Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
P3P
X-AspNet-Version
Age
X-Pingback
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Language
X-Template
X-Generator
X-Buckets
Alt-Svc
X-Request-Id
X-Drupal-Cache
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Powered-By-Plesk
Content-Location
X-Permitted-Cross-Domain-Policies
X-Download-Options
Host-Header
X-Runtime
MS-Author-Via
X-ShopId
X-Dc
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-FRAME-OPTIONS
Cartoon
X-Powered-CMS
X-IPLB-Instance
X-UA-Device
X-Served-By
X-Amz-Cf-Id
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Status
Access-Control-Allow-Methods
X-Cache-Status
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
CF-Cache-Status
X-Backend
Referrer-Policy
X-Contextid
X-DIS-Request-ID
X-Mod-Pagespeed
X-PC-Key
X-PC-Hit
Powered-By
X-PC-Date
X-PC-Host
X-PC-AppVer
Content-Encoding
X-WPE-Loopback-Upstream-Addr
X-CST
X-ServedBy
X-Server
X-Logged-In
Keep-Alive
X-Request-ID
X-Host
X-Cache-Hit
X-Port
P3p
X-CDN
X-Rid
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Server-Powered-By
X-Cache-Enabled
X-Tumblr-Pixel-1
X-Endurance-Cache-Level
X-Robots-Tag
X-Nginx-Cache-Status
X-Accel-Version
X-Seen-By
X-Wix-Request-Id
X-Wix-Server-Artifact-Id
X-Turbo-Charged-By
X-Tumblr-Pixel-2
X-Page-Speed
X-Original-Date
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
WP-Super-Cache
X-Content-Digest
X-Proxy-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-AH-Environment
X-Rack-Cache
X-Varnish-Cache
X-GitHub-Request-Id
X-Tumblr-Pixel-3
X-Ua-Compatible
X-LiteSpeed-Cache
X-Request-Country
X-XRDS-Location
Edge-Control
SPRequestGuid
X-Cnection
X-SharePointHealthScore
X-MS-InvokeApp
X-Cache-Lookup
MicrosoftSharePointTeamServices
X-Died
X-Node
Timing-Allow-Origin
X-Amz-Id-2
X-Amz-Request-Id
Cf-Railgun
X-FW-Hash
Charset
X-Trace
X-FW-Type
X-FW-Static
X-FW-Serve
X-Webserver
Edge-Cache-Tag
X-Webcom-Cache-Status
X-Content-Security-Policy
Request-Id
X-FullPageCaching
X-HS-Cache-Config
X-PhApp
MicrosoftOfficeWebServer
X-HS-Content-Id
X-Safe-Firewall
X-CF-Powered-By
X-PHP-Backend
X-Hits
X-INKT-SITE
X-INKT-URI
Composed-By
SPIisLatency
SPRequestDuration
Request-Context
Access-Control-Max-Age
X-Newrelic-App-Data
X-BC-Stapler
Access-Control-Expose-Headers
X-Swift-CacheTime
X-Swift-SaveTime
EagleId
Served-By
Grace
X-Spip-Cache
X-CDN-Pop-IP
X-CDN-Pop
X-Hyper-Cache
Liferay-Portal
X-Tumblr-Pixel-4
X-Backend-Server
X-Dw-Request-Base-Id
X-Device
X-Server-Name
X-Fastly-Request-ID
X-Wix-Renderer-Server
X-Microcache
X-LiteSpeed-Cache-Control
X-VCache
X-SERVER
X-ServerName
X-FB-Debug
X-Clacks-Overhead
