Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
X-AspNet-Version
Age
P3P
X-Pingback
Content-Language
Via
X-UA-Compatible
Upgrade
Expect-CT
Access-Control-Allow-Origin
X-Adblock-Key
Content-Security-Policy
X-Cacheable
X-Check
X-Language
X-Template
X-Varnish
X-Request-Id
Alt-Svc
X-Generator
X-Buckets
X-Drupal-Cache
X-Xss-Protection
P3p
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Content-Location
Host-Header
Referrer-Policy
X-ShopId
X-Runtime
MS-Author-Via
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId-Cached
X-ShardId
X-Dc
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-UA-Device
X-IPLB-Instance
X-Powered-CMS
X-Served-By
Cartoon
X-Amz-Cf-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Cache-Status
Access-Control-Allow-Credentials
Status
X-Via
X-Iinfo
X-Wix-Server-Artifact-Id
X-Timer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Accel-Buffering
X-ServedBy
CF-Cache-Status
X-Contextid
X-Ua-Compatible
X-Backend
X-PC-Hit
X-PC-Key
Powered-By
X-PC-Host
X-PC-Date
X-PC-AppVer
X-Mod-Pagespeed
X-CST
Content-Encoding
X-DIS-Request-ID
X-WPE-Loopback-Upstream-Addr
X-Logged-In
X-Host
Keep-Alive
X-CDN
X-Rid
X-Cache-Hit
X-Port
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Cache-Enabled
X-Server-Powered-By
X-Tumblr-Pixel-1
X-Endurance-Cache-Level
X-Server
X-Robots-Tag
X-Nginx-Cache-Status
X-Accel-Version
X-Original-Date
X-Sorting-Hat-PrivacyLevel
X-Seen-By
X-Wix-Request-Id
X-Drupal-Dynamic-Cache
X-Tumblr-Pixel-2
X-Turbo-Charged-By
X-Page-Speed
X-Content-Powered-By
X-Wix-Punisher
X-Pad
X-Forwarded-For
X-Proxy-Cache
X-Content-Digest
X-AH-Environment
X-Forwarded-Proto
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
WP-Super-Cache
X-NewRelic-App-Data
X-Rack-Cache
X-Varnish-Cache
Content-Security-Policy-Report-Only
X-LiteSpeed-Cache
X-Tumblr-Pixel-3
SPRequestGuid
X-GitHub-Request-Id
X-Newrelic-App-Data
Edge-Control
X-SharePointHealthScore
X-MS-InvokeApp
X-Request-Country
X-XRDS-Location
MicrosoftSharePointTeamServices
X-Cache-Lookup
X-SERVER
Timing-Allow-Origin
X-Cnection
X-Node
X-FW-Hash
X-Amz-Id-2
X-Amz-Request-Id
Cf-Railgun
Charset
X-FW-Serve
X-FW-Static
X-FW-Type
X-Content-Security-Policy
X-FullPageCaching
X-Trace
X-Died
X-Webcom-Cache-Status
Request-Id
X-Webserver
Edge-Cache-Tag
X-HS-Cache-Config
X-CF-Powered-By
X-HS-Content-Id
Request-Context
X-Hits
X-PhApp
MicrosoftOfficeWebServer
SPIisLatency
SPRequestDuration
X-BC-Stapler
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
Access-Control-Max-Age
Composed-By
X-Safe-Firewall
Access-Control-Expose-Headers
EagleId
X-Swift-SaveTime
X-Swift-CacheTime
X-Sorting-Hat-FeatureSet
Grace
Served-By
X-Spip-Cache
