Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
CF-RAY
X-Cache
Age
Content-Language
X-AspNet-Version
P3P
X-Pingback
Expect-CT
X-UA-Compatible
Via
Upgrade
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Request-Id
X-Adblock-Key
Referrer-Policy
X-Varnish
X-Check
X-Generator
X-Language
X-Template
X-Buckets
X-Drupal-Cache
P3p
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-Xss-Protection
Alt-Svc
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-AspNetMvc-Version
X-Cache-Hits
Host-Header
X-Ac
X-Hacker
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-ShopId
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PodId-Cached
X-Powered-By-Plesk
X-Runtime
X-Served-By
X-Via
MS-Author-Via
Content-Location
X-Amz-Cf-Id
X-Powered-CMS
X-Contextid
Access-Control-Allow-Headers
X-IPLB-Instance
X-UA-Device
X-ServedBy
Access-Control-Allow-Methods
X-PC-Hit
X-PC-Key
Cartoon
Status
X-PC-Date
X-PC-AppVer
X-PC-Host
X-Timer
Access-Control-Allow-Credentials
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
CF-Cache-Status
X-Iinfo
X-Rid
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Wix-Request-Id
X-Seen-By
X-Backend
X-NewRelic-App-Data
X-WPE-Loopback-Upstream-Addr
Powered-By
X-Tumblr-Pixel-1
Content-Encoding
X-Mod-Pagespeed
X-Cache-Status
X-Host
X-CST
X-Tumblr-Pixel-2
X-Server
X-Endurance-Cache-Level
X-Cache-Enabled
X-Cache-Hit
X-Port
Keep-Alive
X-Logged-In
X-CDN
X-Server-Powered-By
X-DIS-Request-ID
X-Nginx-Cache-Status
X-Drupal-Dynamic-Cache
X-Tumblr-Pixel-3
X-Robots-Tag
X-Accel-Version
Server-Timing
X-Turbo-Charged-By
X-Proxy-Cache
X-Page-Speed
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Content-Digest
X-Content-Powered-By
X-LiteSpeed-Cache
X-GitHub-Request-Id
X-Rack-Cache
Content-Security-Policy-Report-Only
X-ASPNET-VERSION
X-AH-Environment
X-Pad
X-Varnish-Cache
Edge-Control
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Serve
Request-Context
X-XRDS-Location
X-Request-Country
SPRequestGuid
WP-Super-Cache
X-Newrelic-App-Data
X-SharePointHealthScore
X-MS-InvokeApp
X-Tumblr-Pixel-4
X-Hits
X-Trace
X-Webcom-Cache-Status
MicrosoftSharePointTeamServices
Timing-Allow-Origin
Cf-Railgun
X-BC-Stapler
X-Node
Edge-Cache-Tag
X-HS-Cache-Config
X-Amz-Request-Id
X-Ua-Compatible
X-Amz-Id-2
Access-Control-Expose-Headers
X-HS-Content-Id
X-Cache-Lookup
X-Died
Charset
X-Content-Security-Policy
X-CF-Powered-By
X-Webserver
X-PhApp
X-FullPageCaching
X-Cnection
Access-Control-Max-Age
X-HS-Combine-CSS
Request-Id
X-Fastly-Request-ID
X-INKT-URI
X-INKT-SITE
X-PHP-Backend
SPIisLatency
SPRequestDuration
EagleId
X-Backend-Server
X-Swift-CacheTime
X-Swift-SaveTime
MicrosoftOfficeWebServer
X-CDN-Pop
X-CDN-Pop-IP
Composed-By
Grace