Content-Style-Type
X-Cloud-Trace-Context
X-Servedby
Public-Key-Pins
Content-Script-Type
X-RateLimit-Remaining
Rating
X-RateLimit-Limit
X-Firenze-Processing-Times
X-User-Agent
Real-Hostname
X-Loop
X-TNCMS
X-Acc-Exp
Surrogate-Control
X-RateLimit-Reset
Front-End-Https
Refresh
X-DDC-Arch-Trace
X-Jimdo-Wid
X-Jimdo-Instance
X-Cache-Config
X-SS-Location
X-SS-Conf
X-XN-XNHTML
X-XN-Trace-Token
Fpc-Cache-Id
X-Microcachable
X-Middleton-Display
X-Middleton-Response
Display
Response
Xkey
X-Sol
X-Hostname
X-Age
X-StackifyID
X-HS-Combine-CSS
X-Tumblr-Content-Rating
X-Generated-By
X-N-OperationId
X-Cached
X-DNS-Prefetch-Control
X-Zen-Fury
X-Cdn
X-Px
X-OneAgent-JS-Injection
X-Topify-Platform
X-Tumblr-Pixel-5
X-Vtex-Processado-Em
PageSpeed
X-Cached-By
X-Url
X-Correlation-Id
X-Request-Time
TCN
Edge-Control-Message
X-Whom
X-MiniProfiler-Ids
X-Frame-Option
X-Amz-Version-Id
X-Ruxit-JS-Agent
X-WebKit-CSP
X-CMS-Version
Product
X-DynaTrace-JS-Agent
X-Magento-Tags
P-WS
P-LB
X-Content-Options
Surrogate-Key
Rt-Fastcgi-Cache
X-Kinsta-Cache
X-Handled-By
X-Outils-CS
X-URL
X-Varnish-TTL
X-B-Cache
X-Via-JSL
X-Forwarded-For
X-VARNISH-Cache
X-DynaTrace
X-AspNetWebPages-Version
Imagetoolbar
Access-Control-Request-Method
Host
X-Edge-Location
Fastly-Debug-Digest
X-Recruiting
Powered
X-Engine
ServedBy
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-HOST
X-Cache-Rule
X-CacheServer
X-Umbraco-Version
X-Varnish-Cache-Hits
Alternate-Protocol
X-FORWARDED-FOR
Fhost
X-Track
X-LBLID
X-Debug-Info
X-NWS-LOG-UUID
X-Msg-2-Log
X-Signature
X-Goog-Hash
No
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-Powered-By-VTEX-Janus-ApiCache
X-PERF
X-VTEX-Janus-Router-Backend-App
X-ApacheServer
X-VTEX-Cache-Status-Janus-ApiCache
X-Actual-URL
X-Application-Context
DynaTrace
X-Passed-To-DLL
X-Location-Id
X-Passed-To
X-Original-Request
X-Returned-From
X-Returned-From-DLL
X-From
X-Response-Time
X-Returned-From-PostProcessResponse
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
Generator
X-Returned-From-BeforeDispatch
X-Powered-By-360WZB
WZWS-RAY
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Powered-By-VTEX-Janus-Edge
X-Platform
X-Stale
X-Micro-Cache
Public-Key-Pins-Report-Only
X-Hosted-By
Akamai-IP
Dmn
X-Pantheon-Site
X-Pantheon-Phpreq
X-Pantheon-Environment
X-Developer
Surrogate-Key-Raw
X-Cache-Age
Origin
X-Upstream
X-LW-Cache
HTTPS
X-Accel-Expires
X-Supported-By
Arr-Disable-Session-Affinity
X-UD-Method
X-Varnish-Host
X-Cache-Info
Fastcgi-Cache
X-RESOURCE
X-Cache-TTL
X-TransIP-Balancer
X-Source
X-Rocket-Nginx-Bypass
X-URLSCHEME
X-Director
X-Device-Type
X-Version
Retry-After
X-S
X-LB
