Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
CF-RAY
X-Cache
Age
Content-Language
X-AspNet-Version
P3P
X-Pingback
Expect-CT
X-UA-Compatible
Via
Upgrade
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Request-Id
X-Adblock-Key
Referrer-Policy
X-Varnish
X-Check
X-Generator
X-Language
X-Template
X-Buckets
X-Drupal-Cache
P3p
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-Xss-Protection
Alt-Svc
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-AspNetMvc-Version
X-Cache-Hits
Host-Header
X-Hacker
X-Ac
X-Dc
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-FeatureSet
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Powered-By-Plesk
X-Runtime
X-Served-By
X-Via
MS-Author-Via
Content-Location
X-Amz-Cf-Id
X-Powered-CMS
Access-Control-Allow-Headers
X-Contextid
X-IPLB-Instance
Access-Control-Allow-Methods
X-ServedBy
X-UA-Device
X-PC-Key
X-PC-Hit
Cartoon
Status
X-PC-AppVer
X-PC-Host
X-PC-Date
X-Timer
Access-Control-Allow-Credentials
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
CF-Cache-Status
X-Rid
X-Iinfo
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-NewRelic-App-Data
X-Wix-Request-Id
X-Seen-By
X-Backend
Powered-By
X-WPE-Loopback-Upstream-Addr
X-Tumblr-Pixel-1
Content-Encoding
X-Mod-Pagespeed
X-Cache-Status
X-CST
X-Host
X-Tumblr-Pixel-2
X-Server
X-Endurance-Cache-Level
X-Cache-Enabled
X-Cache-Hit
X-Port
X-Logged-In
Keep-Alive
X-CDN
X-Server-Powered-By
X-DIS-Request-ID
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Robots-Tag
X-Tumblr-Pixel-3
X-Accel-Version
Server-Timing
X-Turbo-Charged-By
X-Proxy-Cache
X-Page-Speed
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Content-Digest
X-Content-Powered-By
X-LiteSpeed-Cache
X-GitHub-Request-Id
X-Rack-Cache
Content-Security-Policy-Report-Only
X-Pad
X-ASPNET-VERSION
X-AH-Environment
X-Varnish-Cache
Edge-Control
X-FW-Hash
X-FW-Server
Request-Context
X-FW-Type
X-FW-Serve
X-FW-Static
X-XRDS-Location
X-Request-Country
SPRequestGuid
WP-Super-Cache
X-SharePointHealthScore
X-MS-InvokeApp
X-Tumblr-Pixel-4
X-Hits
X-Trace
MicrosoftSharePointTeamServices
X-Webcom-Cache-Status
X-Request-ID
X-Newrelic-App-Data
Timing-Allow-Origin
X-BC-Stapler
Cf-Railgun
X-Node
Edge-Cache-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-HS-Cache-Config
Access-Control-Expose-Headers
X-HS-Content-Id
X-Ua-Compatible
X-Died
Charset
X-Cache-Lookup
X-Webserver
X-Content-Security-Policy
X-CF-Powered-By
X-PhApp
X-Cnection
X-FullPageCaching
Access-Control-Max-Age
X-HS-Combine-CSS
X-Fastly-Request-ID
Request-Id
X-PHP-Backend
X-INKT-SITE
X-INKT-URI
SPIisLatency
SPRequestDuration
EagleId
X-Backend-Server