X-Request-ID
X-SS-Location
X-SS-Conf
X-Safe-Firewall
Served-By
X-Device
Liferay-Portal
Rating
X-Spip-Cache
X-Hyper-Cache
X-Server-Name
X-Dw-Request-Base-Id
Front-End-Https
X-NF-Request-ID
X-DDC-Arch-Trace
X-Microcache
X-Cloud-Trace-Context
X-Tumblr-Pixel-5
X-VCache
X-Edge-Cache
X-Edge-Cache-Key
X-Tumblr-Content-Rating
X-HeyJason
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-RateLimit-Remaining
X-LiteSpeed-Cache-Control
X-RateLimit-Limit
X-RateLimit-Reset
X-Jimdo-Instance
X-Jimdo-Wid
X-Cluster-Node
X-FB-Debug
X-Loop
X-TNCMS
X-Clacks-Overhead
X-Wix-Punisher
X-Sol
Display
Surrogate-Control
X-Middleton-Display
X-Acc-Exp
Response
X-Middleton-Response
Content-Style-Type
Refresh
P-LB
P-WS
Content-Script-Type
X-Vtex-Processado-Em
Public-Key-Pins
X-OneAgent-JS-Injection
X-DNS-Prefetch-Control
X-Firenze-Processing-Times
X-Debug-Info
X-Age
X-StackifyID
X-SERVER
X-Kinsta-Cache
X-User-Agent
X-Magento-Tags
Fpc-Cache-Id
X-Goog-Hash
X-Px
X-Cache-Config
X-XN-Trace-Token
X-Cached
X-XN-XNHTML
X-WebKit-CSP
X-Amz-Version-Id
Xkey
X-Ruxit-JS-Agent
X-Shopid
X-N-OperationId
X-Sorting-Hat-Shopid
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Featureset
X-Shardid
X-Sorting-Hat-Podid-Cached
X-Sorting-Hat-Podid
X-Original-Date
X-Generated-By
X-Hostname
Retry-After
X-Zen-Fury
PageSpeed
X-Frame-Option
X-URL
X-Tumblr-Pixel-6
X-DynaTrace-JS-Agent
X-Handled-By
X-Topify-Platform
X-Loopia-Node
X-LW-Cache
X-MiniProfiler-Ids
Rt-Fastcgi-Cache
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-B-Cache
X-Cdn
X-Whom
X-Edge-Location
X-Varnish-TTL
X-Upstream
Edge-Control-Message
Access-Control-Request-Method
X-Url
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-CMS-Version
Feature-Policy
X-Request-Time
X-Cached-By
X-Servedby
Fastcgi-Cache
X-Outils-CS
X-Engine
Powered
TCN
X-Content-Options
X-Source
Fhost
X-From
X-AspNetWebPages-Version
X-FORWARDED-FOR
ServedBy
Public-Key-Pins-Report-Only
X-EdgeConnect-Origin-MEX-Latency
X-Accel-Expires
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Varnish-Host
X-Signature
Pagespeed
X-EdgeConnect-MidMile-RTT
X-Recruiting
X-Powered-By-VTEX-Janus-ApiCache
X-CacheServer
X-VTEX-Cache-Status-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-Vtex-Remote-Cache
No
X-Vtex-Processed-At
X-Developer
X-RESOURCE
Product
Allow
X-DynaTrace
X-Version
X-Magento-Cache-Debug
X-Varnish-Cache-Hits
X-Application-Context
X-F-Cache
Warning
X-Response-Time
X-URLSCHEME
Last-Published
X-Correlation-Id
Imagetoolbar
X-Location-Id
X-Umbraco-Version
X-Forwarded-For
X-Shop-Id
Generator
X-ApacheServer
Host
X-PERF
X-Defender
X-Actual-URL
X-LBLID
X-Platform-Cache
X-Passed-To-DLL
X-Varnish-Beresp-Grace
X-Passed-To
X-Returned-From-DLL