X-CDN-Pop
X-CDN-Pop-IP
X-Hyper-Cache
Liferay-Portal
X-Server-Name
X-Backend-Server
X-VCache
X-Tumblr-Pixel-4
X-HS-Combine-CSS
X-Dw-Request-Base-Id
X-Device
X-Fastly-Request-ID
X-Firenze-Processing-Times
X-Microcache
X-FB-Debug
X-Request-ID
Surrogate-Control
X-Clacks-Overhead
X-RateLimit-Remaining
X-RateLimit-Limit
Content-Style-Type
Front-End-Https
X-LiteSpeed-Cache-Control
X-DDC-Arch-Trace
X-Cloud-Trace-Context
Rating
X-RateLimit-Reset
Xkey
X-Loop
X-TNCMS
Content-Script-Type
X-Jimdo-Wid
X-Jimdo-Instance
X-Acc-Exp
Public-Key-Pins
X-DNS-Prefetch-Control
X-ServerName
X-User-Agent
X-Cache-Config
Refresh
X-Vtex-Processado-Em
X-Frame-Option
X-XN-XNHTML
X-XN-Trace-Token
X-Age
X-StackifyID
X-Middleton-Response
X-Sol
X-Middleton-Display
Display
Response
X-Hostname
Fpc-Cache-Id
X-Cached
X-N-OperationId
X-Tumblr-Content-Rating
X-SS-Location
X-SS-Conf
X-Generated-By
X-WebKit-CSP
X-Px
X-Dscp-Value
X-Zen-Fury
X-Tumblr-Pixel-5
Real-Hostname
X-Topify-Platform
TCN
X-Magento-Tags
X-HOST
X-MiniProfiler-Ids
X-Kinsta-Cache
X-OneAgent-JS-Injection
X-Request-Time
X-Outils-CS
P-WS
P-LB
X-CMS-Version
X-URL
X-Correlation-Id
X-Amz-Version-Id
Rt-Fastcgi-Cache
PageSpeed
X-Whom
X-Cached-By
X-Handled-By
X-Url
X-B-Cache
X-Content-Options
X-Ruxit-JS-Agent
X-DynaTrace
Dmn
Access-Control-Request-Method
Product
X-Varnish-TTL
ServedBy
X-AspNetWebPages-Version
X-DynaTrace-JS-Agent
Imagetoolbar
Surrogate-Key
Powered
X-CacheServer
Host
X-Edge-Location
X-Msg-2-Log
X-Varnish-Cache-Hits
X-FORWARDED-FOR
X-Cache-Rule
X-From
Public-Key-Pins-Report-Only
X-LBLID
X-Upstream
X-Accel-Expires
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-Vtex-Remote-Cache
X-Debug-Info
X-Vtex-Processed-At
X-VTEX-Cache-Status-Janus-ApiCache
No
X-Umbraco-Version
X-Signature
X-Location-Id
X-SRCache-Store-Status
X-Track
X-Goog-Hash
X-SRCache-Fetch-Status
X-Via-JSL
DynaTrace
Fhost
X-Fastcgi-Cache
X-Engine
X-Platform
X-Actual-URL
X-Original-Request
X-Returned-From-DLL
Alternate-Protocol
Edge-Control-Message
X-Returned-From
X-Application-Context
X-Passed-To-DLL
X-Passed-To
X-Recruiting
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Returned-From-PostProcessResponse
X-Passed-To-PostProcessResponse
X-Returned-From-BeforeDispatch
X-NWS-LOG-UUID
X-Passed-To-BeforeDispatch
X-Hosted-By
X-Stale
Retry-After
Arr-Disable-Session-Affinity
X-Powered-By-VTEX-Janus-Edge
X-Loopia-Node
Fastcgi-Cache
X-Micro-Cache
X-Cache-Info
X-Response-Time
X-LW-Cache
X-UD-Method
X-Version
X-Magento-Cache-Debug
X-Art-Request-Id
X-Rocket-Nginx-Bypass
X-URLSCHEME
X-Developer
X-Varnish-Host
Ohc-File-Size
Generator
Pagespeed
X-F-Cache
X-Rnd
X-ApacheServer
X-VARNISH-Cache
X-PERF