X-Platform-Router
X-Platform-Processor
X-Tumblr-Pixel-6
X-Fastcgi-Cache
X-Shop-Id
X-Defender
X-CSRF-Protection
X-TransIP-Backend
Content-Hash
X-F-Cache
X-Platform-Cluster
X-Rnd
X-Matrix-Server
X-Matrix-Proxy
X-NetCat-Version
X-EdgeConnect-Origin-MEX-Latency
X-BS
X-Instart-Request-ID
X-I-Sp
X-App-Hosting
X-Powered-By-VelaWeb
X-HS-Content-Campaign-Id
X-Art-Request-Id
X-AOL-HN
Cache-Provider
Last-Published
X-EdgeConnect-MidMile-RTT
X-Dispatcher
X-Storage
X-LB-Node
IBM-Web2-Location
Version
X-Varnish-HitMiss
X-Magento-Cache-Debug
X-Varnish-Count
X-Cache-Key
X-Translation
Pagespeed
X-Microcache-Status
X-ATG-Version
X-Daa-Tunnel
X-Gamma-Serve
X-Front
Pool
X-Page-Cache
X-Drupal-Cache-Tags
USPLoggingUUID
Ohc-File-Size
RTSS
X-Cache-Tags
X-Hypernode
Allow
X-Route-Server
MIME-Version
X-Cache-Operation
X-Expires-Orig
X-Cache-Debug
SSPAppContext
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-Varnish-RemainingLife
Node
Powered-By-ChinaCache
X-Ua-Device
X-ARC
X-I
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Loopia-Node
X-Platform-Server
X-UPSTREAM
X-Server-Upstream
X-Flow-Powered
X-Revision
X-Server-ID
X-NoCache
Lsrequestid
X-SSL-Protocol
X-SSL-Cipher
X-Content-Encoded-By
Cache-Key
X-Lambda-Id
Content-Disposition
X-Varnish-Age
X-Dns-Prefetch-Control
X-Platform-Cache
X-Generated
X-Hiawatha-Cache
X-SV-CacheTags
X-SV-Nginx-Duration
X-SV-Pid
X-Environment
X-SV-FromDBCache
X-SV-Expires
X-SV-Cacheable
X-SV-CreatedAt
X-SV-Duration
X-SV-Edge
X-Varnish-Cacheable
X-Drupal-Cache-Contexts
X-Dispatch
Content-MD5
X-Edge-IP
Location
Content-Encoding-Handler
Wsr-Cache
Accept-Encoding
X-Cache-Only-Varnish
X-Id
X-Grace
X-Abgroup
X-Cache-Expires
X-Url-Base
X-GeoIP-Country-Code
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
S-Cnection
X-Client-IP
Page-Completion-Status
X-VTEX-Cache-Status-Janus-Edge
X-RequestId
X-IsCacheURL
X-Debug
X-Ttl
Section-Io-Id
X-Firenze-Processing-Time
X-CJ-Soft
X-Cache-Control-Orig
X-Duration
X-Proxy
X-Sentry-ID
Pv
X-Cache-Lifetime
X-Cache-Server
If-Modified-Since
X-Nbs
X-Country-Code
ServerName
ServerID
X-Sucuri-ID
X-Cache-Engine
X-TTL
X-Ezoic-Cdn
Srv
X-Content-Age
X-N
Proxy-Connection
X-Sapient
Fw-Via
X-Litespeed-Cache
FAI-W-FLOW
Backend
X-Geo-Country
Cneonction
X-Amz-Meta-S3cmd-Attrs
X-PwB-Node
X-Vhost
PICS-Label
X-Location
SN
X-Cache-Type
X-ServerID
NetMindSessionID
X-Magento-Cache-Control
X-Processing-Time
X-Discourse-Route
Server-Name
X-Server-Id
Req-Id
Author
X-Speed-Cache-Key
SRV
X-Speed-Cache
IM-Version
X-Browser
X-Time
X-Yadis-Location
X-Dynatrace-Js-Agent
X-Orig-Vary
X-Always-Cache
X-Sucuri-Cache
X-SRCache-Key
