Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
P3P
X-AspNet-Version
Age
X-Pingback
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Template
X-Language
X-Generator
X-Buckets
X-Request-Id
Alt-Svc
X-Drupal-Cache
X-Xss-Protection
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Content-Location
Host-Header
X-Runtime
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-ShardId
X-Dc
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-Section
X-Sorting-Hat-PodId-Cached
X-Alternate-Cache-Key
MS-Author-Via
X-FRAME-OPTIONS
Cartoon
X-UA-Device
X-Powered-CMS
X-IPLB-Instance
X-Served-By
X-Amz-Cf-Id
Status
Access-Control-Allow-Headers
Access-Control-Allow-Credentials
Access-Control-Allow-Methods
X-Cache-Status
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
CF-Cache-Status
X-Backend
X-Contextid
Referrer-Policy
Powered-By
X-PC-Hit
X-PC-Key
X-CST
X-Mod-Pagespeed
X-DIS-Request-ID
X-PC-AppVer
X-PC-Date
X-PC-Host
Content-Encoding
X-ServedBy
X-WPE-Loopback-Upstream-Addr
X-Logged-In
Keep-Alive
X-Cache-Hit
X-Rid
X-Request-ID
X-Host
X-Port
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Server
P3p
X-CDN
X-Tumblr-Pixel-1
X-Server-Powered-By
X-Cache-Enabled
X-Endurance-Cache-Level
X-Seen-By
X-Wix-Request-Id
X-Wix-Server-Artifact-Id
X-Robots-Tag
X-Nginx-Cache-Status
X-Tumblr-Pixel-2
X-Turbo-Charged-By
X-Page-Speed
X-Accel-Version
X-Original-Date
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
X-Content-Digest
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
WP-Super-Cache
X-Proxy-Cache
X-Rack-Cache
X-Tumblr-Pixel-3
X-AH-Environment
X-GitHub-Request-Id
X-Varnish-Cache
X-LiteSpeed-Cache
X-Ua-Compatible
X-Died
Edge-Control
SPRequestGuid
X-XRDS-Location
X-SharePointHealthScore
X-MS-InvokeApp
X-Request-Country
MicrosoftSharePointTeamServices
X-Cnection
X-Cache-Lookup
Cf-Railgun
Timing-Allow-Origin
X-Amz-Request-Id
X-Amz-Id-2
X-Trace
X-Node
Charset
X-FW-Hash
Edge-Cache-Tag
X-FW-Type
X-FW-Serve
X-FW-Static
Request-Id
X-HS-Cache-Config
X-HS-Content-Id
X-FullPageCaching
X-Webcom-Cache-Status
X-Content-Security-Policy
X-Webserver
X-CF-Powered-By
X-Safe-Firewall
MicrosoftOfficeWebServer
X-PhApp
X-Hits
SPIisLatency
SPRequestDuration
X-Wix-Renderer-Server
Access-Control-Max-Age
X-INKT-SITE
X-INKT-URI
Request-Context
X-Newrelic-App-Data
X-BC-Stapler
X-PHP-Backend
Composed-By
X-SERVER
Access-Control-Expose-Headers
X-Swift-SaveTime
X-Swift-CacheTime
X-CDN-Pop-IP
X-CDN-Pop
EagleId
Grace
X-Tumblr-Pixel-4
Served-By
Liferay-Portal
X-Hyper-Cache
X-Spip-Cache
X-Backend-Server
X-Fastly-Request-ID
X-Device
X-Dw-Request-Base-Id
X-Microcache
X-Server-Name