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-NWS-LOG-UUID
X-Returned-From
X-Original-Request
DynaTrace
X-Stale
X-Returned-From-PostProcessResponse
X-Powered-By-360WZB
X-UD-Method
X-Returned-From-BeforeDispatch
X-Guploader-Uploadid
X-Microcachable
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
Origin
X-Micro-Cache
X-Cache-Key
Arr-Disable-Session-Affinity
X-Device-Type
X-ET-API-ROOT
X-ET-API-ORIGIN
X-ET-API-VERSION
X-Via-JSL
X-Cache-Namespace
X-Platform-Server
X-Hosted-By
X-Environment
Alternate-Protocol
X-S
X-Cache-Info
X-Fastcgi-Cache
X-Varnish-HitMiss
X-Varnish-Count
Content-Hash
X-Platform
X-Cache-Rule
Version
X-Ezoic-Cdn
Cache-Provider
X-Msg-2-Log
X-Dns-Prefetch-Control
X-I-Sp
X-SO
WZWS-RAY
X-Rnd
X-BS
X-Supported-By
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-App-Status
X-Lambda-Id
X-Instart-Request-ID
X-HOST
X-Cache-Age
X-Correlation-ID
X-Duration
X-HS-Content-Campaign-Id
X-Cache-Tags
Surrogate-Key
X-TransIP-Balancer
RTSS
X-Microcache-Status
Cache-Key
X-Translation
X-LB-Node
X-Sapient
X-Dispatcher
X-Expires-Orig
X-TransIP-Backend
X-Server-ID
X-Director
X-Cache-Control-Orig
USPLoggingUUID
X-SSL-Cipher
X-Server-Upstream
X-Front
X-SSL-Protocol
X-Page-Cache
X-Magento-Cache-Control
MIME-Version
X-Akam-SW-Version
Content-Disposition
X-Powered-By-VelaWeb
X-Revision
X-Vcap-Request-Id
X-Hypernode
X-Track
X-Abgroup
X-Edge-IP
X-Rocket-Nginx-Serving-Static
X-Daa-Tunnel
X-Storage
Pool
Dmn
X-App-Hosting
X-GUploader-UploadID
X-Ttl
X-Cache-Debug
Wsr-Cache
X-ORACLE-DMS-ECID
X-Dealeron-Backend
X-Varnish-GracePeriod
X-Varnish-RemainingLife
X-Geo-Country
X-Varnish-ObjectSource
X-Varnish-RemainingTTL
X-Varnish-Seen-By
X-Dealeron-Original-Url
X-CSRF-Protection
X-DealerOn
X-Cache-TTL
X-Cache-Handler
X-Last-Modified
Accept-Encoding
X-Debug
X-ARC
X-NetCat-Version
X-Powered-By-VTEX-Janus-Edge
X-Rocket-Nginx-Bypass
Akamai-IP
X-NoCache
X-Matrix-Server
SSPAppContext
X-Forwarded-Proto
Node
X-Matrix-Proxy
X-I
X-Art-Request-Id
X-Litespeed-Cache
X-Magnolia-Registration
X-Drupal-Cache-Tags
X-Dispatch
S-Cnection
SN
If-Modified-Since
X-Url-Base
X-Cache-Lifetime
X-Cache-Engine
X-Varnish-Cacheable
X-Client-IP
X-IsCacheURL
X-Hiawatha-Cache
X-ATG-Version
X-Cache-Type
Backend
X-VARITI-CCR
X-Route-Server
X-Cache-Only-Varnish
ServerID
Contao-Page-Layout
X-Gamma-Serve
X-Varnish-Url
X-Discourse-Route
X-Country-Code
X-Pressidium-NinukisWP-Ver
X-Cache-Level
Cneonction
X-Cf-Powered-By
ServerName
X-ServerName
Powered-By-ChinaCache
Author
X-Vhost
X-N
X-Generated
Content-Encoding-Handler
X-Grace
X-SDS
X-SV-Cacheable
X-SV-CacheTags
X-Drupal-Cache-Contexts
FAI-W-FLOW
X-SSLProxy
X-Varnish-Backend
X-Firenze-Processing-Time
X-SSLUpstream
X-SV-CreatedAt