X-Cache-Level
X-Cache-Fix
X-Cache-PageType
X-Cookie-Domain
X-Cache-Control
Accept-Charset
Server-Info
Nodo
Cm-Server
X-Pressidium-NinukisWP-Ver
X-NB-Cached-Page
X-Akamai-Device-Model
X-Runtime-Rack
X-Middleware-Start
X-Akamai-Device-Characteristics
X-GeoIP-Country-Name
X-Last-Modified
X-Nginx-Cache
X-Processed-By
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Worker
X-Varnish-Url
X-Goog-Stored-Content-Length
X-Shield-Request-Id
NnCoection
X-Akamai-Transformed
Qs-Cache
X-GUploader-UploadID
Thanks
X-Varnish-Backend
X-BackendServer
X-SERVER-NAME
X-Cache-Namespace
X-Real-Server
X-ACMCache
X-Magnolia-Registration
Use-Proxy
X-Frontend
X-FW
X-Config-Blacklist-Version
Cached
HAVer
X-Purge-URL
HCVer
X-App-Server
X-Webkit-CSP
X-Cache-CFC
X-Traffic
X-Route-To
Cache
AMF-Ver
X-SO
X-SDS
X-Litespeed-Cache-Control
X-Forwarded-Proto
SiteSpeed
Xc-Version
X-Abuse
SVR
X-BKSrc
X-Purge-Host
X-Framework
Pf.Web.Request.Id
X-DealerOn
EagleEye-TraceId
X-CDN-Forward
X-Server-IP
X-JG-Page-Cache
X-Sys-Req-ID
S
A-Powered-By
X-CF-Passed-Proto
X-High-Performance
Local-Info
X-Cache-Device-Type
X-Varnish-Retries
X-Cluster-Node
X-Amz-Storage-Class
X-Origin
Pics-Label
X-Varnish-IP
X-Jphone-Copyright
MC
Server-Timing
SEOMOZ
X-SRV
X-Garden-Version
X-Srv
MJ12bot
X-Session-ID
X-FTR-Request-ID
X-Dev
X-Empowered-By
X-Cms-Mode
X-Culture
X-FastCGI-Cache
Worker
X-Webstats-RespID
X-Content-Type-Option
X-Varnish-Hits
Cache-Tag
W
WN
X-Drectory-Script
X-WR-Flags
X-ClientSide-Caching
X-Cf-Powered-By
X-Connection-Hash
X-LB-Server
X-Mobilized-By
X-Twitter-Response-Tags
X-WN-ClientGroup
X-DataDome
X-Transaction
Keywords
X-Rocket-Nginx-Serving-Static
X-PF-Uncompressing
X-Sorting-Hat-Expire-Cache
HitType
X-Remote-Addr
X-Balanceador
Eomportal-Instance
X-ARRServer
X-AF-Userserver
P-ID
X-VARITI-CCR
Nitro-Cache
Frame-Options
Tracecode
WWW-Authenticate
X-Amz-Meta-Cb-Modifiedtime
Magicmarker
X-Yottaa-Metrics
X-Varnish-ID
Proxy-Agent
X-LW-Web-Server
Content-Transfer-Encoding
X-LP
X-Yottaa-Optimizations
Dispatcher
X-Runtime-Memory
X-OpenCart-Lightning
AC-ELC
X-Redman-Final-Url
Backend-Timing
X-Redman-Backend
X-Directory-Script
X-AVG-Country-Code
X-Analytics
X-Clara-ASAP
X-Akamai-Edgescape
X-Runtime-Affili
X-Avg-Cookie-Expires
X-Client-Vid
X-App-Runtime
X-ASAP-Cache
X-Cache-TTL-Remaining
X-VNode
X-Hit-Cache
X-Detected-Device
X-Provisioner-Version
X-Cache-Doesi
Description
X-HW
X-GeoIP
Ufe-Result
X-Domain-Checked
X-App-Status
X-EPiphany-Vid
X-Pagename
X-Client-Image-Vid
X-HTML-Minification-Powered-By
X-NginX-Cache
Max-Age
Adm-Server
VANITY-HOST
X-App
X-Adobe-Loc
Web-App-Origin-Name
X-Cache-Handler
X-Adobe-Content
