Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Content-Type
Date
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
X-Cache
Strict-Transport-Security
X-AspNet-Version
CF-RAY
P3P
X-Pingback
Age
Content-Language
X-UA-Compatible
Via
Access-Control-Allow-Origin
X-Adblock-Key
Upgrade
X-Varnish
X-Cacheable
P3p
X-Check
X-Template
X-Language
Content-Security-Policy
X-Generator
X-Buckets
X-Drupal-Cache
X-Type
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Xss-Protection
X-Request-Id
X-Hacker
X-Ac
X-Powered-By-Plesk
Content-Location
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Runtime
X-Download-Options
MS-Author-Via
Host-Header
Alt-Svc
X-ShopId
X-Sorting-Hat-ShopId-Cached
X-ShardId
X-Dc
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-IPLB-Instance
X-Request-ID
Cartoon
X-Powered-CMS
X-UA-Device
Status
X-Served-By
Access-Control-Allow-Credentials
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Via
X-Amz-Cf-Id
X-Iinfo
X-Cache-Status
X-Backend
X-Contextid
X-Timer
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Wix-Server-Artifact-Id
X-ServedBy
X-PC-Hit
X-PC-Key
CF-Cache-Status
Powered-By
X-Mod-Pagespeed
X-PC-AppVer
X-PC-Date
X-PC-Host
X-DIS-Request-ID
X-Server
X-Logged-In
Keep-Alive
Content-Encoding
X-Rid
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Hit
X-CDN
X-Port
X-Tumblr-Pixel-1
X-Host
X-CST
X-Server-Powered-By
X-Robots-Tag
Referrer-Policy
X-Tumblr-Pixel-2
X-Pad
X-Cache-Enabled
X-Nginx-Cache-Status
WP-Super-Cache
X-Endurance-Cache-Level
Fastly-Debug-Digest
X-Accel-Version
X-Page-Speed
X-Seen-By
X-Wix-Request-Id
X-Wix-Renderer-Server
X-Turbo-Charged-By
X-Wix-PunisherID
X-Content-Powered-By
X-Tumblr-Pixel-3
X-Drupal-Dynamic-Cache
X-Rack-Cache
X-Content-Digest
X-Varnish-Cache
X-Forwarded-For
X-FRAME-OPTIONS
X-AH-Environment
Expect-CT
X-Forwarded-Proto
Content-Security-Policy-Report-Only
X-Styx-Req-Id
Surrogate-Key-Raw
X-Pantheon-Styx-Hostname
X-GitHub-Request-Id
X-Proxy-Cache
SPRequestGuid
X-SharePointHealthScore
X-Cnection
MicrosoftSharePointTeamServices
X-Request-Country
X-MS-InvokeApp
X-XRDS-Location
X-Cache-Lookup
X-LiteSpeed-Cache
X-Original-Date
Edge-Control
Cf-Railgun
X-Safe-Firewall
Timing-Allow-Origin
MicrosoftOfficeWebServer
X-FullPageCaching
Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Webserver
X-Died
Charset
X-PhApp
X-FW-Hash
X-Node
X-FW-Serve
X-FW-Static
X-FW-Type
SPIisLatency
Edge-Cache-Tag
SPRequestDuration
X-INKT-URI
X-INKT-SITE
X-HS-Cache-Config
X-Content-Security-Policy
X-HS-Content-Id
X-Tumblr-Pixel-4
X-CF-Powered-By
X-Hits
Composed-By
Access-Control-Max-Age
Content-MD5
Liferay-Portal
Access-Control-Expose-Headers
X-Swift-CacheTime
X-Swift-SaveTime