X-SV-Nginx-Duration
X-Cache-Operation
X-SV-Pid
X-Amz-Meta-S3cmd-Attrs
X-SV-FromDBCache
X-Cache-Server
X-SV-Duration
X-SV-Edge
X-SV-Expires
X-LB
Section-Io-Id
X-Svr-Proxy
Page-Completion-Status
AMF-Ver
X-SVR-IIS
X-Flow-Powered
Proxy-Connection
X-Cache-Expires
X-Processing-Time
X-LB-Server
X-SRCache-Key
X-CJ-Soft
PICS-Label
X-Content-Encoded-By
X-Cache-Device-Type
X-Service-Id
X-ServerID
X-Pantheon-Environment
X-Pantheon-Site
X-Pantheon-Phpreq
Update-Time
Surrogate-Key-Raw
X-Frontend
X-GeoIP-Country-Code
Src-Update
Lsrequestid
IM-Version
X-Server-Id
X-PwB-Node
Req-Id
Srv
X-FTR-Request-ID
SiteSpeed
X-TransIP-Reserved
X-Browser
X-Unbounce-PageId
X-TTFB-L
X-Unbounce-Variant
X-Nbs
X-UPSTREAM
X-Sucuri-ID
X-Unbounce-VisitorID
X-Varnish-IP
Smug-CDN
X-Dynamic-Cache
X-SmugMug-Values
X-Server-Instance
Cache
X-Trace-Id
X-SmugMug-Hiring
X-Id
X-TTFB
X-SRV
X-ACMCache
X-Varnish-Ttl
X-ORACLE-DMS-RID
Location
X-Env
Pv
Nodo
Server-Name
X-Real-Server
X-Varnish-Age
X-Runtime-Rack
Qs-Cache
X-Time
X-High-Performance
X-RequestId
X-HW
X-Varnish-Retries
X-Symfony-Cache
X-FW
X-CF-Passed-Proto
Https
Edit
Tracecode
X-Config-Blacklist-Version
X-Middleware-Start
X-FastCGI-Cache
X-CDN-Forward
Xc-Version
X-Varnish-Hits
X-CacheFROM
X-Cache-Fix
MJ12bot
X-Always-Cache
Ohc-File-Size
SEOMOZ
X-Nginx-Cache
Fw-Via
X-Cache-PageType
MC
X-Esi
NnCoection
X-Sucuri-Cache
X-Speed-Cache-Key
X-Origin
IBM-Web2-Location
Use-Proxy
X-Drectory-Script
X-Transaction
X-Locale
X-Twitter-Response-Tags
X-Empowered-By
X-Speed-Cache
X-Akamai-Device-Model
X-Akamai-Device-Characteristics
X-PF-Uncompressing
X-Connection-Hash
Cache-Tags
Content_type
X-Content-Age
X-GeoIP-Country-Name
From-Origin
X-Cookie-Domain
Backend-Timing
X-Analytics
Custom-Header
NetMindSessionID
X-Purge-URL
Dtk-Cache-Check-0
X-Content-Type-Option
X-Varnish-Server
X-WR-Flags
X-Srv
Proxy-Agent
Nginx-Cache
Local-Info
X-Orig-Vary
W
X-Sys-Req-ID
X-CacheDebug
X-ARRServer
X-Dynatrace-Js-Agent
X-GoCache-CacheStatus
X-Wikidot-Backend
X-Purge-Host
X-Wikidot-Static-Cache
Strikingly-Cached
X-Rq
X-Runtime-Memory
X-LP
X-Cache-Control
X-Unique-ID
Content-MD5
X-BKSrc
X-Webstats-RespID
CacheControlHeader
X-Varnish-ID
X-Nitro-Cache
Strikingly-Cached-Version
Strikingly-Cache-Region
X-LW-Web-Server
S
X-Worker
Content-Transfer-Encoding
X-Role
Cached
X-Fedora-School-Id
X-VC-Enabled
WWW-Authenticate
X-SE-Debug
Ram
Adm-Server
Web-App-Origin-Name
Noq
Ramp
Service-Worker-Allowed
X-BackendServer
X-JG-Page-Cache
X-Litespeed-Cache-Control
Accept-Charset
Swift-Performance
X-Beget-Proxy
X-TTL
X-Adobe-Content
X-Framework
X-ID
X-Shield-Request-Id
X-CB-Server
X-Adobe-Loc
X-Proxy
X-Cache-CFC
X-VNode
X-Location
X-Culture
X-Resty-Request-Id