X-Swift-CacheTime
X-Swift-SaveTime
MicrosoftOfficeWebServer
X-CDN-Pop-IP
X-CDN-Pop
Grace
Composed-By
X-Safe-Firewall
X-SS-Conf
X-SS-Location
Served-By
Liferay-Portal
X-Device
X-Spip-Cache
Rating
X-Dw-Request-Base-Id
X-Hyper-Cache
X-Server-Name
Front-End-Https
X-Cloud-Trace-Context
X-Microcache
X-HeyJason
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-Tumblr-Pixel-5
X-NF-Request-ID
X-VCache
X-DDC-Arch-Trace
X-Edge-Cache
X-Edge-Cache-Key
Refresh
X-Tumblr-Content-Rating
X-RateLimit-Remaining
X-RateLimit-Limit
X-LiteSpeed-Cache-Control
X-RateLimit-Reset
X-Jimdo-Instance
X-Jimdo-Wid
X-Cluster-Node
X-FB-Debug
X-TNCMS
X-Loop
X-Wix-Punisher
X-Middleton-Display
X-Acc-Exp
Display
Surrogate-Control
X-Sol
X-Clacks-Overhead
X-Middleton-Response
Response
Content-Style-Type
P-LB
X-DNS-Prefetch-Control
P-WS
Content-Script-Type
Public-Key-Pins
X-Vtex-Processado-Em
X-OneAgent-JS-Injection
X-Firenze-Processing-Times
X-Debug-Info
X-StackifyID
X-Age
X-SERVER
X-Kinsta-Cache
X-User-Agent
X-Magento-Tags
X-Goog-Hash
Fpc-Cache-Id
X-Px
X-Cache-Config
X-XN-Trace-Token
X-XN-XNHTML
X-WebKit-CSP
X-Amz-Version-Id
X-Cached
Xkey
X-N-OperationId
X-Ruxit-JS-Agent
X-Shopid
X-Sorting-Hat-Shopid-Cached
X-Sorting-Hat-Shopid
X-Sorting-Hat-Privacylevel
X-Sorting-Hat-Featureset
X-Sorting-Hat-Podid-Cached
X-Shardid
X-Sorting-Hat-Podid
X-Hostname
X-Generated-By
X-Original-Date
X-Zen-Fury
Retry-After
PageSpeed
X-DynaTrace-JS-Agent
X-Frame-Option
X-Tumblr-Pixel-6
X-LW-Cache
X-Handled-By
X-Topify-Platform
X-Url
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Loopia-Node
X-Whom
X-URL
Rt-Fastcgi-Cache
X-MiniProfiler-Ids
X-B-Cache
X-Edge-Location
X-Varnish-TTL
X-Upstream
Edge-Control-Message
Feature-Policy
X-Platform-Processor
X-Platform-Cluster
X-CMS-Version
X-Platform-Router
X-Request-Time
X-Cached-By
Access-Control-Request-Method
X-Engine
Fhost
X-Servedby
Fastcgi-Cache
X-AspNetWebPages-Version
TCN
Powered
X-Content-Options
X-Source
X-Outils-CS
Public-Key-Pins-Report-Only
X-From
X-EdgeConnect-Origin-MEX-Latency
X-FORWARDED-FOR
ServedBy
X-Accel-Expires
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Developer
X-Varnish-Host
X-EdgeConnect-MidMile-RTT
X-CacheServer
No
X-Vtex-Processed-At
X-Vtex-Remote-Cache
X-VTEX-Janus-Router-Backend-App
X-VTEX-Cache-Status-Janus-ApiCache
X-Powered-By-VTEX-Janus-ApiCache
X-RESOURCE
X-Cdn
X-DynaTrace
Allow
X-Recruiting
Pagespeed
X-Magento-Cache-Debug
X-Version
X-Signature
X-URLSCHEME
Product
X-Location-Id
X-Varnish-Cache-Hits
Imagetoolbar
X-Response-Time
X-Application-Context
X-F-Cache
X-Correlation-Id
Warning
Last-Published
X-Defender
X-Shop-Id
X-Umbraco-Version