X-Content-Security-Policy-Report-Only
X-Unbounce-VisitorID
X-Varnish-Ttl
Content_type
X-FireWall-Port
XDomainRequestAllowed
X-Server-Instance
X-Unbounce-PageId
CacheControlHeader
X-Unbounce-Variant
X-Generated-Time
NODE
Cleartype
X-WPL-DATA
X-Atraveo-Cache-Control
X-Atraveo-From-Varnish-Cache
CLMOB
Play-Detected-Device
X-Atraveo-ETag
X-Atraveo-Param-Rm
X-Atraveo-TTL
X-Atraveo-Zone
X-Atraveo-Expires
X-Force
Play-Detected-UserAgent
X-Atraveo-Set-Cookie
X-PRAM
X-Atraveo-Varnish-Server-Id
X-HP-Trace-ID
ServerTokens
X-Key
X-Varnish-Hostname
ServerSignature
X-Debug-Token
X-RiS-UFDI
X-Varnish-Debug-TTL
X-Source-ID
X-Varnish-Debug-Age
X-GoCache-CacheStatus
Cteonnt-Length
X-Plat
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Amcomm-Site
X-HP-Trace-Project
X-Mobile-URL
BALANCEDTO
X-ServerIndex
X-Page
X-Akamai-3PM-SW-Version
X-MCB-Server
X-AEM
Noq
X-Webkit-Csp
X-Rq
Cache-Tags
Ramp
From-Origin
Front
X-WP
X-CB-Server
Ram
X-CAPServer
X-ID
X-HOSTNAME
X-Cache-Node
X-ORACLE-DMS-RID
X-Disney-Akamai-Rule
X-Correlation-ID
Machine
SERVER-ID
NLCacheNote
Cmstype
SBGI-RenderTime
X-Esi
Cmsid
SBGI-RealPath
SBGI-7
SBGI-1
SBGI-9
Contao-Page-Layout
X-Fedora-School-Id
X-Resty-Request-Id
X-Unique-ID
X-Backend-Status
AMP-Access-Control-Allow-Source-Origin
Beyond-Iis
X-Unique-Id
SBGI-5
SBGI-Device
X-Nginx-Host
SBGI-10
X-SmugMug-Hiring
From
X-Data-Request
X-Compressed-By
Access-Control-Allow-Header
ViewMode
X-TTFB-L
X-Symfony-Cache
Disablevcache
X-WebKit-CSP-Report-Only
X-Wikidot-Static-Cache
OriginServer
X-TTFB
X-CDN-RULE
X-CDN-COMPRESS
X-Wikidot-Backend
X-SmugMug-Values
Strikingly-Cached
X-Real-IP
Smug-CDN
X-Env
X-HashTwo
X-Smartcache-Keys
X-Frames-Options
Og
Service-Worker-Allowed
X-Resolver-IP
X-Trace-Id
Resin-Trace
X-Varnish-Server
X-Smartcache-Timeout
Strikingly-Cache-Region
X-Cache-Keep
X-Info
X-NginX-Server
X-OPNET-Transaction-Trace
X-HydroSheep
X-CacheResult
Strikingly-Cached-Version
Lb
X-VC-Enabled
X-V
X-Stage
Fastly-Backend-Name
Bios
X-IIJ-Cache
Device
X-A
X-Varnish-Ip
X-Dynamic-Cache
X-Autoru-LB
X-AutoRu-App-Id
X-Autoru-Host
MS-CV
Dis-Env
X-Proto
Id
Web
X-Airee-Node
X-VC-TTL
X-Rack-CORS
TC-Cache-IC
TC-Cache-U
CommunityServer
TC-S-Cache
Nginx-Cache
TC-Cache
X-E
COMMERCE-SERVER-SOFTWARE
WebServer
X-Ser
X-Cache-Dispatchercachecontrol
X-Cache-Dispatcherpragma
X-TB-M
X-L-Path
X-GSL-Server
X-Distributor
Paypal-Debug-Id
X-Webcelerate
X-Environment-Context
TC-S-Cache-M
X-Req-Head-Response
ScoreTracker
N365rili
Ibf5scheme
X-Bip
X-Cache-On
X-Varnish-Cache-Local
Hamster
Content-Server
X-B2f-Not-Route
X-Aramark-SID
X-WR-MODIFICATION
Yoncu-Errno
X-Refresh
X-RDP