X-Provisioner-Version
Max-Age
Front
X-Xrds-Location
X-WP
X-RiS-UFDI
Cm-Server
X-AF-Userserver
X-AEM
X-Domain-Checked
SVR
X-Disney-Akamai-Rule
X-Amz-Rid
HCVer
X-SERVER-NAME
X-TB-M
HAVer
X-Stage
Frame-Options
X-GeoIP
X-Amz-Storage-Class
X-Key
FindLaw
X-Application
X-Now-Id
Server-Info
X-ClientSide-Caching
X-Webkit-CSP
X-Balanceador
X-FireWall-Port
X-Pool
X-SH-Cache-Status
X-HostName
X-Session-ID
X-Sedo-Request-Id
X-Origin-Id
X-Processed-By
X-Generated-Time
X-Storage-Cache-Expires
Lb
X-Vip
X-Plat
Pf.Web.Request.Id
X-Detected-Device
X-CAPServer
X-Yadis-Location
X-FIRSTBase
X-Content-Security-Policy-Report-Only
X-Webcelerate
RequestId
X-Cache-Miss-From
X-Storage-Cache-Date
Access-Control-Allow-Method
X-App
X-Storage-Cache
X-Smartcache-Timeout
X-Smartcache-Keys
X-NginX-Cache
X-RealServer
X-NginX-Server
X-App-Runtime
Device
X-Runtime-Affili
X-Amzn-Trace-Id
X-Backend-Status
Dispatcher
X-OpenCart-Lightning
Hummingbird-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
XDomainRequestAllowed
Copyright
F5-Trid-Name
SRV
X-Akamai-Edgescape
Upgrade-Insecure-Requests
X-Lw-Cache
X-HydroSheep
X-Info
X-App-Server
X-Amz-Meta-Content-Md5
F5-Trid-Value
X-A
X-IIJ-Cache
X-WPL-DATA
Access-Control-Request-Headers
CLMOB
Play-Detected-UserAgent
RN-Server
X-ServerIndex
X-Rack-Cors
Play-Detected-Device
X-Jphone-Copyright
X-Frames-Options
X-Hit-Cache
X-Pagename
AETN-DEVICE
Beyond-Iis
X-DSMX-Render-MS
AETN-EU
X-DSMX-Rewrite-MS
X-Real-IP
AETN-Latitude
X-Forwarded-Host
X-Goog-Meta-Policy
X-ESI
Traffic-Origin
X-Test
X-Varnish-Cache-Local
X-B2f-Not-Route
Proxy-Cache
VServer
AETN-Continent-Code
X-Goog-Meta-Replace
Ibf5scheme
X-MidCOM-Meta-Cache
Access-Control-Allow-Header
AETN-Country-Name
N365rili
AETN-City
Home
Il-Cl
X-Server-IP
COMMERCE-SERVER-SOFTWARE
X-Desc
NtCoent-Length
AETN-Area-Code
Num
X-GSL-Server
X-SAPP
X-Amz-Id-1
X-Say-TTL
X-Captured
SHInfo
Filters
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Agent
X-Confluence-Request-Time
Ufe-Result
EagleEye-TraceId
AETN-Longitude
AETN-State-Code
BackendServer
BALANCEDTO
AKA-DEVICE
X-Say-Cacheable
Cteonnt-Length
Arrnode
EN-User
X-DynamicCache
X-Cache-On
X-Data-Request
X-HashTwo
X-Oferteo-Domain
AETN-Postal-Code
X-Varnish-Hostname
X-HA-Frontend
AMP-Redirect-To
X-MAT-GEO
X-VCS-Ttl
X-CRA-DC
X-SayCDN-TTL
X-Varnish-Action
X-Cache-Detail
X-Debug-Token
X-Response
X-VCS-Cacheable
X-VC-TTL
AETN-Country-Code
Paypal-Debug-Id
X-HA-Backend
X-Aramark-SID
NODE
X-CACHE-TTL
ScoreTracker
Eomportal-Instance
X-Now-Cache
AsisCache
X-Garden-Version
X-SP-Farm
X-SP-UniqueName
Pics-Label
X-Hosting-Env
X-WN-ClientGroup
X-SDE-Name
X-Cache-Doesi
X-Cache-2
X-Redman-Backend
X-AVG-Country-Code
Url
X-Avg-Cookie-Expires
X-HS-Status
WN