X-ApacheServer
X-PERF
X-Forwarded-For
Host
X-LBLID
X-Actual-URL
X-Platform-Cache
X-Original-Request
X-Varnish-Beresp-Status
X-Returned-From
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
DynaTrace
X-Passed-To
X-Passed-To-DLL
X-Returned-From-DLL
X-NWS-LOG-UUID
Generator
Arr-Disable-Session-Affinity
X-Microcachable
X-Stale
X-Device-Type
X-ET-API-VERSION
X-ET-API-ROOT
X-ET-API-ORIGIN
X-Via-JSL
X-Returned-From-BeforeDispatch
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Environment
X-UD-Method
X-Passed-To-PostProcessResponse
X-Micro-Cache
X-Cache-Namespace
X-Cache-Key
Origin
Alternate-Protocol
X-Hosted-By
X-Powered-By-360WZB
X-Platform-Server
X-Fastcgi-Cache
X-S
X-Guploader-Uploadid
X-Varnish-HitMiss
Version
X-Varnish-Count
X-Ezoic-Cdn
X-Platform
Content-Hash
Cache-Provider
X-Cache-Rule
X-Cache-Info
X-Supported-By
X-Msg-2-Log
X-Rnd
X-SO
X-BS
X-I-Sp
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
WZWS-RAY
X-App-Status
X-HS-Content-Campaign-Id
X-Correlation-ID
X-HOST
X-Lambda-Id
X-Cache-Age
Surrogate-Key
X-Dns-Prefetch-Control
X-Duration
X-Microcache-Status
X-Cache-Tags
X-Instart-Request-ID
X-Translation
X-TransIP-Balancer
X-Expires-Orig
RTSS
X-Server-ID
X-LB-Node
X-Cache-Control-Orig
X-Dispatcher
Cache-Key
X-TransIP-Backend
USPLoggingUUID
X-Sapient
X-Director
X-Server-Upstream
X-Magento-Cache-Control
X-SSL-Cipher
X-GUploader-UploadID
X-Front
X-SSL-Protocol
X-Last-Modified
X-Page-Cache
MIME-Version
X-Akam-SW-Version
Content-Disposition
X-Revision
X-Vcap-Request-Id
X-Powered-By-VelaWeb
X-Hypernode
Pool
X-Track
X-Edge-IP
X-Abgroup
X-Rocket-Nginx-Serving-Static
X-CSRF-Protection
X-Daa-Tunnel
X-Storage
Akamai-IP
X-App-Hosting
Dmn
Wsr-Cache
X-ORACLE-DMS-ECID
S-Cnection
X-Ttl
X-Cache-Debug
X-Varnish-Seen-By
X-Cache-TTL
X-Varnish-RemainingTTL
X-Geo-Country
X-Varnish-GracePeriod
X-Dealeron-Backend
SSPAppContext
X-DealerOn
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Dealeron-Original-Url
X-ARC
Accept-Encoding
X-Cache-Handler
X-Debug
X-Powered-By-VTEX-Janus-Edge
X-NetCat-Version
X-Rocket-Nginx-Bypass
X-Forwarded-Proto
X-NoCache
X-Matrix-Proxy
X-I
X-Art-Request-Id
Node
X-Cache-Engine
X-Matrix-Server
X-Client-IP
X-Litespeed-Cache
X-Drupal-Cache-Tags
X-Dispatch
X-Magnolia-Registration
X-SDS
If-Modified-Since
X-Url-Base
X-Cache-Type
X-Cache-Lifetime
X-ATG-Version
X-VARITI-CCR
SN
X-Hiawatha-Cache
ServerName
X-Varnish-Cacheable
X-IsCacheURL
Backend
Contao-Page-Layout
X-Route-Server
X-Gamma-Serve
X-Cache-Only-Varnish
X-Generated
ServerID
X-Varnish-Url
X-Discourse-Route
X-Country-Code
X-Cf-Powered-By
X-Pressidium-NinukisWP-Ver
Cneonction
X-Cache-Level