WZWS-RAY
X-Powered-By-360WZB
X-Platform-Router
X-Platform-Processor
X-Instart-Request-ID
X-BS
X-TransIP-Balancer
X-I-Sp
HTTPS
X-Supported-By
X-Platform-Cluster
X-Cache-TTL
X-Varnish-HitMiss
USPLoggingUUID
X-Varnish-Count
X-Cache-Age
Origin
X-Shop-Id
X-Defender
X-Litespeed-Cache
X-TransIP-Backend
X-RESOURCE
X-Device-Type
X-Server-ID
X-Microcachable
Content-Hash
X-Tumblr-Pixel-6
X-I
Last-Published
X-NetCat-Version
Fastly-Debug-Digest
Akamai-IP
X-HS-Content-Campaign-Id
X-Source
X-Cluster-Node
X-S
X-Powered-By-VelaWeb
X-Director
Cache-Provider
X-CSRF-Protection
X-ATG-Version
Surrogate-Key-Raw
X-Front
X-Pantheon-Site
X-Pantheon-Phpreq
X-Pantheon-Environment
X-Cdn
X-Gamma-Serve
X-Platform-Server
RTSS
X-Litespeed-Cache-Control
X-Storage
X-Cache-Tags
X-Shard
X-EdgeConnect-Origin-MEX-Latency
Version
X-App-Hosting
Content-Disposition
X-Dispatcher
X-Varnish-GracePeriod
X-Page-Cache
X-Matrix-Proxy
X-Flow-Powered
X-Matrix-Server
X-Varnish-ObjectSource
X-Hypernode
X-Varnish-RemainingTTL
X-Varnish-RemainingLife
X-Varnish-Seen-By
X-Cache-Operation
Powered-By-ChinaCache
X-Daa-Tunnel
MIME-Version
X-Microcache-Status
X-Translation
X-ORACLE-DMS-ECID
X-Expires-Orig
X-Cache-Key
Cache-Key
X-LB-Node
X-Ttl
X-Sapient
X-Environment
X-Route-Server
X-EdgeConnect-MidMile-RTT
X-SV-FromDBCache
X-SV-Edge
X-SV-CreatedAt
X-SV-CacheTags
X-SV-Expires
X-SV-Nginx-Duration
X-ARC
Allow
X-SV-Pid
X-SV-Cacheable
X-SV-Duration
X-Content-Encoded-By
X-Vcap-Request-Id
X-Platform-Cache
IBM-Web2-Location
X-Abgroup
Pool
X-CJ-Soft
X-Ezoic-Cdn
X-Cache-Namespace
SSPAppContext
X-LB
X-Drupal-Cache-Tags
X-Server-Upstream
X-Revision
X-SSL-Cipher
X-Varnish-Age
X-Varnish-Cacheable
SN
X-Firenze-Processing-Time
X-Magento-Cache-Control
X-Grace
X-Cache-Debug
Lsrequestid
X-SSL-Protocol
X-Cache-Expires
X-Lambda-Id
Pv
X-Varnish-Ttl
Cneonction
X-Github-Request-Id
X-Duration
Accept-Encoding
Node
X-Nginx-Cache
X-NoCache
Wsr-Cache
Content-MD5
X-Varnish-Backend
FAI-W-FLOW
PICS-Label
Backend
X-Dispatch
Fw-Via
Srv
X-Edge-IP
Section-Io-Id
X-Generated
S-Cnection
X-Cache-Control-Orig
X-Cache-Lifetime
X-Dynatrace-Js-Agent
X-ID
Content-Encoding-Handler
X-IsCacheURL
X-Cache-Only-Varnish
X-PwB-Node
X-Hiawatha-Cache
X-Drupal-Cache-Contexts
ServerID
X-Ss-Conf
X-Client-IP
Req-Id
X-Ss-Location
Location
X-Amz-Meta-S3cmd-Attrs
X-GeoIP-Country-Code
X-Akamai-Device-Characteristics
X-Time
X-Content-Age
X-N
X-Varnish-IP
X-Last-Modified
X-Server-Id
X-Akamai-Device-Model
X-Vhost
X-Url-Base
X-Yadis-Location
X-RequestId
X-Debug
X-Varnish-Url
X-Pressidium-NinukisWP-Ver
X-Proxy
X-Cache-Level
X-SDS
X-AOL-HN
X-Cache-Engine
Server-Timing
X-Fastly-Request-Id
X-Worker
If-Modified-Since