X-Render-Time
X-Adnet
X-CACHE-TTL
X-Batcache
X-Batcache-Reason
X-Captured
X-DN-Cache-Control
X-Viator-Tapersistentcookie
X-Cdn-Forward
X-FPC
X-EC2-Instance-Id
X-Gyrobase-Publication
X-MAT-GEO
X-Machine-Name
Home
Ews
ClientIP
Il-Cl
X-Sc-Cache
F5-IpCliente
Gzip
IISExport
X-Hrouter
X-Hstore
Hostname
Arrnode
X-Highwire-RequestId
X-Apm-Telemetry-Syncmark
Traffic-Origin
X-Desc
X-ENV
PagesDisplayed
X-Session-Reinit
SHInfo
Proxy-Cache
Hname
X-Pj-Cache-Status
SG
X-Dw-Trace-Id
X-Say-TTL
Viewport
Session-From
ServerIP
X-JSESSIONID
X-Middleton-PageSpeed
X-Highwire-SessionId
X-Hosting-Env
X-Header
X-Map-Context
X-Fstrz
X-Origin-Server
X-MSEdge-Ref
Custom-Header
X-Proxy-Cache-Key
X-SmartBan-Host
X-Rewrite
X-SmartBan-URL
X-Say-Cacheable
X-Hosting
X-Redirector
Identity
X-ETag
X-Confluence-Request-Time
X-DTC
X-SayCDN-TTL
Myheader
X-SDE-Name
X-Ghost-Cache-Status
X-Ss-Conf
MW-Webserver
Xc
X-W3TC-Minify
X-Grid-Server
X-RealServer
X-Cocoon-Version
X-Ss-Location
X-PM-ID
Warning
Server-Id
X-KoobooCMS-Version
AsisCache
RN-Server
Serverid
X-SH-Cache-Status
X-Goog-Meta-Replace
X-Rack-Cors
NtCoent-Length
X-Pagely-Cache
X-Protected-By
X-Goog-Meta-Policy
X-Resource
X-UA
X-HostName
X-CRA-DC
X-Your-GrandPa-Would-Wait
X-CH-Device
X-Author
X-Would-Your-GrandPa-Wait
X-Varnish-Id
SB-Site-IE-VERSION
X-TTL-Age
X-Cache-TTL-Age
Aoestatic
X-Cache-Time
X-LBPoolMember
Note
X-We-Are-Hiring
X-Enhanced-By
X-Tag-Playlist
X-Magento-Lifetime
X-Rebelmouse-Cache-Control
X-Cache-Set
X-Beatles-Hits
RequestId
X-Magento-Action
X-Bcwwwid
X-Flex-Evstart
X-DSMX-Rewrite-MS
X-Depends
X-Flex-Lang
X-Cache-TTL-Current
BackendServer
X-Src-Webcache
X-IP
X-Flex-Evend
X-DSMX-Render-MS
X-Flex-Community
X-Does-He-Have-Time
SS
Edgecast
SB-Site-Device
X-Response
X-NewCloud-V-Cache
SB-Cache-Remaining
X-Cache-Id
X-Nginx
DNNOutputCache
PServer
SB-Cache-Life
X-Rebelmouse-Surrogate-Control
Hummingbird-Cache
MageStack-Cacheable
MageStack-Cache-Status
MageStack-Cache-Lifetime
Hosted-By
X-Upstream-Backend
MageStack-Config
MageStack-Magento-Version
MageStack-Loadbalancer
X-VC-Cache
MageStack-Debug
MageStack-Cache-Hits
X-Avvio-Cms-Cacheload
X-Machine
Accept-Language
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-RemovedCookies
X-ASAP-Age
MageStack-Area
X-Old-Content-Length
Ctx
MageStack-Cache
X-CacheID
MageStack-PageSpeed
X-ProcessESI
X-Amz-Id-1
MageStack-Web-Node
X-Server-Generated
X-Cluster
X-Forwarded-Host
X-Backend-TTL
X-Timestamp
VServer
X-Cache-Me-Harder
X-Cache-Detail
X-Flex-Lastmod
X-Flex-Tag
User-Agent
X-Powered-By-Home.Pl
MageStack-Tag
X-Origin-Cache
X-M
X-Amz-Meta-S3b-Last-Modified
X-Flex-Tags
X-Backend-Host