A-Powered-By
X-Akamai-Transformed
Referer
X-Timestamp
X-ENV
Disablevcache
From
X-Dw-Trace-Id
X-Span
X-Cms-Mode
Worker
Accept-Language
X-Redman-Final-Url
X-Compress-Hint
X-Origin-Cache
X-Proxy-Skip
X-Dev
X-Reflector
X-Reflector-Cache
AR-ATIME
X-Map-Context
X-JSESSIONID
MageStack-Cache-Lifetime
X-FastCGI-Cache-Status
X-Varnish-Id
MageStack-Cache
Edgecast
MageStack-Area
X-Source-ID
X-Atraveo-Cache-Control
MS-CV
X-MCB-Server
X-Amz-Meta-Cb-Modifiedtime
X-ASAP-Cache
X-Cache-Ttl
X-Page
MageStack-Cache-Hits
X-Varnish-Debug-Age
X-Clara-ASAP
X-Amcomm-Site
MageStack-Config
MageStack-Loadbalancer
X-DataDome
X-Hosting
X-Ghost-Cache-Status
MageStack-Debug
Prama
X-Varnish-Debug-TTL
X-Upgrade-Enabled
X-Dscp-Value
AR-SID
X-Middleton-PageSpeed
X-Fstrz
MageStack-Cacheable
AR-CACHE
Id
Pragrma
X-V
X-4ormat-Cacheable
X-Server-Addr
Environment
XX
X-Atraveo-ETag
AR-PoweredBy
MageStack-Cache-Status
X-Req-Head-Response
X-Atraveo-TTL
ServerTokens
ServerSignature
X-Bip
X-Remote-Addr
X-Rebelmouse-Cache-Control
X-Svr
MageStack-Tag
WP-FROM-CACHE
X-Path-Route
MageStack-Magento-Version
MageStack-PageSpeed
Request-Country
Request-EU
X-E
Web
X-Atraveo-Expires
Firespring-Website-Id
X-Refresh
CS-SERVER
Thanks
X-PRAM
X-RemovedCookies
Fastly-Debug-Digest
X-Atraveo-Set-Cookie
X-Rule
X-Atraveo-Varnish-Server-Id
X-Atraveo-Param-Rm
X-Hstore
X-Atraveo-From-Varnish-Cache
X-Depends
X-ProcessESI
X-Appmachine-Environment
X-Atraveo-Zone
X-Distributor
PServer
X-Hrouter
X-Rack-CORS
X-Force
X-Cache-Varnish
Cleartype
X-Box
MageStack-Web-Node
X-Cdn-Forward
X-SilverStripe-Cache
CommunityServer
X-Varnish-URL
X-DB-Content-Length
X-CACHE-KEY
Server-Id
X-RAMCache
X-Proxy-Backend
WP-AdvCache-MemCached
X-Proto
X-Ratelimit-Limit
X-Middleton-Pagespeed
X-HeBS-Cache-Status
X-Consent-Required
X-Cocoon-Version
SS
Fastly-Backend-Name
X-Ratelimit-Remaining
Cache-Status
X-Nginx-Host
X-Request-Uri
X-Generated-Timestamp
MageStack-Cache-Warning
Pramga
X-LBPoolMember
Magicmarker
Load-Balancer
IES-Server
X-Highwire-RequestId
X-EC2-Instance-Id
X-HAProxy
X-Built-With
X-Distributed-By
X-AOL-HN
SBSS
X-AutoRu-App-Id
X-Autoru-Host
X-Cache-Dispatchercachecontrol
Identity
Content
X-Reqid
X-Ser
X-Block-Rule
X-Via-NSCOPI
X-Cache-Dispatcherpragma
AC-ELC
X-UA-Bot
X-SuperCache
Xc
X-B3-Sampled
X-Batcache
X-Session-Reinit
X-Proxy-Id
X-DDM-SERVER
X-DDM-SERVER-UPDATED
X-Highwire-SessionId
X-PHP-Response-Code
X-Batcache-Reason
X-Scheme
X-Enabled2
X-Enabled3
Cmsid
X-Enabled1
Cmstype
DNNOutputCache
Access-Control
Aurora-Node
X-Yottaa-Optimizations
X-Mobile-Rewrite
X-FPC
X-PBY
PB-RID
X-Yottaa-Metrics
PB-PID
*
X-Via-S
X-Flex-Evstart
X-Flex-Tags
X-Flex-Evend
X-Block-RuleID
X-Flex-Tag
X-Flex-Lang
X-Flex-Lastmod