X-ServerName
Powered-By-ChinaCache
X-CJ-Soft
X-Grace
Content-Encoding-Handler
X-Vhost
Author
X-SV-Duration
X-SV-Expires
X-SV-FromDBCache
X-SV-Nginx-Duration
X-SV-CreatedAt
X-SV-CacheTags
Section-Io-Id
X-Drupal-Cache-Contexts
X-LB
X-SV-Cacheable
FAI-W-FLOW
X-Firenze-Processing-Time
X-SV-Edge
X-SSLUpstream
X-Varnish-Backend
X-Cache-Operation
X-SSLProxy
X-N
X-SV-Pid
X-Cache-Server
X-Amz-Meta-S3cmd-Attrs
X-Processing-Time
X-Cache-Expires
Proxy-Connection
X-SRCache-Key
Lsrequestid
AMF-Ver
X-LB-Server
X-SVR-IIS
Page-Completion-Status
X-Svr-Proxy
X-Flow-Powered
X-Content-Encoded-By
X-Browser
X-ServerID
X-Varnish-Age
PICS-Label
X-Service-Id
X-Cache-Device-Type
Src-Update
Update-Time
Surrogate-Key-Raw
X-UPSTREAM
X-Trace-Id
X-Pantheon-Site
X-Pantheon-Phpreq
X-Frontend
X-GeoIP-Country-Code
X-Pantheon-Environment
Srv
X-FTR-Request-ID
X-Server-Id
SiteSpeed
X-TransIP-Reserved
X-PwB-Node
X-Varnish-IP
Req-Id
X-Server-Instance
X-SmugMug-Values
X-Unbounce-PageId
X-SRV
X-TTFB
Pv
Smug-CDN
Cache
X-Nbs
X-Dynamic-Cache
X-TTFB-L
X-SmugMug-Hiring
X-Unbounce-Variant
X-Unbounce-VisitorID
X-Id
Location
Nodo
X-Varnish-Ttl
X-Env
X-ORACLE-DMS-RID
Xc-Version
X-ACMCache
IM-Version
X-Real-Server
X-HW
X-Time
X-CF-Passed-Proto
X-Symfony-Cache
X-Varnish-Retries
X-High-Performance
X-Sucuri-ID
X-FW
Server-Name
Qs-Cache
X-RequestId
Https
Edit
X-FastCGI-Cache
X-CacheFROM
X-Locale
X-Config-Blacklist-Version
X-CDN-Forward
X-Middleware-Start
X-Varnish-Hits
Tracecode
Fw-Via
NnCoection
X-Runtime-Rack
X-Esi
MC
X-Always-Cache
MJ12bot
X-Nginx-Cache
SEOMOZ
X-Cache-PageType
X-Cache-Fix
Ohc-File-Size
X-Akamai-Device-Characteristics
X-Akamai-Device-Model
IBM-Web2-Location
Use-Proxy
X-Connection-Hash
X-Empowered-By
X-Drectory-Script
X-Origin
X-Twitter-Response-Tags
Dtk-Cache-Check-0
X-Speed-Cache-Key
X-PF-Uncompressing
Content_type
X-Speed-Cache
X-Transaction
Cache-Tags
X-Content-Type-Option
From-Origin
X-GeoIP-Country-Name
X-Cookie-Domain
X-Purge-URL
Backend-Timing
Custom-Header
NetMindSessionID
X-Content-Age
X-Analytics
X-Orig-Vary
X-Rq
Local-Info
Nginx-Cache
X-Sys-Req-ID
X-Dynatrace-Js-Agent
X-Varnish-Server
X-Worker
Proxy-Agent
X-CacheDebug
X-Srv
WWW-Authenticate
X-Sucuri-Cache
X-ARRServer
W
X-WR-Flags
Strikingly-Cached-Version
X-CB-Server
Strikingly-Cached
X-GoCache-CacheStatus
Strikingly-Cache-Region
X-Cache-Control
X-BKSrc
X-Proxy
X-Nitro-Cache
X-Unique-ID
CacheControlHeader
Content-MD5
Swift-Performance
X-LP
X-Webstats-RespID
X-Runtime-Memory
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Purge-Host
X-Varnish-ID
X-Role
X-Fedora-School-Id
X-SE-Debug
Service-Worker-Allowed
Cached
X-Location
X-VC-Enabled