X-Beatles
X-Streams-Distribution
X-Litespeed-Tag
X-ACCELERATE
X-HAProxy
X-HS-Status
X-CSRF-Token
X-Reflector-Cache
Provider
Server-Ip
NZSpeedy
X-SV
X-Varnish-Action
X-Serv
X-Netrix-ID
X-4ormat-Cacheable
X-Reflector
X-DEBUG
X-HP-CAM-COLOR
X-Dynatrace
X-RAMCache
X-Served-Server
X-DB-Content-Length
Url
X-Lw-Cache
X-ReqId
X-Server-Addr
X-WA-Info
X-Varnish-URL
Fastly-Restarts
Yola-ID
X-Pixelsilk-Version
CDCHOST
Y-Trace
X-Pixelsilk-Server
WP-AdvCache-MemCached
X-Max-Age
X-Full-Url
X-Cjtype
X-Pubstack
X-Rewritten-By
X-Test-Debug
X-XHTML-Minification-Powered-By
X-ManagedFusion-Rewriter-Version
X-Distil-CS
X-Domino-CacheValidationWithETagResult
X-Domino-CacheValidationWithETagReason
X-Blog
Cacheid
X-CPU-Time
X-MidCOM-Meta-Cache
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-ZORequestID
X-Cache-Original-TTL
ServerNode
Www.Aujourdhui.Com
X-Backend-Name
X-Gateway-Cache-Key
X-Title
Tempo
Upgrade-Insecure-Requests
RSB-LINK
Microcache
EQ-Cache
X-Cname-TryFiles
X-Deity
X-Served
X-Server-Ip
Ttl
X-Made-On
X-Amz-Meta-Content-Md5
Control-Cache
AR-SID
X-Header-Treatment
X-Custom-Header
X-DevSrv-CMS
X-Enabled3
X-Enabled2
X-Route
X-CCM
AR-CACHE
AR-PoweredBy
AR-ATIME
!~Request-OOB-Work
X-Router
Generate-Time
PB-PID
X-VC-Cacheable
X-Accel-Cache-Control
Copyright
X-UT-Cache
X-Mobile-Rewrite
X-Turpentine-Esi
X-Search-Id
X-Memcached
X-Server-Ident
X-SCM-Server-Number
X-Layout
X-Czt
X-HA
X-FastCGI-Cache-Status
Uuri
X-Activity-Id
Tesla.Performance
Quri
PB-RID
X-AppVersion
X-Az
X-DynamicCache
X-VC-Debug
X-VC-Hash
X-Debug-Message
X-Enabled1
X-Not-Cacheable
X-REDIRECTSERVER
X-Geo-IP
X-Skip-Cache
X-Upgrade-Enabled
X-7d-Trace-Id
X-7d-Instance-Id
X-Container
X-Client-Ip
X-Agent
TP-L2-Cache
X-Application
X-Box
X-Cache-Extended
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-D-Time
X-Config-By
X-Generation-Time
X-Node-Name
X-S-Misc
X-PHP-Response-Code
X-Cache-Varnish
X-AppServer-Cache-Rule
X-SuperCache
X-Hash
X-Uncacheable
Kanooh-Host
Progma
TP-Cache
INFO
XDisk
X-BeResp-Ttl
DrivedBy
NS-VaryByCustom-Key
X-Cache-FS-Status
Services
Referer
Provided-Host
X-Fastly-Request-Id
X-WebServer
X-ProBase-Server
X-SE-Debug
AccessControlAllowOrigin
X-Catalyst
X-Instance-Id
X-PBS-Appsvrname
X-PBS-Appsvrip
X-PBS-Fwsrvname
X-Upstream-Status
FRONT-END-SECUREBROWSER
X-Wix-PunisherID
X-NewsFlow-Sitename
X-MainProfileCategory
X-LOCATION
X-MainProfileID
X-MainProfileName
X-MainProfileURL
X-Time-Microsecs
Access-Control-Request-Headers
Server-ID
X-DS1D
X-Gannett-Site-Version
X-Instance
MwpReleaseVersion
MachineName
Access-Control-Allow-Method
X-Node-ID
Debug-Status
Expiries
X-Secret