X-Hyper-Cache
EagleId
Served-By
Grace
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-CDN-Pop-IP
X-CDN-Pop
X-Spip-Cache
X-BC-Stapler
Rating
Request-Context
X-Device
X-Backend-Server
X-Server-Name
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-Microcachable
X-Newrelic-App-Data
X-Firenze-Processing-Times
X-Microcache
X-Tumblr-Content-Rating
X-RateLimit-Remaining
X-RateLimit-Limit
X-RateLimit-Reset
X-User-Agent
X-VCache
Content-Style-Type
X-FB-Debug
X-ServerName
X-Jimdo-Instance
X-Jimdo-Wid
Content-Script-Type
X-Clacks-Overhead
X-Cache-Config
Public-Key-Pins
X-Cloud-Trace-Context
X-TNCMS
X-Loop
Real-Hostname
X-DDC-Arch-Trace
Refresh
X-Acc-Exp
Xkey
Front-End-Https
Surrogate-Control
X-Age
X-Aspnetmvc-Version
X-Hostname
X-XN-Trace-Token
X-XN-XNHTML
X-HOST
Fpc-Cache-Id
X-Generated-By
X-Tumblr-Pixel-5
PageSpeed
X-Px
X-N-OperationId
X-Middleton-Display
Display
X-Middleton-Response
Response
X-Sol
X-Cached
X-SS-Location
X-SS-Conf
X-LiteSpeed-Cache-Control
X-DNS-Prefetch-Control
X-SERVER
X-MiniProfiler-Ids
X-Topify-Platform
X-StackifyID
Surrogate-Key
X-Cached-By
X-WebKit-CSP
X-Request-Time
X-Zen-Fury
X-Url
X-CMS-Version
X-Servedby
Rt-Fastcgi-Cache
X-URL
X-Pantheon-Environment
X-Pantheon-Phpreq
X-Pantheon-Site
X-Outils-CS
X-Content-Options
TCN
X-FORWARDED-FOR
Edge-Control-Message
X-OneAgent-JS-Injection
X-Whom
X-Correlation-Id
X-Varnish-TTL
X-Umbraco-Version
X-Amz-Version-Id
X-Varnish-Cache-Hits
X-Ruxit-JS-Agent
X-AspNetWebPages-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-DynaTrace-JS-Agent
X-ApacheServer
Access-Control-Request-Method
X-PERF
X-Handled-By
Imagetoolbar
X-DynaTrace
Alternate-Protocol
Product
Host
X-Engine
X-Kinsta-Cache
X-Cache-Rule
P-LB
P-WS
WZWS-RAY
Powered
X-Powered-By-360WZB
X-Magento-Tags
X-From
Fhost
ServedBy
DynaTrace
X-Edge-Location
X-Msg-2-Log
X-NWS-LOG-UUID
Generator
X-Micro-Cache
X-Recruiting
X-Location-Id
X-Track
X-CacheServer
X-Hosted-By
X-Tumblr-Pixel-6
X-B-Cache
X-VARNISH-Cache
X-Cache-Age
X-VTEX-Janus-Router-Backend-App
No
X-VTEX-Cache-Status-Janus-ApiCache
X-Vtex-Processado-Em
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-Powered-By-VTEX-Janus-ApiCache
X-LBLID
Fastcgi-Cache
X-Developer
X-I-Sp
X-Response-Time
X-BS
Origin
X-Goog-Hash
Arr-Disable-Session-Affinity
X-Powered-By-VTEX-Janus-Edge
X-Application-Context
X-RESOURCE
X-Fastcgi-Cache
X-URLSCHEME
X-Actual-URL
X-Shop-Id
X-Defender
X-Instart-Request-ID
X-Original-Request
X-Varnish-Host
X-Returned-From-DLL
X-Passed-To
X-Passed-To-DLL
X-Internal-ReqID
X-Returned-From
Akamai-IP
X-LB
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-UD-Method
X-TransIP-Balancer
X-Platform-Router
X-Matrix-Proxy
X-Source
