
X-ACCELERATE
X-Netrix-ID
X-Dynatrace
X-HA
X-Max-Age
X-Gateway-Cache-Status
X-Turpentine-Esi
X-Pixelsilk-Server
AR-CACHE
X-SCM-Server-Number
X-Nginx-Request-Time
X-Search-Id
X-VCS-Cacheable
X-Mobile-Rewrite
AR-ATIME
X-Pixelsilk-Version
!~Request-OOB-Work
X-FastCGI-Cache-Status
X-UT-Cache
X-Cache-2
Www.Aujourdhui.Com
X-Backend-Name
X-Cache-Original-TTL
EQ-Cache
ServerNode
Cacheid
Fw-Cache-Status
Session-Id
AR-SID
X-Cjtype
X-Gateway-Cache-Key
X-Amz-Id-1
Microcache
X-Instart-Cache-Id
X-Full-Url
X-Hosting
X-Say-Cacheable
X-SayCDN-TTL
AR-PoweredBy
X-Say-TTL
X-IP-Address
X-Gateway-Skip-Cache
VC-NoCache
Generate-Time
X-Server-Ip
X-CCM
X-Domino-CacheValidationWithETagReason
PB-PID
Ec-CorrId
X-VCS-Ttl
PB-RID
X-Domino-CacheValidationWithETagResult
Upgrade-Insecure-Requests
Fastly-Restarts
X-DevSrv-CMS
X-Enabled1
X-MidCOM-Meta-Cache
X-Cname-TryFiles
X-Custom-Header
X-Made-On
X-Enabled3
X-Served
X-Enabled2
Quri
Ec-Machine
X-Cache-Detail
X-Az
X-AppVersion
RSB-LINK
X-Debug-Message
X-DynamicCache
X-VC-Debug
X-VC-Hash
X-Deity
X-Pageid
Ttl
X-Route
Tesla.Performance
X-Header-Treatment
Control-Cache
X-Amz-Meta-Content-Md5
X-Router
Tempo
X-Activity-Id
Uuri
X-VC-Cacheable
X-XHR-Current-Location
X-7d-Instance-Id
X-Upgrade-Enabled
X-7d-Trace-Id
X-DDM-SERVER
X-Hash
X-DDM-SERVER-UPDATED
X-Skip-Cache
X-REDIRECTSERVER
X-Cache-Extended
X-Box
X-Client-Ip
X-Container
X-Geo-IP
X-SuperCache
X-Uncacheable
X-PHP-Response-Code
X-Node-Name
X-S-Misc
X-Time-Microsecs
Cache-Status
X-Generation-Time
X-D-Time
Progma
Kanooh-Host
X-AppServer-Cache-Rule
X-Cache-Varnish
X-Config-By
X-Application
X-Agent
X-Cache-FS-Status
Services
X-Catalyst
X-Instance-Id
X-LOCATION
X-XHTML-Minification-Powered-By
DrivedBy
X-WebServer
X-Fastly-Request-Id
AMFplus-Ver
AccessControlAllowOrigin
Access-Control-Request-Headers
X-MainProfileCategory
X-MainProfileID
FRONT-END-SECUREBROWSER
X-Upstream-Status
INFO
TP-Cache
TP-L2-Cache
X-PBS-Fwsrvname
X-PBS-Appsvrname
X-MainProfileURL
X-MainProfileName
X-NewsFlow-Sitename
X-Not-Cacheable
X-PBS-Appsvrip
EN-User
NS-VaryByCustom-Key
X-Node-ID
Server-ID
X-Pubstack
X-DS1D
X-ManagedFusion-Rewriter-Version
X-Nginx-Request-Processing-Time
X-SilverStripe-Cache
Debug-Status
X-RequesterIP
X-NodeID
X-UnsetCookies
MachineName
X-Test-Debug
Expiries
MwpReleaseVersion
X-Cache-V
X-Enhanced-By
X-Rewritten-By
X-Blog
StatusCode
X-Gannett-Site-Version
X-Status
X-Instance
X-Artvisual-Server
X-AISO-Cache
X-AISO-Server
X-AMAZEEIO
Access-Control-Allow-Method
X-AISO-Cacheable
CDCHOST
X-Distil-CS
X-ESI
X-Cache-Ttl
Dynatrace
X-Oneagent-Js-Injection
X-Oracle-DMS-ECID
X-Ruxit-Js-Agent
X-Ssl-Cipher
X-FORWARDED-PROTO
X-Lb
X-Archive-Orig-Server