Content-Transfer-Encoding
Web-App-Origin-Name
Ram
Frame-Options
Adm-Server
Noq
S
Ramp
X-LW-Web-Server
X-ID
X-Shield-Request-Id
X-Adobe-Content
X-Adobe-Loc
X-ClientSide-Caching
X-Framework
X-Litespeed-Cache-Control
X-Beget-Proxy
Accept-Charset
X-JG-Page-Cache
X-Cache-CFC
X-BackendServer
X-TTL
X-NginX-Cache
X-WP
X-RiS-UFDI
X-Xrds-Location
Max-Age
X-Resty-Request-Id
X-AF-Userserver
X-NginX-Server
X-AEM
X-Amz-Rid
X-VNode
X-Provisioner-Version
Front
X-Disney-Akamai-Rule
X-Domain-Checked
SVR
Cm-Server
X-Culture
X-Key
X-HydroSheep
HAVer
Server-Info
HCVer
FindLaw
X-Stage
X-Pool
X-Amz-Storage-Class
X-GeoIP
X-FireWall-Port
X-Now-Id
X-Application
X-Balanceador
X-SERVER-NAME
SRV
X-TB-M
X-Detected-Device
X-CAPServer
X-Origin-Id
X-Amzn-Trace-Id
X-Processed-By
EN-User
X-Webcelerate
Pf.Web.Request.Id
Hummingbird-Cache
RequestId
X-Smartcache-Timeout
X-Smartcache-Keys
X-Cache-Miss-From
X-Yadis-Location
Lb
X-Vip
X-Content-Security-Policy-Report-Only
X-Session-ID
X-FIRSTBase
X-Generated-Time
X-Goog-Meta-Goog-Reserved-File-Mtime
Copyright
X-Sedo-Request-Id
X-Storage-Cache
X-Amz-Apigw-Id
X-App-Runtime
X-SH-Cache-Status
X-Plat
Device
Access-Control-Allow-Method
X-Goog-Meta-Policy
X-Goog-Meta-Replace
X-Amzn-RequestId
X-Runtime-Affili
X-OpenCart-Lightning
Dispatcher
X-RealServer
X-HostName
X-App
Eomportal-Instance
X-Storage-Cache-Expires
X-Storage-Cache-Date
X-Backend-Status
XDomainRequestAllowed
Upgrade-Insecure-Requests
X-IIJ-Cache
CLMOB
Play-Detected-Device
X-ServerIndex
F5-Trid-Name
X-Akamai-Edgescape
X-Info
X-App-Server
X-Jphone-Copyright
X-Amz-Meta-Content-Md5
X-Rack-Cors
Access-Control-Request-Headers
RN-Server
X-A
Referer
X-WPL-DATA
F5-Trid-Value
Play-Detected-UserAgent
X-HA-Backend
X-HA-Frontend
X-Hit-Cache
Proxy-Cache
X-Aramark-SID
Il-Cl
Home
X-Varnish-Hostname
COMMERCE-SERVER-SOFTWARE
X-B2f-Not-Route
X-DSMX-Render-MS
X-Varnish-Cache-Local
Traffic-Origin
X-Test
X-Pagename
X-DSMX-Rewrite-MS
X-Frames-Options
X-ESI
AETN-DEVICE
N365rili
Ibf5scheme
NtCoent-Length
X-Cache-On
X-CRA-DC
Access-Control-Allow-Header
X-Server-IP
VServer
AMP-Redirect-To
X-Desc
X-Forwarded-Host
X-MidCOM-Meta-Cache
X-Response
X-Varnish-Action
X-SAPP
Ufe-Result
X-Debug-Token
X-VCS-Ttl
X-VCS-Cacheable
EagleEye-TraceId
BALANCEDTO
X-Now-Cache
Filters
X-Agent
X-Captured
Arrnode
X-MAT-GEO
Paypal-Debug-Id
X-Ghost-Cache-Status
X-Confluence-Request-Time
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Amz-Id-1
X-DynamicCache
X-HashTwo
X-Data-Request
X-Oferteo-Domain
X-VC-TTL
X-Cache-Detail
AETN-Area-Code
AETN-City
AKA-DEVICE
AETN-State-Code
Cteonnt-Length
X-GSL-Server
SHInfo
AETN-Postal-Code
AETN-Longitude