X-Platform-Processor
X-Platform-Cluster
X-Matrix-Server
X-Stale
Dmn
X-Cache-TTL
X-Cache-Info
X-App-Hosting
X-Cdn
X-Upstream
X-Akamai-Transformed
X-Accel-Expires
X-Origin
X-HS-Content-Campaign-Id
X-Device-Type
Content-Hash
Powered-By-ChinaCache
X-NetCat-Version
X-I
X-S
X-Varnish-Count
X-Varnish-HitMiss
X-Storage
X-Varnish-RemainingLife
X-Varnish-GracePeriod
X-Varnish-ObjectSource
X-Varnish-Seen-By
X-Varnish-RemainingTTL
X-Cache-Tags
Ohc-File-Size
X-TransIP-Backend
X-Expires-Orig
USPLoggingUUID
X-Revision
IBM-Web2-Location
X-Cache-Debug
X-Varnish-Cacheable
X-Powered-By-VelaWeb
X-Gamma-Serve
X-Dispatcher
X-Cache-Operation
Pool
X-Version
Version
X-Front
MIME-Version
WPE-Backend
X-Cache-Key
X-Rocket-Nginx-Bypass
X-LB-Node
X-Content-Encoded-By
X-Translation
X-Signature
X-Microcache-Status
X-Daa-Tunnel
X-EdgeConnect-Origin-MEX-Latency
HTTPS
Content-Disposition
X-Route-Server
X-VTEX-Cache-Status-Janus-Edge
X-Supported-By
X-UPSTREAM
X-Cache-Lifetime
X-Platform
Public-Key-Pins-Report-Only
Srv
X-Varnish-Backend
X-NewRelic-App-Data
Last-Published
X-NoCache
X-Debug-Info
X-Dispatch
X-Art-Request-Id
X-Vcap-Request-Id
X-ATG-Version
X-EdgeConnect-MidMile-RTT
X-Server-Upstream
X-Platform-Cache
Page-Completion-Status
X-Director
X-Varnish-Age
ServerID
X-Page-Cache
X-SSL-Protocol
X-Sapient
X-SSL-Cipher
Node
X-Firenze-Processing-Time
ServerName
X-Server-Id
Cache-Tag
X-Flow-Powered
X-Last-Modified
X-Duration
X-Server-ID
X-AOL-HN
X-Cache-Control-Orig
X-Cache-Only-Varnish
X-Platform-Server
Proxy-Connection
X-TTL
X-Debug
X-SV-Edge
X-SV-Cacheable
X-SV-CacheTags
X-Url-Base
X-SV-Duration
X-SV-CreatedAt
X-SV-Pid
X-SDS
X-PwB-Node
X-SV-FromDBCache
X-SV-Nginx-Duration
SSPAppContext
X-Hypernode
X-SV-Expires
X-ORACLE-DMS-ECID
X-F-Cache
X-Country-Code
X-Edge-IP
X-Cookie-Domain
X-Abuse
Cache-Key
FAI-W-FLOW
X-CJ-Soft
X-Abgroup
X-Geo-Country
X-Dns-Prefetch-Control
WSR-Cache
Edge-Content-Tag
Cneonction
X-Cache-CFC
Lsrequestid
SN
Allow
Accept-Encoding
Author
X-Cache-Expires
X-ServerID
X-Magento-Cache-Debug
X-GeoIP-Country-Code
X-Speed-Cache
X-RequestId
X-Cache-Server
X-Nbs
X-Speed-Cache-Key
X-Grace
X-Client-IP
IM-Version
X-Amz-Meta-S3cmd-Attrs
Location
X-Frontend
Content-Encoding-Handler
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
If-Modified-Since
X-LW-Cache
X-IsCacheURL
X-GeoIP-Country-Name
X-Id
NnCoection
X-FW
PICS-Label
X-SERVER-NAME
X-Orig-Vary
X-Discourse-Route
X-CDN-Cache-Status
X-CDN-Node
X-Akamai-Device-Characteristics
X-Loopia-Node
X-BackendServer
X-Time
X-Varnish-IP
A-Powered-By
X-Middleware-Start
X-Purge-URL
X-NB-Cached-Page
X-Content-Age
Cache-Provider
X-ARC
X-Processing-Time
X-Sucuri-ID
S-Cnection
Backend
X-Real-Server