X-ORACLE-DMS-RID
Page-Completion-Status
X-Cache-Type
X-Cache-Server
Nodo
X-BKSrc
X-Cache-Handler
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Country-Code
ServerName
X-GUploader-UploadID
X-Purge-URL
X-Akamai-Transformed
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
Proxy-Connection
NnCoection
HCVer
HAVer
IM-Version
X-Speed-Cache-Key
X-Speed-Cache
X-Discourse-Route
Server-Name
X-SRCache-Key
Cache
AMF-Ver
X-Oneagent-Js-Injection
X-Purge-Host
X-GeoIP-Country-Name
X-Origin
X-Geo-Country
X-SO
X-Cache-CFC
X-Runtime-Rack
X-Magnolia-Registration
X-App-Server
Cteonnt-Length
X-Location
X-Middleware-Start
X-ServerID
SEOMOZ
X-Cache-Control
X-Nbs
Accept-Charset
Server-Info
Front
MJ12bot
X-Cookie-Domain
X-App-Status
Use-Proxy
Pf.Web.Request.Id
X-Always-Cache
X-Browser
SRV
X-Empowered-By
X-Srv
X-BackendServer
X-PF-Uncompressing
X-TTL
Content-Transfer-Encoding
X-UPSTREAM
X-Correlation-ID
X-FW
X-Frontend
Nitro-Cache
Xc-Version
X-Cache-Device-Type
X-Real-Server
Cached
X-Config-Blacklist-Version
Cm-Server
X-Esi
X-Cache-Fix
X-High-Performance
X-Cache-PageType
X-Varnish-Retries
X-CF-Passed-Proto
X-Resource
X-Client-Vid
X-Client-Image-Vid
X-Pagename
X-Hit-Cache
X-Content-Type-Option
Cache-Tags
X-Framework
X-Processing-Time
CacheControlHeader
S
X-EPiphany-Vid
X-WPL-DATA
X-SRV
X-CDN-Forward
Qs-Cache
X-Amz-Storage-Class
X-Rocket-Nginx-Serving-Static
VANITY-HOST
X-VARITI-CCR
X-DealerOn
X-Server-Instance
X-Unbounce-VisitorID
X-Unbounce-PageId
X-Unbounce-Variant
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Id
X-Gateway-Skip-Cache
Tracecode
Local-Info
X-Sentry-ID
X-Sucuri-ID
X-OpenCart-Lightning
Cache-Tag
W
X-AF-Userserver
X-Abuse
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-WN-ClientGroup
Custom-Header
WN
X-Mobilized-By
X-Ruxit-Js-Agent
MC
X-Rq
Frame-Options
Author
X-ACMCache
P-ID
Magicmarker
X-JG-Page-Cache
Eomportal-Instance
X-FTR-Request-ID
X-HTML-Minification-Powered-By
X-Dns-Prefetch-Control
X-Xrds-Location
X-Varnish-Hits
NODE
X-Env
X-Session-ID
Url
Thanks
NetMindSessionID
X-Shield-Request-Id
X-Processed-By
Environment
X-VTEX-Cache-Status-Janus-Edge
WWW-Authenticate
X-Adobe-Loc
X-Adobe-Content
SiteSpeed
X-Sys-Req-ID
X-Fedora-School-Id
X-Orig-Vary
Ufe-Result
X-Page
X-WR-Flags
A-Powered-By
X-Cache-Dispatchercachecontrol
ServerSignature
X-Cache-Dispatcherpragma
X-Stage
Smug-CDN
X-Transaction
X-Resty-Request-Id
X-TTFB-L
X-TTFB
X-WA-Info
Content_type
X-Twitter-Response-Tags
X-Content-Security-Policy-Report-Only
X-SmugMug-Values
ServerTokens
X-Directory-Script
X-Connection-Hash
X-SmugMug-Hiring
X-Server-IP
Machine
EagleEye-TraceId
X-Runtime-Memory
X-NB-Cached-Page