X-LiteSpeed-Cache-Control
Rating
X-ServerName
X-VCache
X-Cloud-Trace-Context
X-FB-Debug
X-RateLimit-Remaining
Content-Style-Type
X-Firenze-Processing-Times
X-RateLimit-Limit
X-Servedby
X-DDC-Arch-Trace
Public-Key-Pins
Content-Script-Type
X-Clacks-Overhead
X-RateLimit-Reset
Front-End-Https
X-Acc-Exp
X-Jimdo-Instance
X-Jimdo-Wid
X-Loop
X-TNCMS
Real-Hostname
Surrogate-Control
X-User-Agent
Xkey
Refresh
X-Cache-Config
X-Tumblr-Content-Rating
X-Microcachable
Fpc-Cache-Id
X-XN-Trace-Token
X-XN-XNHTML
X-HS-Combine-CSS
X-Middleton-Display
X-Middleton-Response
Display
Response
X-Sol
X-Age
X-StackifyID
X-SS-Conf
X-SS-Location
X-DNS-Prefetch-Control
X-Hostname
X-Cached
X-Generated-By
X-N-OperationId
X-Cdn
X-Px
X-Zen-Fury
X-Tumblr-Pixel-5
X-Topify-Platform
X-Vtex-Processado-Em
PageSpeed
X-OneAgent-JS-Injection
X-MiniProfiler-Ids
X-Request-Time
X-Cached-By
P-WS
P-LB
X-Amz-Version-Id
TCN
X-Correlation-Id
X-WebKit-CSP
X-Frame-Option
X-CMS-Version
Edge-Control-Message
X-Url
X-Kinsta-Cache
X-Whom
X-Magento-Tags
X-Content-Options
X-URL
X-Ruxit-JS-Agent
X-Handled-By
X-Forwarded-For
X-DynaTrace-JS-Agent
Product
Surrogate-Key
Rt-Fastcgi-Cache
X-Varnish-TTL
X-Outils-CS
X-Via-JSL
X-VARNISH-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-B-Cache
Access-Control-Request-Method
X-AspNetWebPages-Version
Host
X-DynaTrace
Imagetoolbar
X-Edge-Location
Fastly-Debug-Digest
Powered
X-Cache-Rule
X-Varnish-Cache-Hits
X-Umbraco-Version
X-Engine
X-CacheServer
X-HOST
ServedBy
Alternate-Protocol
X-Goog-Hash
X-Track
Fhost
X-LBLID
X-Recruiting
X-VTEX-Cache-Status-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-Powered-By-VTEX-Janus-ApiCache
No
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-Debug-Info
X-Application-Context
X-NWS-LOG-UUID
X-Platform
X-Signature
X-ApacheServer
X-PERF
Generator
X-Developer
X-Msg-2-Log
X-Powered-By-VTEX-Janus-Edge
X-FORWARDED-FOR
X-Actual-URL
X-Passed-To
X-Original-Request
X-Upstream
DynaTrace
X-Passed-To-DLL
X-Returned-From
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Returned-From-BeforeDispatch
X-Passed-To-PostProcessResponse
X-From
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Location-Id
X-Micro-Cache
Public-Key-Pins-Report-Only
X-Varnish-Beresp-Ttl
HTTPS
Akamai-IP
X-Pantheon-Phpreq
X-Pantheon-Site
Dmn
X-Pantheon-Environment
Surrogate-Key-Raw
X-Powered-By-360WZB
X-Stale
X-Cache-Age
X-Response-Time
WZWS-RAY
X-Accel-Expires
X-Hosted-By
X-Supported-By
X-LW-Cache
X-Varnish-Host
Origin
X-Defender
X-Rocket-Nginx-Bypass
Fastcgi-Cache
X-Shop-Id
X-UD-Method
X-RESOURCE
X-Device-Type
X-URLSCHEME
X-I-Sp
X-BS
X-LB
X-Cache-TTL
Arr-Disable-Session-Affinity