X-Processed-By
X-Vhost
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
Section-Io-Id
X-Proxy
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Sucuri-Cache
X-Cache-Handler
Qs-Cache
X-GUploader-UploadID
X-DealerOn
Req-Id
X-Nginx-Cache
Pv
X-Purge-Host
Use-Proxy
Cached
X-Ttl
X-Akamai-Device-Model
NetMindSessionID
X-Lambda-Id
X-SRCache-Key
X-SE-Debug
AMF-Ver
X-N
X-Varnish-Url
X-Pressidium-NinukisWP-Ver
X-Shield-Request-Id
CacheControlHeader
X-Cache-Level
Access-Control-Allow-Header
Cteonnt-Length
X-Browser
X-Yadis-Location
Fw-Via
Cache
X-Framework
X-Cache-Control
RTSS
X-Always-Cache
S
SEOMOZ
MJ12bot
X-Cache-PageType
Nodo
X-Cache-Fix
X-BKSrc
X-Generated
X-TB-M
X-Healthy
Nitro-Cache
NODE
X-PF-Uncompressing
X-Trace
X-Config-Blacklist-Version
X-Worker
X-Cache-Type
X-Cache-Engine
Tracecode
Local-Info
X-WR-Flags
MC
X-CDN-Forward
Xc-Version
X-Magnolia-Registration
Accept-Charset
Server-Info
X-ClientSide-Caching
X-Hiawatha-Cache
X-Varnish-Server
X-Unique-ID
X-Content-Type-Option
X-SO
Thanks
SVR
X-Transaction
X-Connection-Hash
Retry-After
X-Cache-TTL-Remaining
X-Varnish-Hits
X-Twitter-Response-Tags
WWW-Authenticate
Frame-Options
X-Drupal-Cache-Tags
HAVer
HCVer
Identity
Content-Transfer-Encoding
X-Content-Security-Policy-Report-Only
X-Amz-Storage-Class
X-LB-Server
X-Adobe-Content
Eomportal-Instance
X-ID
X-Empowered-By
X-Hit-Cache
X-Pagename
X-Adobe-Loc
X-Mobilized-By
X-Powered-By-Server
EagleEye-TraceId
X-HP-Trace-Project
BALANCEDTO
X-Srv
X-JG-Page-Cache
X-HP-Trace-ID
Cm-Server
RATING
X-Drectory-Script
HitType
X-VC-TTL
X-Varnish-Ttl
X-Sys-Req-ID
X-CB-Server
X-LW-Web-Server
X-Cache-Device-Type
X-Varnish-ID
X-Server-IP
X-Resty-Request-Id
Server-Name
X-Fedora-School-Id
X-Site-Name
X-Session-Reinit
X-Symfony-Cache
X-HW
X-LP
X-ACMCache
X-Traffic
X-Route-To
X-Static
X-Directory-Script
Front
Buuteeq-Source
NtCoent-Length
X-OPNET-Transaction-Trace
X-GeoIP
Fastly-Backend-Name
X-Disney-Akamai-Rule
X-Runtime-Memory
X-Magento-Cache-Control
X-Environment
X-CF-Passed-Proto
SBGI-7
X-RiS-UFDI
SBGI-9
SBGI-RealPath
ServerSignature
ServerTokens
X-ORACLE-DMS-RID
X-Nginx-Host
SBGI-10
SBGI-5
Max-Age
X-App-Server
Disablevcache
SBGI-1
Content_type
SBGI-Device
X-AF-Userserver
X-Varnish-Retries
Ufe-Result
X-HydroSheep
Keywords
X-High-Performance
X-Garden-Version
SBGI-RenderTime
X-Key
X-FORWARDED-PROTO
X-Remote-Addr
X-TTFB
X-Cocoon-Version
X-TTFB-L
X-Generated-Time
X-A
X-SmugMug-Values
Pics-Label
X-FireWall-Port
X-VC-Enabled
X-SmugMug-Hiring
Smug-CDN
CLMOB
From-Origin
X-Client-Image-Vid
X-OpenCart-Lightning
X-Client-Vid
IISExport
Magicmarker
X-EPiphany-Vid
X-CAPServer
SRV
X-Cache-Provider
X-Cache-Source
X-Varnish-Hostname
X-ARRServer