Contao-Page-Layout
X-ClientSide-Caching
X-LB-Server
NtCoent-Length
X-Traffic
X-VC-TTL
X-Route-To
X-Source-ID
X-Cache-Doesi
X-DEBUG
X-Remote-Addr
X-VC-Enabled
X-AEM
X-RealServer
X-IIJ-Cache
X-Drectory-Script
X-Trace-Id
SVR
X-Sucuri-Cache
X-Varnish-Hostname
X-ServerIndex
Proxy-Agent
X-A
Web-App-Origin-Name
X-Clara-ASAP
BALANCEDTO
Max-Age
X-ASAP-Cache
X-CAPServer
X-Generated-Time
Adm-Server
Service-Worker-Allowed
X-Akamai-Edgescape
Ramp
Id
X-AVG-Country-Code
X-Avg-Cookie-Expires
X-Backend-Status
Ram
X-Compress-Hint
X-Jphone-Copyright
X-NginX-Server
Noq
X-Redman-Backend
X-Redman-Final-Url
X-HW
Bios
X-Sorting-Hat-Expire-Cache
SHInfo
X-Sites
X-Application
Description
SBGI-1
X-Disney-Akamai-Rule
X-Webstats-RespID
Server-ID
X-Resolver-IP
SBGI-7
X-LP
NLCacheNote
SBGI-RenderTime
SBGI-9
X-Unique-ID
X-Garden-Version
SBGI-5
SBGI-10
Keywords
X-DTC
SBGI-Device
X-Airee-Node
X-FPC
SBGI-RealPath
X-Webkit-CSP
Cmsid
Cmstype
X-Force
X-HydroSheep
IISExport
X-Varnish-Id
Pics-Label
MW-Webserver
X-Info
X-CB-Server
X-VNode
X-PRAM
Play-Detected-UserAgent
Play-Detected-Device
X-ARRServer
X-RiS-UFDI
X-Symfony-Cache
Beyond-Iis
X-Magento-Action
X-Vcache
X-LW-Web-Server
Identity
Dispatcher
X-Akamai-3PM-SW-Version
Yoncu-Errno
X-Origin-Server
From-Origin
X-CACHE-TTL
X-Debug-Token
X-Real-IP
X-Acquia-Debug-Password
X-WP
X-Smartcache-Keys
X-Request-Uri
X-Cocoon-Version
X-Provisioner-Version
X-Smartcache-Timeout
X-Highwire-SessionId
X-Machine
Dis-Env
X-Domain-Checked
X-Varnish-Debug-TTL
X-Varnish-Debug-Age
X-SmartBan-Host
X-Secret
X-Src-Webcache
X-SmartBan-URL
X-Highwire-RequestId
X-Detected-Device
Backend-Timing
X-FireWall-Port
X-Goog-Meta-Goog-Reserved-File-Mtime
X-WebKit-CSP-Report-Only
X-TB-M
X-Key
Ohc-Response-Time
X-Balanceador
Home
X-Plat
Og
X-GeoIP
AsisCache
X-Analytics
X-Cache-Node
ScoreTracker
VServer
X-NodeID
X-Varnish-ID
X-IP
RN-Server
X-Cache-Via
X-E
X-Varnish-Server
X-Proxy-Cache-Key
X-Culture
RequestId
Fastly-Backend-Name
X-Hosting-Env
X-Render-Time
X-SDE-Name
XDomainRequestAllowed
Web
X-Atraveo-Cache-Control
X-Atraveo-ETag
X-Distil-CS
Nginx-Cache
X-GoCache-CacheStatus
SS
AC-ELC
X-Highwire-Smart-Code
X-Highwire-Sitecode
X-Nginx-Request-Processing-Time
X-Atraveo-Varnish-Server-Id
X-Bip
X-Atraveo-Expires
X-SV
X-Atraveo-Zone
WP-AdvCache-MemCached
X-Proto
X-ESI
X-Atraveo-TTL
X-Atraveo-Set-Cookie
Access-Control-Allow-Method
X-Atraveo-Param-Rm
COMMERCE-SERVER-SOFTWARE
X-Atraveo-From-Varnish-Cache
X-ACCELERATE
Ec-Machine
Myheader
X-Hosting
X-Cms-Mode
X-Amz-Meta-Cb-Modifiedtime
X-Wikidot-Static-Cache
X-WHOIS-Cached
X-Runtime-Affili
Ec-CorrId
X-Wikidot-Backend
X-Adnet
X-Distributor
X-Pass-Through
X-PBY
X-PROCESSED-BY
X-Fstrz