X-Cache-Info
X-Tumblr-Pixel-6
X-Source
X-Page-Cache
X-Rnd
Cache-Provider
Retry-After
X-Fastcgi-Cache
X-Platform-Router
X-Platform-Processor
X-Version
Content-Hash
X-NetCat-Version
X-TransIP-Balancer
X-Instart-Request-ID
X-F-Cache
X-HS-Content-Campaign-Id
X-S
X-Magento-Cache-Debug
X-Director
X-Platform-Cluster
X-CSRF-Protection
X-Cache-Key
X-Storage
X-Powered-By-VelaWeb
Last-Published
X-Revision
X-Front
X-EdgeConnect-Origin-MEX-Latency
X-TransIP-Backend
X-Matrix-Server
X-Daa-Tunnel
X-Translation
X-Microcache-Status
X-Art-Request-Id
X-Matrix-Proxy
X-App-Hosting
X-AOL-HN
X-Varnish-Count
X-Varnish-HitMiss
X-EdgeConnect-MidMile-RTT
Allow
Pool
Version
Pagespeed
Ohc-File-Size
USPLoggingUUID
X-ATG-Version
MIME-Version
X-Dispatcher
X-Dispatch
X-Gamma-Serve
X-Hypernode
X-Cache-Operation
X-Expires-Orig
Cache-Key
RTSS
IBM-Web2-Location
X-Varnish-RemainingTTL
X-Varnish-GracePeriod
X-Varnish-Seen-By
X-ARC
X-Cache-Tags
X-Varnish-RemainingLife
X-Varnish-ObjectSource
X-Cache-Only-Varnish
X-Route-Server
X-Varnish-Age
X-Platform-Server
X-Ua-Device
X-Loopia-Node
X-I
Powered-By-ChinaCache
X-Drupal-Cache-Tags
X-Flow-Powered
Content-Disposition
X-Content-Encoded-By
Node
X-SV-CreatedAt
X-SV-Duration
X-SV-Edge
X-Abgroup
X-SV-Cacheable
X-SV-CacheTags
X-Lambda-Id
X-Cache-Debug
X-SV-Pid
X-SV-Nginx-Duration
X-SV-Expires
X-SV-FromDBCache
X-LB-Node
X-NoCache
X-Server-Upstream
X-Varnish-Cacheable
SSPAppContext
X-Server-ID
X-Edge-IP
Lsrequestid
X-SSL-Cipher
X-IsCacheURL
X-Hiawatha-Cache
X-SSL-Protocol
Accept-Encoding
X-UPSTREAM
X-Environment
X-Id
X-Platform-Cache
Wsr-Cache
X-Cache-Engine
X-Vcap-Request-Id
Pv
Content-MD5
X-Drupal-Cache-Contexts
Backend
X-GeoIP-Country-Code
X-Generated
X-Firenze-Processing-Time
X-Dns-Prefetch-Control
X-Cache-Control-Orig
X-Duration
Page-Completion-Status
X-RequestId
X-Ttl
Section-Io-Id
X-Proxy
Fw-Via
X-Cache-Type
X-Cache-Lifetime
X-ORACLE-DMS-ECID
X-Grace
X-Discourse-Route
X-VTEX-Cache-Status-Janus-Edge
X-Ezoic-Cdn
Content-Encoding-Handler
Cneonction
X-Debug
X-Geo-Country
X-Cache-Expires
X-CJ-Soft
X-Sentry-ID
X-Nbs
Server-Name
X-Url-Base
X-Cache-Server
Srv
X-Forwarded-Proto
X-Magento-Cache-Control
ServerID
IM-Version
X-TTL
X-SRCache-Key
X-Client-IP
S-Cnection
X-Sucuri-ID
Location
X-Sapient
X-N
X-Country-Code
X-Litespeed-Cache
X-Correlation-ID
ServerName
X-Amz-Meta-S3cmd-Attrs
If-Modified-Since
X-Speed-Cache-Key
X-Browser
X-Speed-Cache
FAI-W-FLOW
X-Nginx-Cache
X-Location
X-Cookie-Domain
SN
X-PwB-Node
X-Goog-Stored-Content-Length
NnCoection
X-Cache-Fix
X-Cache-PageType
X-Processing-Time
X-GeoIP-Country-Name
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-Yadis-Location