X-Cache-Dispatcherpragma
X-Cache-Dispatchercachecontrol
AsisCache
X-Cache-Doesi
X-Frame-Option
X-Webcelerate
X-Cache-Node
X-WP
X-Dynatrace-Js-Agent
Dis-Env
X-Runtime-Rack
X-Smartcache-Timeout
X-Distributor
AC-ELC
X-Balanceador
X-Mobile-URL
X-Env
X-Cache-Detail
X-WHOIS-Cached
X-NginX-Cache
X-Yottaa-Metrics
RN-Server
Description
X-Yottaa-Optimizations
X-Smartcache-Keys
Machine
X-Captured
X-Unbounce-PageId
X-Debug-Token
X-E
X-Blog
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Middleton-PageSpeed
X-Cached-Status
X-App-Status
X-Served-Server
X-Server-Instance
X-Unbounce-Variant
X-Unbounce-VisitorID
Home
Response-Time
Ctx
X-CacheResult
WN
X-WN-ClientGroup
Provider
X-VARITI-CCR
X-App
X-Esi
X-Jphone-Copyright
Yoncu-Errno
Web-App-Origin-Name
Strikingly-Cached-Version
X-Amz-Meta-Cb-Modifiedtime
X-ServerIndex
From
Strikingly-Cache-Region
Strikingly-Cached
XDomainRequestAllowed
SS
X-AEM
X-PageType
X-UA
X-Drupal-Cache-Contexts
X-Analytics
Backend-Timing
X-Location
X-NginX-Server
X-DataDome
X-Author
ScoreTracker
X-Backend-Status
X-L-Path
X-Rewrite
X-SH-Cache-Status
X-GSL-Server
X-Domain-Checked
Dispatcher
CommunityServer
X-ETag
X-Site
NLCacheNote
X-Cache-Keep
X-Environment-Context
X-HP-Redirect
X-Provisioner-Version
X-Grid-Server
X-Desc
X-Machine-Name
X-Rebelmouse-Cache-Control
X-Actindo-RS
X-Source-ID
X-Application
X-Plat
SG
X-Rebelmouse-Surrogate-Control
X-Resolver-IP
Sophnep-Edge-FX
X-RDP
X-Cache-On
X-Proto
Bios
X-Page
X-Time-Microsecs
DNNOutputCache
Cmsid
X-MAT-GEO
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
Cmstype
X-Atraveo-Set-Cookie
Paypal-Debug-Id
Hname
X-PRAM
X-Force
X-Batcache
X-Machine
X-Atraveo-Param-Rm
X-Atraveo-TTL
X-Atraveo-Expires
X-Atraveo-ETag
X-Atraveo-Cache-Control
X-Atraveo-From-Varnish-Cache
X-WR-MODIFICATION
X-Runtime-Affili
X-Detected-Device
Og
X-Session-ID
X-Dw-Trace-Id
MW-Webserver
X-Ser
X-EC2-Instance-Id
X-Cdn-Forward
VServer
Device
Resin-Trace
Ttl
Xc
X-Culture
X-PM-ID
X-Batcache-Reason
X-App-Runtime
X-Rack-Cors
X-We-Are-Hiring
X-Render-Time
X-SDE-Name
X-Hosting-Env
X-Correlation-ID
X-Nginx
X-Req-Head-Response
X-Autoru-LB
X-Map-Context
X-AutoRu-App-Id
X-Autoru-Host
X-Varnish-Debug-Age
X-Varnish-Debug-TTL
X-Cluster-Node
X-Webapp
X-Sc-Cache
X-ASAP-Cache
X-Amcomm-Site
ViewMode
X-Clara-ASAP
X-IIJ-Cache
X-Amz-Id-1
X-FRUIT
X-Rocket-Nginx-Serving-Static
X-Pageid
X-Magento-Action
X-Frames-Options
X-Info
X-MSEdge-Ref
W
X-Response
X-RemovedCookies
X-Trace-Id
Content-Server
Ibf5scheme
X-Viator-Tapersistentcookie
VANITY-HOST
X-Proxy-Cache-Key
X-KoobooCMS-Version
X-Config-By
X-CRA-DC
Beyond-Iis
Id
Cluster-ID
X-ProcessESI
X-Forwarded-Host
X-Airee-Node
N365rili
X-Rq
X-ENV
X-Resource
X-Varnish-Action