AETN-Country-Code
AETN-Continent-Code
AETN-Country-Name
AETN-EU
AETN-Latitude
Num
X-Real-IP
X-SP-Farm
X-CACHE-TTL
X-Garden-Version
X-SP-UniqueName
Pics-Label
BackendServer
ScoreTracker
AsisCache
Beyond-Iis
X-Webkit-CSP
NODE
WN
X-AVG-Country-Code
X-Avg-Cookie-Expires
X-WN-ClientGroup
A-Powered-By
Id
X-Akamai-Transformed
X-Span
X-Redman-Backend
X-Dev
X-Reflector
Disablevcache
X-Cache-2
X-HS-Status
X-Redman-Final-Url
X-Reflector-Cache
Url
X-SDE-Name
X-Compress-Hint
X-Proxy-Skip
X-Timestamp
X-Origin-Cache
Accept-Language
X-Cms-Mode
Worker
X-Dw-Trace-Id
X-ENV
From
X-Cache-Doesi
X-Hosting-Env
X-ASAP-Cache
X-Remote-Addr
X-Varnish-Debug-Age
Web
MageStack-Tag
PServer
X-Clara-ASAP
X-Page
X-Server-Addr
X-FastCGI-Cache-Status
MageStack-Web-Node
X-Amz-Meta-Cb-Modifiedtime
MageStack-PageSpeed
Cleartype
TC-Cache
X-Hosting
TC-Cache-IC
MS-CV
Server-Ip
CS-SERVER
XX
X-Varnish-Debug-TTL
Prama
X-Hstore
X-JSESSIONID
Request-Country
X-Upgrade-Enabled
Request-EU
WP-FROM-CACHE
X-Path-Route
X-Middleton-PageSpeed
Firespring-Website-Id
X-Bip
X-DataDome
X-HTML-Minification-Powered-By
X-Fstrz
X-Amcomm-Site
Fastly-Debug-Digest
X-Hrouter
X-Cache-Varnish
X-Req-Head-Response
X-MCB-Server
X-Map-Context
X-V
Edgecast
X-Refresh
X-Appmachine-Environment
X-Served-Server
Thanks
X-Source-ID
X-Cache-Ttl
AR-ATIME
MageStack-Cache-Lifetime
MageStack-Cache-Hits
MageStack-Cache
X-Mobilized-By
X-PRAM
ServerSignature
AR-CACHE
TC-Cache-U
X-Varnish-Id
MageStack-Area
X-Svr
X-RemovedCookies
X-Rebelmouse-Cache-Control
X-E
X-ProcessESI
X-Distributor
X-4ormat-Cacheable
X-Box
Environment
X-Dscp-Value
X-Depends
ServerTokens
MageStack-Cache-Status
X-Atraveo-Cache-Control
MageStack-Magento-Version
X-Atraveo-Param-Rm
X-Atraveo-Set-Cookie
X-Atraveo-From-Varnish-Cache
AR-SID
X-Atraveo-Expires
MageStack-Loadbalancer
TC-S-Cache-M
X-Atraveo-ETag
X-Rack-CORS
TC-S-Cache
MageStack-Cacheable
X-Rule
X-Force
AR-PoweredBy
MageStack-Config
X-Atraveo-Zone
MageStack-Debug
X-Atraveo-TTL
X-Atraveo-Varnish-Server-Id
X-LBPoolMember
X-RAMCache
X-DB-Content-Length
X-Varnish-URL
Pramga
CommunityServer
MageStack-Cache-Warning
X-Middleton-Pagespeed
X-CACHE-KEY
X-Lw-Cache
X-Proto
X-Ratelimit-Limit
X-Cocoon-Version
SS
X-Cdn-Forward
X-Appid
Magicmarker
X-Consent-Required
X-HeBS-Cache-Status
Load-Balancer
X-Ratelimit-Remaining
IES-Server
X-Request-Uri
X-Nginx-Host
X-Generated-Timestamp
WP-AdvCache-MemCached
Fastly-Backend-Name
X-Proxy-Backend
Server-Id
Cache-Status
X-SilverStripe-Cache
X-Distributed-By
X-DDM-SERVER-UPDATED
X-Cache-Dispatcherpragma
X-Enabled2
X-Log
X-Qiniu-Zone
X-Reqid
X-Ser
X-PHP-Response-Code
X-Unique-Id
X-Autoru-Host