SRV
X-Varnish-Backend
Author
X-Cache-Control
Proxy-Connection
Req-Id
X-Vhost
X-Server-Id
X-Content-Age
X-ServerID
X-Worker
PICS-Label
X-Sucuri-Cache
X-Middleware-Start
X-Akamai-Device-Characteristics
SiteSpeed
X-NB-Cached-Page
X-Akamai-Device-Model
X-Always-Cache
Server-Info
X-Route-To
X-Cache-Level
X-Traffic
X-CDN-Forward
Cm-Server
X-SO
X-FastCGI-Cache
X-SERVER-NAME
NetMindSessionID
X-Time
X-Pressidium-NinukisWP-Ver
X-Cache-Namespace
X-Varnish-Url
Accept-Charset
X-Dynatrace-Js-Agent
X-FW
Nodo
X-ACMCache
X-Magnolia-Registration
Use-Proxy
S
X-Cache-Device-Type
X-Akamai-Transformed
Xc-Version
X-Shield-Request-Id
X-App-Server
Cached
X-BackendServer
X-Session-ID
X-LB-Server
X-Webkit-CSP
AMF-Ver
X-Last-Modified
X-Cluster-Node
X-Amz-Storage-Class
X-JG-Page-Cache
X-Frontend
X-Real-Server
X-Server-IP
X-Litespeed-Cache-Control
Qs-Cache
X-DealerOn
X-Cache-CFC
X-BKSrc
Frame-Options
X-Srv
HCVer
X-Orig-Vary
X-Abuse
X-Content-Type-Option
Cache
HAVer
X-FTR-Request-ID
X-SDS
P-ID
X-Runtime-Rack
X-Config-Blacklist-Version
Local-Info
Web-App-Origin-Name
A-Powered-By
Thanks
X-Varnish-ID
Server-Timing
Pf.Web.Request.Id
X-Processed-By
SVR
X-Purge-URL
X-Runtime-Memory
X-Framework
X-Varnish-Retries
X-Origin
X-Rocket-Nginx-Serving-Static
X-CF-Passed-Proto
MJ12bot
X-VARITI-CCR
SEOMOZ
X-Varnish-IP
EagleEye-TraceId
WWW-Authenticate
X-High-Performance
X-SRV
AC-ELC
X-Purge-Host
X-DataDome
W
X-Empowered-By
WN
X-WN-ClientGroup
X-Cf-Powered-By
X-Drectory-Script
X-WR-Flags
X-VNode
X-ClientSide-Caching
Magicmarker
X-Amz-Meta-Cb-Modifiedtime
Tracecode
Pics-Label
Eomportal-Instance
X-Debug-Token
Nitro-Cache
X-Balanceador
X-AF-Userserver
X-HW
Keywords
X-Twitter-Response-Tags
X-Connection-Hash
X-Sorting-Hat-Expire-Cache
X-Transaction
X-Mobile-URL
X-HP-Trace-ID
X-Mobilized-By
X-Resty-Request-Id
X-Culture
Cache-Tag
Content-Transfer-Encoding
X-Sys-Req-ID
X-Content-Security-Policy-Report-Only
Proxy-Agent
X-LP
X-HP-Trace-Project
X-Yottaa-Metrics
Ramp
X-Yottaa-Optimizations
Ram
Noq
X-Fedora-School-Id
X-NginX-Cache
X-App-Status
X-HTML-Minification-Powered-By
X-Cache-TTL-Remaining
X-ASAP-Cache
X-PF-Uncompressing
X-Client-Image-Vid
X-Pagename
X-Adobe-Content
VANITY-HOST
X-Adobe-Loc
X-Domain-Checked
X-Akamai-Edgescape
HitType
X-EPiphany-Vid
X-Provisioner-Version
Adm-Server
X-Backend-Status
X-AVG-Country-Code
X-Client-Vid
Max-Age
Dispatcher
X-Remote-Addr
X-Redman-Backend
Ufe-Result
X-Clara-ASAP
X-Redman-Final-Url
X-Cache-Doesi
X-Cache-Handler
X-Directory-Script
X-Avg-Cookie-Expires
MC
Description
X-Hit-Cache
X-Garden-Version
X-LW-Web-Server
X-Unbounce-VisitorID