X-Goog-Meta-Policy
X-Goog-Meta-Replace
X-ACCELERATE
X-Lb
X-Stage
X-Hstore
X-This-Proto
X-Optimization
BackendServer
X-Varnish-Info
X-Header
Nginx-Cache
X-Rack-CORS
X-Hrouter
X-Farm-Server
X-Hosting
X-HTML-Minification-Powered-By
X-Streams-Distribution
F5-IpCliente
X-Secret
Tempo
Web
X-CDN-RULE
AccessControlAllowOrigin
Proxy-Cache
X-CDN-COMPRESS
X-V
Server-ID
X-Zendesk-Origin-Server
X-XHR-Current-Location
X-Ezoic-Cdn
X-Highwire-SessionId
X-M
X-LOCATION
Lb
X-HA-Frontend
X-Node-Name
Il-Cl
X-Zendesk-User-Id
X-SmartBan-URL
X-SmartBan-Host
X-Powered-By-Home.Pl
X-Highwire-RequestId
NS-VaryByCustom-Key
X-WebKit-CSP-Report-Only
X-7d-Instance-Id
OriginServer
X-HA-Backend
X-Avvio-Cms-Cacheload
X-Varnish-Cache-Local
X-RAMCache
X-Cache-Varnish
X-Reflector
Expect-Ct
X-Data-Request
X-Refresh
Note
X-MidCOM-Meta-Cache
FastCGI-Cache-Status
X-Adnet
RequestId
Gzip
X-DTC
Set-Cookie2
Accept-Language
X-Cache-Via
Worker
X-Cacheable-TTL
X-Cms-Mode
ClientIP
X-Cache-TTL-Age
X-HashTwo
WP-AdvCache-MemCached
X-Dev
Access-Control-Request-Headers
NCache
X-Reflector-Cache
X-Depends
X-RealServer
X-7d-Trace-Id
X-Cache-TTL-Current
X-CACHE-TTL
X-APP
X-Nginx-Request-Time
SERVER-ID
X-SV
X-HAProxy
X-Src-Webcache
X-DB-Content-Length
PagesDisplayed
X-MCB-Server
X-Pagely-Cache
SBMCLOUD
X-Generation-Time
X-Apm-Telemetry-Syncmark
X-Gyrobase-Publication
X-ELB
X-DN-Cache-Control
X-B2f-Not-Route
X-Proxy-Id
X-DevSrv-CMS
D
X-AISO-Cacheable
X-AISO-Cache
X-Time-Zone
X-Uncacheable
X-Varnish-Instance
X-VLoc
X-ServiceProvider
Cache-Status
COMMERCE-SERVER-SOFTWARE
X-ACLR-Version
X-S-Misc
X-Server-FQDN
X-AISO-Server
X-Flex-Lastmod
TC-Cache-U
TC-S-Cache
TC-S-Cache-M
X-CCM
TC-Cache-IC
ServerIP
Session-From
TC-Cache
X-DSMX-Render-MS
Myheader
X-Cache-Time
X-Server-Generated
X-Distil-CS
Traffic-Origin
X-D-Time
X-SCM-Server-Number
X-Ghost-Cache-Status
Progma
X-Compressed-By
X-DSMX-Rewrite-MS
X-Search-Id
X-Test
X-Fpc
X-Built-With
X-Bcwwwid
Kanooh-Host
X-Upstream-Backend
Kp-EeAlive
X-Flex-Tags
X-Flex-Tag
X-Flex-Evend
X-Flex-Community
X-Varnish-Cached-TTL
X-Flex-Evstart
X-Node-ID
X-MCF-ID
X-Obj.Ttl
X-Flex-Lang
VAR-Cache
X-Varnish-Cached
AMFplus-Ver
X-Beresp-Ttl
Url
X-Session-Id
Debug-Status
SiteSpeed
X-RiS-PX
X-Router
X-Router-Backend
X-Tradeindia-Request-GUID
X-Tradeindia-SMgmt
X-CacheID
X-Catalyst
X-PBS-Appsvrip
X-Cache-FS-Status
XDisk
X-UseReverse-Proxy
X-ReqId
X-Webstats-RespID
X-Provided-By
PServer
X-W3TC-Minify
WFE
Session-Id
SB-Site-IE-VERSION
X-CACHE-KEY
X-Cache-Warmer
NZSpeedy
Ews
X-CH-Device
SB-Site-Device
SB-Cache-Remaining
X-JSESSIONID
X-Artvisual-Server
Provided-Host
X-IP-Address
RSL-Trace-ID
X-EC-Security-Audit
SB-Cache-Life
X-Front-Cache
X-PBS-Fwsrvname