X-Redirector
X-Dw-Trace-Id
X-Artvisual-Server
X-Rewrite
X-Depends
X-HP-Trace-ID
X-SCM-Server-Number
Worker
X-Who
X-ZSITES-DNS
Disablevcache
X-Flex-Community
X-Webcelerate
X-Varnish-Grace
X-HP-Trace-Project
X-Mobile-URL
X-UnsetCookies
X-Confluence-Request-Time
X-Flex-Lang
X-Autoru-Host
X-Autoru-LB
X-B2f-Not-Route
Traffic-Origin
X-AutoRu-App-Id
X-Aramark-SID
Il-Cl
Proxy-Cache
X-Amz-Meta-S3b-Last-Modified
SERVER-ID
X-Cluster
X-Refresh
ClientIP
Device
Gzip
X-Varnish-Cache-Local
X-MCB-Server
X-DB-Content-Length
X-Frames-Options
OriginServer
X-HashTwo
X-OPNET-Transaction-Trace
X-Dev
From
X-Map-Context
X-Data-Request
X-Flex-Tags
X-Flex-Tag
X-Flex-Evstart
X-Amz-Meta-Content-Md5
X-Flex-Lastmod
X-Nginx-Host
X-Compressed-By
X-Amcomm-Site
AMP-Access-Control-Allow-Source-Origin
X-Rack-CORS
X-Time-Microsecs
X-App-Runtime
X-Req-Head-Response
X-Search-Id
X-Session-Reinit
X-Flex-Evend
X-Pubstack
X-Viator-Tapersistentcookie
Ibf5scheme
X-Serv
Access-Control-Allow-Header
X-Rebelmouse-Surrogate-Control
Ctx
X-DataDome
X-4ormat-Cacheable
X-L-Path
X-LDNR-NOT-ROOT-HL-NOTSET
Hostname
X-ASAP-Age
Hname
X-Response
F5-IpCliente
X-AMAZEEIO
Paypal-Debug-Id
X-Origin-Cache
X-MAT-GEO
X-Desc
X-Cdn-Forward
N365rili
X-RDP
X-CRA-DC
X-Forwarded-Host
X-Environment-Context
X-CacheResult
X-Cache-On
Provider
X-GSL-Server
X-Omnis-SiteID
X-Rebelmouse-Cache-Control
SG
X-Akam-SW-Version
Strikingly-Cached
X-SERVER-NAME
X-EC2-Instance-Id
CLMOB
Strikingly-Cached-Version
X-Magento-Lifetime
Strikingly-Cache-Region
Hummingbird-Cache
X-Lb
X-Avvio-Cms-Cacheload
X-Cf-Powered-By
TP-Cache
Aoestatic
X-NID
VC-NoCache
TP-L2-Cache
X-KoobooCMS-Version
X-SH-Cache-Status
X-Batcache
Accept-Language
X-FORWARDED-PROTO
X-Author
HitType
X-Cache-Varnish
NZSpeedy
X-Varnish-Action
X-Goog-Meta-Policy
X-Goog-Meta-Replace
Xc
X-Served-Server
X-V
Cleartype
X-Timestamp
X-Node-Name
X-PM-ID
X-DN-Cache-Control
X-Ghost-Cache-Status
PServer
X-Ssl-Cipher
X-DSMX-Rewrite-MS
NS-VaryByCustom-Key
Ews
BackendServer
Content-Generator
Copyright
X-Zendesk-User-Id
X-Zendesk-Origin-Server
X-Cache-TTL-Current
X-Rack-Cors
X-Tag-Playlist
Actual-Object-TTL
PagesDisplayed
X-Captured
X-LBPoolMember
X-Gyrobase-Publication
X-DSMX-Render-MS
X-NginX-Cache
X-DynamicCache
TC-S-Cache
TC-S-Cache-M
TC-Cache-U
TC-Cache-IC
X-Site
TC-Cache
X-Grid-Server
X-ReqId
X-FG-RequestId
Lb
X-DS1D
X-Gannett-Site-Version
CommercePlatform-Version
X-Header
X-Server-Addr
Ez
SB-Site-Device
X-Cache-TTL-Age
X-Powered-By-Home.Pl
MachineName
X-PHP-Response-Code
X-Amz-Id-1
X-Enhanced-By
X-SilverStripe-Cache
Server-Id
X-HS-Status
OracleCommerceCloud-Sandiego
SB-Cache-Life
SB-Cache-Remaining
X-App
OracleCommerceCloud-Version