X-Varnish-Ttl
Contao-Page-Layout
X-Varnish-Hits
X-Generated-Time
CacheControlHeader
Content_type
X-ARRServer
X-OpenCart-Lightning
X-Pj-Cache-Status
X-Server-Instance
X-Jphone-Copyright
X-FireWall-Port
X-Unbounce-PageId
X-Unbounce-Variant
X-Map-Context
X-Req-Head-Response
X-ID
X-Data-Request
X-Rq
X-Atraveo-Varnish-Server-Id
X-Force
X-Atraveo-Zone
X-Atraveo-TTL
X-PRAM
Play-Detected-Device
X-ServerIndex
Play-Detected-UserAgent
X-Key
X-Atraveo-Set-Cookie
X-Atraveo-Cache-Control
X-Source-ID
X-Atraveo-ETag
X-Atraveo-Expires
X-Atraveo-Param-Rm
X-Atraveo-From-Varnish-Cache
OriginServer
X-Varnish-Debug-TTL
Cache-Tags
X-HOSTNAME
X-Varnish-Ip
X-Webkit-Csp
X-Varnish-Debug-Age
ServerTokens
X-WebKit-CSP-Report-Only
PagesDisplayed
X-Disney-Akamai-Rule
From-Origin
BALANCEDTO
X-RiS-UFDI
X-Frames-Options
Cteonnt-Length
ServerSignature
X-Webstats-RespID
X-Symfony-Cache
X-HashTwo
X-AEM
X-CB-Server
X-GeoIP
X-Wikidot-Backend
Front
X-Wikidot-Static-Cache
X-ORACLE-DMS-RID
X-CAPServer
X-Akamai-3PM-SW-Version
X-Varnish-Hostname
X-App
X-Unique-ID
SBGI-5
SBGI-1
SBGI-10
SBGI-7
Cmsid
Machine
X-Esi
X-MCB-Server
Backend-Timing
X-Analytics
SBGI-RenderTime
Strikingly-Cached-Version
Cmstype
SBGI-Device
SBGI-RealPath
Strikingly-Cache-Region
Strikingly-Cached
SBGI-9
Worker
X-Dev
NLCacheNote
SERVER-ID
Web
X-Info
X-WPL-DATA
Beyond-Iis
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cms-Mode
ViewMode
Traffic-Origin
Proxy-Cache
X-M
X-GoCache-CacheStatus
Og
X-Apm-Telemetry-Syncmark
X-Aramark-SID
Resin-Trace
Il-Cl
Disablevcache
X-NginX-Server
X-Plat
Home
X-SmugMug-Values
X-SmugMug-Hiring
X-TTFB
X-TTFB-L
X-Resolver-IP
X-OPNET-Transaction-Trace
X-Env
Smug-CDN
X-Varnish-Server
DNNOutputCache
CLMOB
X-Page
X-CDN-COMPRESS
XDomainRequestAllowed
Access-Control-Allow-Header
X-Cache-Detail
X-Author
X-HydroSheep
X-Tag-Playlist
From
X-CDN-RULE
X-WP
X-Smartcache-Timeout
X-Smartcache-Keys
X-CacheResult
X-Cache-Node
X-Cache-Keep
Lb
Cleartype
X-Detected-Device
Fastly-Backend-Name
X-Autoru-LB
X-IIJ-Cache
X-Nginx-Host
X-Stage
NODE
Dis-Env
X-Proto
X-ETag
Bios
X-Dynamic-Cache
X-AutoRu-App-Id
X-Airee-Node
X-VC-TTL
X-V
X-Autoru-Host
X-Wix-PunisherID
X-A
X-Runtime-Affili
X-App-Runtime
Id
X-VC-Enabled
X-Wix-Punisher
COMMERCE-SERVER-SOFTWARE
Paypal-Debug-Id
X-Desc
X-Webcelerate
X-Real-IP
X-Ser
Myheader
X-ENV
X-Hrouter
IISExport
Hname
SG
X-Adnet
Ews
X-Hstore
X-FPC
SHInfo
X-L-Path
X-JSESSIONID
X-Gyrobase-Publication
X-Rewrite
X-Compressed-By
X-Varnish-Cache-Local
X-Trace-Id
X-Dw-Trace-Id
X-Amcomm-Site
X-SDE-Name
Nginx-Cache
X-B2f-Not-Route
X-Environment-Context
X-GSL-Server
X-E
X-Distributor
X-Hosting-Env
X-DN-Cache-Control