X-PBS-Appsvrname
Content-Cache
DbServerName
FindLaw
X-Upgrade-Enabled
X-SilverStripe-Cache
X-PHP-Response-Code
X-Sid
Rewriter
SINA-LB
X-Amzn-Trace-Id
X-AppServer-Cache-Rule
X-Country
X-Amzn-RequestId
Webserver
SINA-TS
UrlWatchModule-Time
X-Dynamic
X-REDIRECTSERVER
X-Cache-Extended
X-Brought-To-You-By
X-Box
X-DEBUG
X-HostName
X-VC-Debug
X-DeliveryServer
X-Dynamic-Cache
X-Pixelsilk-Version
X-4ormat-Cacheable
StatusCode
Warning
X-Cache-BE
X-Pixelsilk-Server
X-Server-Addr
X-Tag-Playlist
X-PBY
X-Ocache
X-Turpentine-Esi
X-LBPoolMember
X-ChromeLogger-Data
Swift-Performance
X-Cache-HT
X-Lima-Id
Cleartype
MS-CV
Server-Ip
X-IP
X-Webkit-CSP
X-Nocache
X-Header-Treatment
X-DDM-SERVER
X-CSRF-Token
X-Config-Version
X-Custom-Header
X-Ss-Conf
X-UPSTREAM-Address
X-Ss-Location
No-Cache
PLCDN
X-Not-Cacheable
X-NewsFlow-Sitename
X-MainProfileURL
RSB-LINK
X-Server-Instance-Name
!~Request-OOB-Work
Access-Control-Allow-Method
ENV
X-Cache-Id
X-Old-Content-Length
X-Aramark-SID
Server-Id
X-GoCache-CacheStatus
X-CM-FE
X-WPL-DATA
X-Phpwcms-Page-Processed-In
X-Phpwcms-Release
X-Real-IP
X-Svr
DrivedBy
X-Script
X-Amz-Meta-Content-Md5
X-Beatles
INFO
X-ServerAddr
X-Gannett-Site-Version
X-UPServer
X-EC-Custom-Error
X-Cname-TryFiles
X-App-Version
X-Backend-TTL
X-Agent
MageStack-Web-Node
MageStack-Tag
MageStack-Magento-Version
MageStack-PageSpeed
X-Faeria
TP-L2-Cache
TP-Cache
X-Title
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NewCloud-V-Cache
X-Cms-Server
X-Origin-Cache
SHInfo
X-Cache-Me-Harder
X-WebNode
MageStack-Loadbalancer
MageStack-Debug
X-MainProfileID
X-Served
AMP-Access-Control-Allow-Source-Origin
X-Rocket-Nginx-Reason
X-Made-On
X-MainProfileName
X-Debug-Message
X-Deity
Brightspot-Id
MageStack-Area
MageStack-Cache-Status
MageStack-Cacheable
MageStack-Config
MageStack-Cache-Lifetime
X-HP-CAM-COLOR
MageStack-Cache
X-MainProfileCategory
MageStack-Cache-Hits
X-Layout
X-Route
X-Pubstack
X-Unique-Id
GP-Remote-Addr
X-ManagedFusion-Rewriter-Version
X-FIRSTBase
Fw-Cache-Status
X-Wm-1
X-Meta-MSThemeCompatible
X-Meta-MSSmartTagsPreventParsing
X-NodeID
X-Who
X-XHTML-Minification-Powered-By
X-Test-Debug
X-OCTOPOD
Ibm-Web2-Location
X-Meta-Imagetoolbar
X-UnsetCookies
X-AWS
Aurora-Node
CDCHOST
Edgecast
X-WA-Info
X-Enhanced-By
X-Nginx-Request-Processing-Time
X-RequesterIP
X-AMAZEEIO
X-AppVersion
X-Count
X-Wm-VIP
Actual-Object-TTL
X-SuperCache
X-Container
GP-Version
Cache-Tags
X-Rewritten-By
X-HASH
X-Cjtype
X-Backend-Name
MSSmartTagsPreventParsing
MSThemeCompatible
X-Sn-Servicetimems
FrontEnd
X-NID
X-Webkit-Csp
X-B3-Traceid
X-B3-Spanid
X-Serendipity-InterfaceLangSource
Expiries
X-DDM-SERVER-UPDATED
X-Serendipity-InterfaceLang
X-FreeTag-Count
X-Fstrz