X-HTML-Minification-Powered-By
X-Proxy-Cache-Control
Report-To
Myheader
X-Custom-Name
X-Soro
X-Flex-Community
X-DevSrv-CMS
X-Cacheable-TTL
X-Adnet
TC-Cache-U
TC-Cache-IC
TC-Cache
TC-S-Cache
TC-S-Cache-M
X-Node-App
X-ETag
Server-Ip
AMP-Access-Control-Allow-Source-Origin
Apachenode
X-MrHost
X-SmartBan-Host
X-SmartBan-URL
X-XHR-Current-Location
X-Streams-Distribution
X-Origin-Server
DrivedBy
Resin-Trace
Machine
X-Domino-CacheValidationWithETagReason
VANITY-HOST
X-Actindo-Request-Id
X-Actindo-Thread-Id
X-Actindo-Rs
X-Status
X-CacheLoc
X-Cache-TTL-Current
X-Cache-TTL-Age
X-Domino-CacheValidationWithETagResult
X-Gannett-Site-Version
X-Secret
X-Resolver-IP
X-ServiceProvider
X-Instance-Id
X-Title
X-SSLTerm-Server
IISExport
X-Custom-Header
X-ZORequestID
X-DN-Cache-Control
X-Gyrobase-Publication
X-Layout
X-Served-Server
X-Route
X-VERSION
Yola-ID
Backend-Name
X-Cache-FS-Status
SINA-TS
X-CacheID
X-Beatles
Ttl
SINA-LB
Session-Id
Dis-Env
Provided-Host
X-Instart-Cache-Id
CDN-Cache
X-Qiniu-Zone
X-Czt
X-Amz-Meta-Version-Id
Keywords
Description
X-ASAP-Age
X-Az
Og
X-Activity-Id
X-Tag-Playlist
Request-Filtered-By
Viewport
X-M
X-Debug-Message
X-HA
X-Cache-Time
X-Build-Id
X-CH-Device
ID
X-TLS-Version
X-Accel-Cache-Control
MageStack-Last-Modified
X-UA
X-OPNET-Transaction-Trace
Amfplus-Ver
MageStack-Cache-Lifetime-Sent
Realaction
Backend-IP-Port
X-MyName
Yoncu-Errno
D
FRONT-END-SECUREBROWSER
Hamster
X-Olaf
X-Mobilized-By
TP-L2-Cache
X-Abuse
X-Container
X-KoobooCMS-Version
HitInfo
HitType
X-Cache-Action
X-Cache-Extended
X-Unique-Id
X-Log
X-WR-Trace
X-7d-Trace-Id
SERVER-ID
Server-ID
Tempo
X-7d-Instance-Id
TP-Cache
Accept-CH
X-Upstream-Addr
Actioncode
X-Nginx-Request-Time
X-PBS-Appsvrip
X-PBS-Fwsrvname
X-PBS-Appsvrname
Hosted-By
X-WebNode
Powered-By-115
Bios
X-ROUTING
X-Resource
X-Now-Trace
X-Now-Instance
X-Bcwwwid
ServerNode
X-Varnish-Debug-Hits
PBS
X-Varnish-Ip
X-IP
X-Pj-Cache-Status
X-ORIKEY
NLCacheNote
X-FromPodPressCache
NZSpeedy
X-APIVERSION
X-APIAUTH-VAL
X-Shard
X-ENDPOINT
VC-NoCache
X-Appid
Now
X-Appversion
X-FORWARDED-PROTO
X-WEBMGR-CACHE
X-NWS-UUID-VERIFY
X-CloudBurst-Frontend
X-Pagely-Cache
X-Appmachine-Name
Prot
X-WebKit-CSP-Report-Only
X-CloudBurst-WordPress
X-Grid-Server
X-CloudBurst-Cache
X-M-Log
X-M-Reqid
X-InDy-Time
X-InDy-Query
X-InDy-Memory
X-Backside-Transport
X-Src-Webcache
X-Time-Microsecs
X-SiteDistrict-Cache
X-From-Cache
X-Vary-Options
X-Gateway-Rate-Limit-Delayed
REFRESH
Sl-Pgid
X-W3TC-Minify
LB
X-VC-Debug
X-We-Are-Hiring
X-Server-Response-Time
X-Appmachine-CreatedOn
X-Appmachine-Duration
X-Firefox-Spdy
X-Global-Transaction-ID
X-CloudBurst-Backend
GranicusServer
X-NewsFlow-Sitename
X-Ms-Request-Id
X-MainProfileURL
Lookup-Cache-Hit