X-Machine-Name
X-WR-MODIFICATION
X-Refresh
X-Session-Reinit
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
X-Cdn-Forward
X-Highwire-RequestId
X-Highwire-SessionId
X-Batcache-Reason
X-Captured
Arrnode
ClientIP
TC-S-Cache
TC-Cache
TC-Cache-IC
Hostname
TC-S-Cache-M
F5-IpCliente
WebServer
Gzip
X-Batcache
X-MSEdge-Ref
X-Proxy-Cache-Key
X-DTC
N365rili
X-SmartBan-URL
Ibf5scheme
Hamster
TC-Cache-U
Yoncu-Errno
Content-Server
X-Bip
X-Cache-On
X-SmartBan-Host
X-UA
X-Origin-Server
X-CACHE-TTL
ScoreTracker
X-RDP
X-Render-Time
X-Viator-Tapersistentcookie
X-MAT-GEO
X-EC2-Instance-Id
Access-Control-Allow-Method
X-Served
Tempo
AR-CACHE
X-SE-Debug
X-Magento-Lifetime
X-Powered-By-Home.Pl
X-Deity
Aoestatic
X-Magento-Action
X-Cname-TryFiles
AR-ATIME
AR-SID
Identity
X-LBPoolMember
AR-PoweredBy
MW-Webserver
RN-Server
X-Ss-Location
Viewport
Xc
X-HostName
X-SH-Cache-Status
X-Goog-Meta-Policy
X-Protected-By
X-W3TC-Minify
X-Goog-Meta-Replace
X-RealServer
X-Rack-Cors
X-Ss-Conf
Warning
X-Cocoon-Version
X-KoobooCMS-Version
X-PM-ID
X-Rack-CORS
X-Grid-Server
AsisCache
Server-Id
MS-CV
NtCoent-Length
Serverid
X-Resource
X-CacheID
X-Avvio-Cms-Cacheload
PB-RID
X-Rebelmouse-Cache-Control
X-Varnish-Id
ServerIP
PB-PID
X-Cache-TTL-Current
X-Src-Webcache
X-Cache-TTL-Age
X-Debug-Message
X-Old-Content-Length
Session-From
X-CRA-DC
X-Forwarded-Host
X-Upstream-Backend
X-Sc-Cache
X-Cache-Id
Ctx
PServer
Upgrade-Insecure-Requests
X-Streams-Distribution
BackendServer
X-Backend-Host
X-Server-Generated
X-Response
X-Rebelmouse-Surrogate-Control
X-Instance-Id
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-Cluster
X-Machine
X-Timestamp
X-ProcessESI
X-VC-Cache
X-Origin-Cache
Accept-Language
Hosted-By
User-Agent
X-Middleton-PageSpeed
X-Flex-Tags
X-Flex-Tag
X-Ghost-Cache-Status
X-Flex-Evstart
X-Depends
X-Redirector
X-Flex-Lastmod
X-Confluence-Request-Time
X-Amz-Meta-S3b-Last-Modified
X-Beatles-Hits
X-Beatles
Hummingbird-Cache
X-ASAP-Age
X-Server-Ip
X-This-Proto
AMP-Access-Control-Allow-Source-Origin
X-Your-GrandPa-Would-Wait
X-Would-Your-GrandPa-Wait
X-Cache-Time
X-Cache-Set
X-Does-He-Have-Time
X-DSMX-Render-MS
X-TTL-Age
X-DSMX-Rewrite-MS
X-Flex-Evend
X-Flex-Lang
SB-Site-Device
SB-Site-IE-VERSION
X-Gateway-Cache-Key
X-Litespeed-Tag
SB-Cache-Remaining
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-HA
Edgecast
VServer
X-Bcwwwid
Service-Worker-Allowed
SB-Cache-Life
CommunityServer
X-TB-M
X-IP
X-Mobile-Rewrite
X-RemovedCookies
SS
X-Domino-CacheValidationWithETagResult
X-Flex-Community
X-Domino-CacheValidationWithETagReason
X-Netrix-ID
Server-Ip
X-RAMCache
X-HP-CAM-COLOR
X-Pagely-Cache