X-SilverStripe-Cache
X-RequesterIP
X-UnsetCookies
X-Zendesk-Origin-Server
X-Zendesk-User-Id
X-NodeID
X-Nginx-Request-Processing-Time
X-Status
X-AMAZEEIO
X-Cache-Via
X-Cache-V
X-Artvisual-Server
X-AISO-Cache
Cache-Status
StatusCode
Response-Time
X-XHR-Current-Location
EN-User
X-AISO-Cacheable
X-AISO-Server
X-Cache-Ttl
X-ESI
X-Ssl-Cipher
X-FORWARDED-PROTO
Dynatrace
X-Oneagent-Js-Injection
X-Oracle-DMS-ECID
X-Ruxit-Js-Agent
X-Lb
X-LB-Backend
X-LB-Frontend
X-Instance-Name
X-Meta-MSThemeCompatible
Actual-Object-TTL
CD4
TTL
X-Wm-VIP
X-Wm-1
X-Meta-MSSmartTagsPreventParsing
X-Restarts
X-Server-Vrn
X-Meta-Imagetoolbar
MSThemeCompatible
X-MCF-ID
X-Nitro-Cache
X-Script
X-ServerAddr
X-Fpc
X-Built-With
Request-Time
X-B3-Spanid
X-B3-Traceid
X-Sn-Servicetimems
X-UPServer
MSSmartTagsPreventParsing
X-WHO
Realaction
WP-FROM-CACHE
Httpd-Identifier
CS-SERVER
X-Varnish-Cached
X-Varnish-Cached-TTL
Actioncode
X-Cache-Warmer
X-Archive-Orig-Connection
X-Cache-Date
Prototype-RootPath
Key
X-Debug-Serve
Powered-By-VeryCDN
Language
X-Request-Received
X-Server-App
Publisher
Ec-Machine
CpuTime
X-Varnish-Esi-Method
X-Varnish-Store
X-Origin-Upstream-Status
X-Serverid
X-Varnish-Esi-Access
X-Varnish-Currency
GranicusServer
X-Ants-Host
X-Fastly-Backend-Reqs
X-ElasticPress-Search
X-Request-Processing-Time
X-Archive-Orig-Date
X-S-C
X-Archive-Orig-ETag
X-Q-S
X-Archive-Orig-Content-Length
Ec-CorrId
X-Transaction-Name
X-S-V
X-Archive-Guessed-Charset
X-Archive-Orig-Server
X-Mw-Workerstats
X-M-T
X-PBY
X-M-P
X-I-V
X-FIRSTBase
X-Built-By
X-AWS
X-M-V
Load-Balancer
Memento-Datetime
X-Config-Version
X-Nginx-Page-Cache
X-Powered-Developer
Page-Template
RlogId
Cache-Ctrol
Requested-Host
X-CO-Host
SINA-TS
SINA-LB
X-9XB-Server
X-EBAY-C-REQUEST-ID
X-COUNTRY-CODE
X-PROCESSED-BY
ReqUrl
OutputRewritten
WSCLoggingUUID
X-FG-RequestId
X-Cache-Served
X-Ar-Debug
X-Clx-Request
X-Cache-Bypass
X-PG
CmsfirstPublishTimestamp
X-ELB
X-VLoc
X-Server-FQDN
X-Time-Zone
X-Varnish-Instance
X-ServiceProvider
Countrycode
X-Country
X-MSU-SOURCE
X-This-Proto
X-Svr
X-SID
X-VG-WebCache
Head
UrlWatchModule-Time
Apple-Itunes-App
X-Varnish-Grace
ATI-Server-Id
X-Sid
X-Via-NSCOPI
Content-Cache
X-Rocket-Nginx-Reason
X-Rocket-Nginx-File
X-ACLR-Version
X-DeliveryServer
X-Dynamic
DbServerName
FindLaw
XX
Cookie
DB-Nickname
X-Service-Id
X-Proxy-Id
Rewriter
Webserver
X-Distributed-By
X-Brought-To-You-By
VAR-Cache
X-BC
X-Ants-Machine-Id
Fw-Cache-Status
AMFplus-Ver
Accept-CH
Aurora-Node
X-Who
X-ZSITES-DNS
Session-Id
X-Cache-2
X-WAF-Proxy
VC-NoCache
E-TAG
X-VCS-Ttl
X-VCS-Cacheable
X-Instart-Cache-Id
X-IP-Address
X-Nginx-Request-Time
IES-Server