X-Compressed-By
X-Origin-Upstream-Status
X-Geo-IP
X-MainProfileName
X-MainProfileID
Nitro-Cache
X-Tradeindia-SMgmt
X-Tradeindia-Request-GUID
X-Avvio-Cms-Cacheload
X-HP-CAM-COLOR
X-MainProfileCategory
X-Len
X-Skip-Cache
X-Trans-Id
X-Generation-Time
X-D-Time
Progma
X-S-Misc
X-Envoy-Upstream-Service-Time
StatusCode
X-Origin-Date
End-User-Country
Backend-Powered-By
X-GEO
X-Clx-Request
Requested-Host
X-MSU-SOURCE
X-Newrelic-Synthetics
X-VG-WebCache
X-SID
X-Stiffia-Cache
X-Front-Cache
X-CSRF-Token
X-Cache-ID
X-Boot
X-From-Varnish
X-From-Varnish-Deploy
X-RunCloud-Cache
X-HEAD
RSB-LINK
Plateforme
X-Varnish-Cache-Control
X-SV
X-Server-Ip
X-Wodby-Node
Content-Generator
NGX
Ews
X-SSL
X-Search-Id
X-ProBase-Server
X-Cache-Me-Harder
Prototype-RootPath
RSL-Trace-ID
X-Amzn-Remapped-Content-Length
X-Content-Type
X-BeResp-Ttl
X-Web-Node
X-This-Proto
X-Cname-TryFiles
X-Cache-LB
X-Deity
X-Processed
X-Served
X-SCProxy
X-Qnm-Cache
X-Test-Debug
CDN-RequestId
CDN-PullZone
CDN-Uid
CommercePlatform-Version
X-Q-S
Ctx
CDN-CachedAt
X-S-C
X-Transaction-Name
X-Sn-Servicetimems
X-UPServer
X-Varnish-Cached
X-S-V
X-Varnish-Cached-TTL
X-Mw-Workerstats
OracleCommerceCloud-Sandiego
X-AISO-Server
X-AISO-Cacheable
X-Hit
X-Nginx-Page-Cache
X-Protected-By
X-Cachable
X-AISO-Cache
X-CPU-Time
X-M-V
OracleCommerceCloud-Version
X-M-T
X-M-P
X-Header
X-I-V
X-Ruby-Cluster-ID
X-MCF-ID
RM-Cache-Control
Nd
UrlWatchModule-Time
Webserver
X-Sorting-Hat-Expire-Cache
X-AppServer-Cache-Rule
DbServerName
X-Backend-Host
X-Geo
X-Lb
X-Dynamic
X-Sid
X-Brought-To-You-By
X-VTEX-Cache-Status-Janus-Edge
VAR-Cache
HSTS
X-B3-Spanid
X-Catalyst
X-B3-Traceid
ProxiaInstanceId
NS-VaryByCustom-Key
X-Fpc
Request-Time
ModuleCacheType
X-Server-Hostname
X-UPSTREAM-Address
X-Netrix-ID
Content-Sn
X-Machine
DB-Nickname
Debug-Status
Key
Cf-Ipcountry
Arrow-RequestId
X-NoIndex
ORIGIN-SERVER
V-TTL
ORIGIN-SITE
X-Shopware-Allow-Nocache
X-Shopware-Cache-Id
X-Node-Id
X-ManagedFusion-Rewriter-Version
X-Render-Time
X-Rewritten-By
X-XHTML-Minification-Powered-By
X-Varnish-Grace
ViewMode
VSID
X-Max-Age
X-Gate-Blk
X-Nginx
X-NodeID
X-PM-ID
X-Pass-Through
X-Gate
X-Device-Item
X-ACCELERATE
Www.Aujourdhui.Com
X-Blog
X-CD
X-Csrf-Token
X-Cjtype
X-EPiphany-Vid
X-Client-Vid
MwpReleaseVersion
MachineName
X-ReqId
X-Serv
Provider
Tesla.Performance
X-AppVersion
X-Distil-CS
X-V-Cache
Expiries
ServerIP
Session-From
X-Cache-Warmer
X-UT-Cache
X-Cache-Via
X-Directory-Script
X-Zendesk-User-Id
X-Zendesk-Origin-Server
CDCHOST
X-Powered-By-Home.Pl
X-Client-Image-Vid
X-Built-By
X-WA-Info
Generate-Time
X-Highwire-Smart-Code
X-Highwire-Sitecode
X-Nginx-Request-Processing-Time
X-Proxy-Cache-Key
X-UnsetCookies
X-RequesterIP
X-PressLabs-Stats