X-Backend-Host
X-DS1D
X-Obj-Ttl
X-COUNTRY-CODE
X-C2M-Runtime
X-Webkit-CSP-Report-Only
X-C2M-Server
X-Ssl-Cipher
X-Cf-Powered-By
X-Varnish-URL
X-Litespeed-Cache-Control
X-Oracle-DMS-ECID
Language
X-SVR
X-Theme
X-PROCESSED-BY
M
B-Rlogid
Content-Generator
Accept-CH
X-CPU-Time
X-Pass-Through
Tk
X-FastCGI-Cache
WSCLoggingUUID
X-EBAY-C-REQUEST-ID
DB-Nickname
X-Generated-Date
X-FPC
X-FG-RequestId
X-Ezpublish-Installationid
X-Ezpublish-Nodeid
X-Highwire-Sitecode
X-ESI
Rlogid
X-Obvious-Tid
X-Obvious-Info
TheAnswer
X-Highwire-Smart-Code
X-Origin-Server
X-Protected-By
X-Pool-Info
X-Cachable
X-Transaction-Name
ReqUrl
Server-Tuning
Resource
X-Build-Id
X-VNode
X-DynamicCache
X-ASAP-Age
X-Serverid
X-UT-Cache
X-Vary-Options
Session
X-Instance-Id
X-Tt-Dbg
X-Skip-Cache
CD4
X-PG
X-Varnish-VCL
X-Geo-IP
X-Client-Ip
X-SRV
X-Netrix-ID
X-Stiffia-Cache
E-TAG
Lookup-Cache-Hit
User-Cache-Control
Tesla.Performance
CpuTime
X-NMT-Proxy
V-Age
X-Cluster
Aoestatic
X-Prerendered
X-BServer
X-BPool-Fx-Cache
X-BC
X-Ants-Machine-Id
X-BPool
X-BPool-Back
X-BPool-Bx-Cache
Be
Contao-Page-Layout
X-Support
X-Magento-Lifetime
X-Varnish-Debug-Hits
Generate-Time
IsMobile
X-HEAD
X-Cache-ID
HostName
EQ-Cache
Microcache
Upgrade-Insecure-Requests
WP-Cache
X-Ants-Host
VC-NoCache
AR-ATIME
X-Your-GrandPa-Would-Wait
AR-CACHE
AR-PoweredBy
AR-SID
X-Would-Your-GrandPa-Wait
X-Server-App
X-Enabled2
X-Enabled3
X-UUID
X-TTL-Age
X-Request-Received
GranicusServer
X-Built-By
X-Imforza-Hosted
X-Archive-Orig-Server
X-Pj-Cache-Status
X-Content-Parsed-By
X-Csrf-Token
X-Request-Processing-Time
ProxiaInstanceId
X-Amz-Meta-Version-Id
X-Cache-LB
X-Enabled1
X-Does-He-Have-Time
X-Varnish-Max-Age
X-Varnish-Set-Cookie
X-Varnish-Store
Content-Legth
X-Varnish-Esi-Method
X-Varnish-Esi-Access
X-Max-Age
X-Hash
X-Turpentine-Cache
X-Varnish-Currency
X-Debug-Serve
X-Debug-Out
X-Cache-Set
WebServer
ServerNode
OutputRewritten
Www.Aujourdhui.Com
X-Beatles-Hits
Public-Extension
ResourceTag
X-Cache-Served
X-Ar-Debug
X-Processed
X-Archive-Orig-ETag
X-W-Cache-Hits
X-Restarts
Ez
X-Instance-Name
X-W-Cache
X-Cache-Action
X-Op-Benvironment
X-ZORequestID
Yola-ID
X-BeResp-Ttl
X-Ec-Custom-Error
X-No-Session
Apple-Itunes-App
X-9XB-Server
X-Auto-Login
X-Cache-Bypass
X-Jcms-Ajax-Id
Url-Hash
Httpd-Identifier
Hosted-By
CD1
Vserver
AGI-Request-ID
X-HS-Status
Copyright
Server-Node
Memento-Datetime
EXT-CACHEEXPIRE
X-Archive-Guessed-Charset
X-Archive-Orig-Connection
X-Archive-Orig-Date
X-SCProxy
X-Archive-Orig-Content-Length
0
X-Vol-Mrp
X-Vol-Correlation
X-Czt
X-FCMS-Cache
Debug-Cache-Control
Container
Debug-Expires
MwpReleaseVersion
Prototype-RootPath
X-Accel-Cache-Control
X-Forwarded-By
X-AG-MIPS
X-Diazo-Applied