X-ACCELERATE
Provider
Device
X-ReqId
Url
X-WA-Info
X-Unique-Id
X-DB-Content-Length
X-CSRF-Token
X-Dynatrace
X-Served-Server
X-Varnish-Action
X-Lw-Cache
NZSpeedy
X-Fstrz
X-Reflector
X-DEBUG
X-SV
X-Reflector-Cache
X-Server-Addr
X-Serv
X-4ormat-Cacheable
X-HS-Status
X-Varnish-URL
X-HAProxy
MachineName
X-Test-Debug
X-XHTML-Minification-Powered-By
Cacheid
X-Rewritten-By
X-Pubstack
X-Blog
X-Distil-CS
X-ManagedFusion-Rewriter-Version
X-BeResp-Ttl
ServerNode
X-Cjtype
Provided-Host
AccessControlAllowOrigin
GranicusServer
X-Cache-Original-TTL
Expiries
Referer
Www.Aujourdhui.Com
X-Backend-Name
MwpReleaseVersion
CDCHOST
X-AMAZEEIO
X-Artvisual-Server
X-Enhanced-By
X-DS1D
X-Status
X-SilverStripe-Cache
X-Instance
XDisk
X-Secret
X-Nginx-Request-Processing-Time
X-NodeID
X-UnsetCookies
X-Zendesk-Origin-Server
Server-ID
X-Zendesk-User-Id
X-CH-Device
X-RequesterIP
Access-Control-Request-Headers
DrivedBy
NS-VaryByCustom-Key
X-Gannett-Site-Version
Note
EQ-Cache
Control-Cache
Microcache
RSB-LINK
X-Made-On
!~Request-OOB-Work
X-Router
X-Enabled2
X-Enabled3
X-Header-Treatment
X-Route
X-Activity-Id
X-AppVersion
X-We-Are-Hiring
Custom-Header
WP-AdvCache-MemCached
Fastly-Restarts
X-Nginx
X-MidCOM-Meta-Cache
X-Az
X-DynamicCache
X-FastCGI-Cache-Status
X-UT-Cache
X-Enabled1
X-DevSrv-CMS
X-Search-Id
X-SCM-Server-Number
X-Turpentine-Esi
X-Say-TTL
X-VC-Cacheable
X-Pixelsilk-Version
X-Pixelsilk-Server
Debug-Status
X-Full-Url
X-Max-Age
X-SayCDN-TTL
X-VC-Debug
X-VC-Hash
X-Cache-Me-Harder
X-Amz-Id-1
X-CCM
X-Custom-Header
X-SCProxy
X-Hosting
X-Say-Cacheable
Ttl
X-Processed
X-Amz-Meta-Content-Md5
RequestId
X-Cache-Via
X-Generation-Time
X-Node-Name
X-PHP-Response-Code
TP-Cache
X-Agent
X-Application
X-Box
X-Config-By
X-D-Time
Uuri
X-S-Misc
Cache-Status
X-Upstream-Status
EN-User
X-PBS-Fwsrvname
X-Amz-Meta-Version-Id
X-XHR-Current-Location
INFO
FRONT-END-SECUREBROWSER
X-Time-Microsecs
X-WebServer
X-Cache-Extended
X-Upgrade-Enabled
X-Skip-Cache
X-REDIRECTSERVER
X-SuperCache
X-Hash
X-DDM-SERVER-UPDATED
X-7d-Instance-Id
X-7d-Trace-Id
X-DDM-SERVER
X-Uncacheable
Quri
X-Fastly-Request-Id
X-Client-Ip
X-Cache-Varnish
X-AppServer-Cache-Rule
X-Container
Kanooh-Host
X-Geo-IP
Progma
X-PBS-Appsvrname
TP-L2-Cache
X-LOCATION
X-Cache-V
X-MainProfileID
StatusCode
X-MainProfileName
X-PBS-Appsvrip
X-MainProfileURL
X-MainProfileCategory
X-NewsFlow-Sitename
X-Not-Cacheable
X-AISO-Cache
X-Catalyst
X-Node-ID
Services
X-AISO-Cacheable
X-Cache-LB
X-Cache-FS-Status
X-AISO-Server
X-Oracle-DMS-ECID
X-Cache-Ttl
X-ESI
X-Header
X-Lb
X-Ruxit-Js-Agent
X-FORWARDED-PROTO
X-Oneagent-Js-Injection
X-Ssl-Cipher
Dynatrace
Webserver