Upgrade-Insecure-Requests
Page-Template
Accept-CH
X-ManagedFusion-Rewriter-Version
X-HAProxy
X-HP-CAM-COLOR
X-Pj-Cache-Status
X-Cache-Detail
X-Batcache-Reason
X-Reflector
X-Pagely-Cache
X-Dealeron-Original-Url
X-Reflector-Cache
Ttl
X-Dealeron-Backend
X-Rewritten-By
Resin-Trace
SB-Site-IE-VERSION
Tk
X-Agent
X-Cache-Me-Harder
X-NO-BREACH
X-Container
FRONT-END-SECUREBROWSER
X-RiS-PX
X-OCTOPOD
X-UPSTREAM-Address
X-WebNode
Fastly-Restarts
X-Hrouter
X-Hstore
FindLaw
Debug-Status
Container
Requested-Host
X-Actindo-Thread-Id
X-Obvious-Tid
X-Obvious-Info
X-MainProfileID
X-MainProfileCategory
X-MainProfileName
X-MainProfileURL
GranicusServer
X-Nginx-Request-Time
X-Status
X-RAMCache
X-Q-S
X-S-C
X-S-V
X-Transaction-Name
X-T
X-Pool-Info
X-Pageid
X-M-P
X-Instart-Cache-Id
X-M-T
X-M-V
X-Mw-Workerstats
X-Built-By
X-BIT-Node
Session-Id
ProxiaInstanceId
DeleGate-Ver
X-Instance-Id
Swift-Performance
CommunityServer
AR-SID
Z-Tpl
Y-Trace
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Middleton-Pagespeed
X-7d-Instance-Id
X-S-Misc
ID
X-ServiceProvider
X-Streams-Distribution
Cache-Status
XX
X-CacheID
X-Nitro-Cache
X-Config-By
X-CDN-COMPRESS
X-Country
X-D-Time
X-Generation-Time
EN-User
Server-Ip
StatusCode
MSThemeCompatible
TZ-Server
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
MSSmartTagsPreventParsing
X-Proxy-Skip
X-Built-With
X-Bcwwwid
X-Catalyst
X-ETag
X-Protected-By
X-Cache-TTL-Remaining
X-AppServer-Cache-Rule
X-Actindo-Request-Id
X-DDM-SERVER-UPDATED
X-Hash
X-MidCOM-Meta-Cache
X-Phpwcms-Page-Processed-In
X-DDM-SERVER
X-I-V
X-Backend-Host
X-7d-Trace-Id
X-Box
X-Actindo-Rs
X-Client-Ip
X-Phpwcms-Release
Hamster
Kanooh-Host
Content-Cache
No-Cache
Progma
UrlWatchModule-Time
X-Via-NSCOPI
X-VG-WebCache
X-REDIRECTSERVER
X-CDN-RULE
X-SE-Debug
X-Sid
X-SuperCache
X-Meta-MSThemeCompatible
MwpReleaseVersion
X-Layout
X-Debug-Message
X-FastCGI-Cache-Status
X-Cjtype
X-CSRF-Token
X-Debug-Token-Link
X-Az
X-Amz-Meta-Version-Id
X-Static
X-Deity
X-AppVersion
X-HA
X-Cacheable-TTL
X-CloudBurst-WordPress
X-Custom-Header
X-CloudBurst-Frontend
X-Serverid
X-UA
X-Cname-TryFiles
X-BServer
X-JSESSIONID
X-Middleton-PageSpeed
X-Route
CpuTime
X-Beatles
X-Full-Url
X-Served
X-VC-Hash
User-Agent
X-ACLR-Version
X-Domino-CacheValidationWithETagResult
X-HeBS-Cache-Status
X-W3TC-Minify
X-HEAD
X-Header-Treatment
X-Made-On
Cacheid
X-VC-Debug
Generate-Time
ViewMode
X-Turpentine-Esi
Viewport
X-Activity-Id
X-Title
Tesla.Performance
X-VC-Cache
X-Domino-CacheValidationWithETagReason
X-VC-Cacheable
MS-CV
RSB-LINK
X-UT-Cache
X-Svr
MageStack-Tag
MageStack-PageSpeed
MageStack-Web-Node
X-Cache-Id
TheAnswer
MageStack-Magento-Version