Powered-By-VeryCDN
Language
X-Request-Received
X-PBY
X-Request-Processing-Time
X-Built-By
X-AWS
X-Server-App
X-WHO
X-Cache-Warmer
WP-FROM-CACHE
X-Instance-Name
X-LB-Backend
X-Meta-Imagetoolbar
X-LB-Frontend
Realaction
MSThemeCompatible
X-Varnish-Cached-TTL
X-Varnish-Cached
Actioncode
CS-SERVER
MSSmartTagsPreventParsing
Httpd-Identifier
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
Memento-Datetime
X-Cache-Date
X-Archive-Guessed-Charset
X-Archive-Orig-Connection
X-Archive-Orig-Date
X-Archive-Orig-Content-Length
TTL
CD4
X-Server-Vrn
X-Restarts
X-Wm-1
X-Wm-VIP
Actual-Object-TTL
X-Archive-Orig-ETag
MageStack-Cache-Lifetime
X-Cacheable-TTL
X-Cachable
X-I-V
X-M-P
X-M-T
X-Beresp-Ttl
X-B
CommercePlatform-Version
Key
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
X-M-V
X-Mw-Workerstats
X-CACHE-KEY
X-Transaction-Name
X-Middleton-Pagespeed
X-UPSTREAM-Address
X-WebNode
X-T
X-S-V
X-Nocache
X-Pool-Info
X-Q-S
X-S-C
X-Serverid
X-ProBase-Server
MageStack-Area
X-Varnish-Store
MageStack-Cache
MageStack-Cache-Hits
X-UPServer
X-Varnish-Esi-Method
X-Varnish-Esi-Access
CpuTime
GranicusServer
X-Fastly-Backend-Reqs
X-Varnish-Currency
MageStack-Cache-Status
MageStack-Cacheable
MageStack-Web-Node
X-Backend-TTL
X-NewCloud-V-Cache
X-Origin-Upstream-Status
MageStack-Tag
MageStack-PageSpeed
MageStack-Config
MageStack-Debug
MageStack-Loadbalancer
MageStack-Magento-Version
X-Debug-Serve
X-Proxy-Id
X-FG-RequestId
X-EBAY-C-REQUEST-ID
X-This-Proto
X-Svr
WSCLoggingUUID
Cache-Ctrol
Requested-Host
RlogId
X-Clx-Request
SINA-TS
SINA-LB
X-9XB-Server
X-PROCESSED-BY
Accept-CH
X-Layout
X-Memcached
Aurora-Node
X-Czt
X-ZSITES-DNS
X-Varnish-Grace
X-Who
Copyright
X-Accel-Cache-Control
Page-Template
X-MSU-SOURCE
X-ServiceProvider
X-Server-FQDN
X-PG
X-Cache-Bypass
X-Time-Zone
X-Varnish-Instance
Response-Time
Countrycode
CmsfirstPublishTimestamp
X-VLoc
X-Varnish-URL
X-ELB
Apple-Itunes-App
X-VG-WebCache
X-SID
X-SE-Debug
X-ACLR-Version
UrlWatchModule-Time
X-CO-Host
X-Country
X-Nginx-Page-Cache
X-Powered-Developer
X-Ants-Host
X-Server-Ident
X-Service-Id
Head
XX
Cookie
DB-Nickname
X-Distributed-By
Webserver
Content-Cache
DbServerName
FindLaw
Rewriter
IES-Server
Load-Balancer
X-MCF-ID
X-Nitro-Cache
X-Script
X-ServerAddr
X-Fpc
X-CPU-Time
Request-Time
X-B3-Spanid
X-B3-Traceid
X-Built-With
X-Via-NSCOPI
X-Sid
X-Ants-Machine-Id
X-BC
X-Ar-Debug
ReqUrl
Yola-ID
Y-Trace
X-Title
X-Cache-Served
X-COUNTRY-CODE
X-ZORequestID
ATI-Server-Id
OutputRewritten
X-DeliveryServer
X-Dynamic
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
X-Config-Version
X-Cache-Me-Harder
X-WAF-Proxy
E-TAG
VAR-Cache
X-Brought-To-You-By
X-Sn-Servicetimems