X-Fastly-Backend-Reqs
X-Distributed-By
X-Debug-Serve
Cookie
X-Wm-VIP
DB-Nickname
X-Cache-Date
XX
X-Service-Id
Rewriter
X-Meta-MSThemeCompatible
X-Meta-MSSmartTagsPreventParsing
X-Proxy-Id
CpuTime
DbServerName
VAR-Cache
E-TAG
X-Brought-To-You-By
X-Restarts
X-Config-Version
X-Varnish-Store
VC-NoCache
X-VCS-Ttl
X-WAF-Proxy
X-Origin-Upstream-Status
Request-Filtered-By
X-DeliveryServer
X-Dynamic
Content-Cache
X-Varnish-Esi-Access
X-Varnish-Currency
X-Meta-Imagetoolbar
X-Wm-1
X-Via-NSCOPI
X-Sid
X-Server-Vrn
X-Varnish-Esi-Method
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
FindLaw
X-LB-Backend
X-ServerAddr
X-Sn-Servicetimems
X-Archive-Orig-ETag
X-UPServer
X-Archive-Orig-Server
X-AWS
X-FIRSTBase
X-Nitro-Cache
X-Built-By
X-Script
WP-FROM-CACHE
Realaction
Actioncode
CS-SERVER
MSSmartTagsPreventParsing
X-Archive-Orig-Connection
X-Varnish-Cached-TTL
X-Varnish-Cached
X-Archive-Orig-Date
X-Archive-Orig-Content-Length
X-Archive-Guessed-Charset
MSThemeCompatible
X-MCF-ID
X-Cache-Warmer
Language
X-B3-Spanid
Httpd-Identifier
TTL
X-LB-Frontend
CD4
IES-Server
Load-Balancer
Request-Time
Actual-Object-TTL
X-WHO
X-B3-Traceid
X-Request-Received
X-VCS-Cacheable
X-Request-Processing-Time
X-PBY
X-Fpc
X-Instance-Name
X-Built-With
X-CPU-Time
Memento-Datetime
X-Server-App
Powered-By-VeryCDN
AMFplus-Ver
X-COUNTRY-CODE
X-Nginx-Page-Cache
X-Powered-Developer
X-Web-Node
X-Csrf-Token
X-Cache-HT
Head
Response-Time
X-Cache-Bypass
X-CO-Host
ReqUrl
Page-Template
X-Varnish-Grace
X-Who
X-ZSITES-DNS
Accept-CH
X-PROCESSED-BY
WSCLoggingUUID
RlogId
ATI-Server-Id
X-EBAY-C-REQUEST-ID
X-FG-RequestId
Countrycode
CmsfirstPublishTimestamp
X-MSU-SOURCE
ProxiaInstanceId
X-SID
X-VG-WebCache
Cache-Ctrol
X-Clx-Request
Requested-Host
SINA-LB
SINA-TS
FastCGI-Cache-Status
Apple-Itunes-App
UrlWatchModule-Time
X-ServiceProvider
X-Time-Zone
X-Varnish-Instance
X-VLoc
X-Server-FQDN
X-PG
X-Country
X-ELB
X-9XB-Server
Aurora-Node
X-HA-Backend
X-Accel-Cache-Control
X-Czt
X-Layout
X-Memcached
Copyright
MageStack-Cache
MageStack-Cache-Lifetime
Generate-Time
Tesla.Performance
MageStack-Cache-Hits
X-Server-Ident
X-Title
Session-Id
X-Cache-2
X-Instart-Cache-Id
X-IP-Address
Fw-Cache-Status
Yola-ID
MageStack-Area
X-ZORequestID
Y-Trace
MageStack-Cache-Status
MageStack-Cacheable
X-Ar-Debug
X-Cache-Served
X-Optimization
X-Svr
OutputRewritten
X-Imforza-Hosted
X-Ants-Host
X-Ants-Machine-Id
X-BC
X-HA-Frontend
X-ProBase-Server
X-NewCloud-V-Cache
MageStack-Magento-Version
MageStack-Loadbalancer
MageStack-Debug
MageStack-Config
MageStack-PageSpeed
MageStack-Tag
X-ACLR-Version
X-Backend-TTL
MageStack-Web-Node
X-Nginx-Request-Time