X-BPool-Fx-Cache
MageStack-Cacheable
X-Cache-Original-TTL
MageStack-Config
MageStack-Debug
Provided-Host
X-Cache-ID
DrivedBy
Control-Cache
HostName
X-FIRSTBase
EQ-Cache
X-CH-Device
X-Cachable
Language
X-B
X-Beresp-Ttl
X-Apm-Telemetry-Syncmark
MageStack-Cache-Warning
MageStack-Loadbalancer
X-BPool
MageStack-Cache
MageStack-Cache-Hits
MageStack-Area
X-CloudBurst-Backend
MageStack-Cache-Status
X-Blog
MageStack-Cache-Lifetime
Key
Amfplus-Ver
X-CloudBurst-Cache
X-Cache-Time
X-BPool-Bx-Cache
X-BPool-Back
X-AISO-Cache
X-AISO-Server
FastCGI-Cache
X-AISO-Cacheable
X-Pixelsilk-Server
X-Cache-Extended
X-Pixelsilk-Version
X-RemovedCookies
X-RequesterIP
X-ProcessESI
X-Ao-Cache-Key
X-ClusterID
WP-FROM-CACHE
V-Age
X-Ants-Host
X-Varnish-Cache-Ttl
X-XHTML-Minification-Powered-By
X-Ants-Machine-Id
X-Test-Debug
X-Old-Content-Length
X-NMT-Proxy
TestCC
WSCLoggingUUID
X-Backend-Name
CDCHOST
X-Dynamic-Cache
X-MSEdge-Ref
X-Instance
Warning
X-Theme
X-Healthy
Rewriter
Webserver
X-Proxy-Id
X-Server-Hostname
DbServerName
CD4
X-Skip-Cache
Be
X-CACHE-KEY
X-Locale
Amp-Access-Control-Allow-Source-Origin
X-BackendProxy
X-Varnish-Cached-TTL
Httpd-Identifier
X-Instance-Name
Disp
X-Varnish-Cached
X-UPServer
X-MCF-ID
X-Script
X-ServerAddr
X-Geo-IP
X-Svr-Proxy
X-Varnish-Debug-Hits
Request-Filtered-By
X-Proxy-Backend
Referer
X-Origin-Date
X-M
X-Reason-Bp
Redirect-Reason
X-Gateway-Rate-Limit-Conn
X-Gateway-Rate-Limit-Delayed
Powered-By-115
ReqUrl
X-PBS-Fwsrvname
X-Prerender-Token
X-SSLProxy
X-SSLUpstream
X-PBS-Appsvrname
X-PBS-Appsvrip
X-Cache-FS-Status
X-MyName
X-NewsFlow-Sitename
X-Prerendered
X-Member
X-Processed
X-Mobile-Rewrite
X-Olaf
X-Upstream-Status
X-Say-Cacheable
X-Say-TTL
Returned-Status
X-SCProxy
X-SayCDN-TTL
Arrnode
X-Max-Age
X-DEBUG-TTL
X-DeliveryServer
X-ENV
X-DEBUG-HOST
X-This-Proto
X-Optimization
X-Cache-LB
X-Clx-Request
VAR-Cache
Www.Aujourdhui.Com
X-Cache-ASPX
X-Test
SINA-LB
X-K8s
Edgecast
X-Request-Processing-Time
X-Request-Received
X-Fastly-Backend-Reqs
SINA-TS
Note
V-TTL
Access-Control-Request-Headers
Arrow-RequestId
X-Restarts
X-Secure
X-ACache
User-Cache-Control
X-Session-Id
X-MSU-SOURCE
X-PoweredBy
X-Cache-Bypass
X-CO-Host
X-CPU-Time
Serverid
Response-Time
CmsfirstPublishTimestamp
Countrycode
Head
X-Hit
X-Nginx-Page-Cache
Expiries
X-Beatles-Hits
ServerIP
CS-SERVER
X-Unique-Id
X-Node-App
X-Cache-Set
X-SH-Cache-Disabled
Xcache
X-XHR-Current-Location
X-Your-GrandPa-Would-Wait
X-Would-Your-GrandPa-Wait
X-TTL-Age
Apple-Itunes-App
X-Upgrade-Enabled
PB-RID
PB-PID
X-Tt-Dbg
X-TLS-Version
X-Cache-Keep
X-Time-Zone
X-Varnish-Instance
X-VLoc
X-DevSrv-CMS
X-Does-He-Have-Time
X-ELB
X-PG
X-Server-FQDN
Session-From