DNNOutputCache
Myheader
X-Cache-Dispatchercachecontrol
SBSS
Content
Identity
X-DDM-SERVER
X-WR-Trace
X-AutoRu-App-Id
Report-To
X-Enabled1
X-Enabled3
X-Via-NSCOPI
X-SmartBan-URL
X-Cacheable-TTL
X-Scheme
X-Adnet
Pragrma
X-Actindo-Rs
X-Actindo-Thread-Id
X-Origin-Server
X-Node-App
PB-PID
X-PBY
X-FPC
PB-RID
X-ETag
X-Cache-TTL-Age
X-Cache-TTL-Current
X-Status
X-VERSION
Machine
Resin-Trace
X-Mobile-Rewrite
VANITY-HOST
X-Actindo-Request-Id
X-Domino-CacheValidationWithETagReason
X-Domino-CacheValidationWithETagResult
X-Gannett-Site-Version
X-Resolver-IP
X-Secret
AMP-Access-Control-Allow-Source-Origin
X-XHR-Current-Location
X-B3-Sampled
SERVER-ID
X-MrHost
Aurora-Node
X-Batcache
Cmsid
Cmstype
X-Session-Reinit
AC-ELC
X-SuperCache
X-UA-Bot
Xc
X-Batcache-Reason
X-Built-With
X-SmartBan-Host
X-ServiceProvider
X-Cache-Extended
X-Streams-Distribution
Apachenode
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-EC2-Instance-Id
IISExport
X-HAProxy
X-Highwire-RequestId
X-Highwire-SessionId
X-Proxy-Id
X-Cache-FS-Status
MageStack-Cache-Lifetime-Sent
Access-Control
MageStack-Last-Modified
X-Accel-Cache-Control
X-Cache-Action
Amfplus-Ver
*
X-Debug-Message
X-Az
X-HA
X-UA
StatusCode
X-CacheLoc
X-CH-Device
X-Title
X-SSLTerm-Server
X-Flex-Tag
X-ZORequestID
Yola-ID
X-Flex-Tags
X-AOL-HN
X-Block-RuleID
X-Czt
X-Block-Rule
X-Layout
X-ASAP-Age
X-Amz-Meta-Version-Id
X-Gyrobase-Publication
X-DN-Cache-Control
X-Via-S
X-Route
X-Soro
X-Custom-Header
X-Beatles
Actioncode
Hosted-By
Realaction
Ttl
X-TLS-Version
ID
X-Proxy-Cache-Control
X-Tag-Playlist
Request-Filtered-By
Viewport
X-Activity-Id
X-M
Og
X-Cache-Time
X-OPNET-Transaction-Trace
Description
Keywords
Backend-IP-Port
X-Build-Id
X-DevSrv-CMS
FRONT-END-SECUREBROWSER
D
Accept-CH
Hamster
X-Upstream-Addr
X-PBS-Appsvrip
X-PBS-Appsvrname
X-PBS-Fwsrvname
HitInfo
X-WebNode
X-7d-Instance-Id
TP-Cache
TP-L2-Cache
Backend-Name
X-Custom-Name
Powered-By-115
X-Abuse
Yoncu-Errno
X-Olaf
X-KoobooCMS-Version
X-Container
X-Flex-Community
X-Nginx-Request-Time
Tempo
X-Flex-Lang
X-MyName
Session-Id
X-Flex-Lastmod
CDN-Cache
Dis-Env
Provided-Host
X-Instart-Cache-Id
X-7d-Trace-Id
Server-ID
X-Flex-Evstart
X-Instance-Id
HitType
X-Flex-Evend
SINA-LB
X-CacheID
SINA-TS
X-APIVERSION
X-APIAUTH-VAL
NLCacheNote
Now
X-ENDPOINT
X-FromPodPressCache
ServerNode
X-IP
PBS
X-Resource
X-WEBMGR-CACHE
X-Bcwwwid
NZSpeedy
X-Shard
X-Appversion
VC-NoCache
X-FORWARDED-PROTO
X-Pj-Cache-Status
X-ROUTING
X-Varnish-Debug-Hits
X-Varnish-Ip
X-Now-Trace
X-Now-Instance
X-ORIKEY
Bios
X-Server-Ip
X-M-Reqid
X-CloudBurst-Frontend
X-Qnm-Cache
X-CloudBurst-WordPress
X-M-Log
X-InDy-Time
X-CloudBurst-Cache
X-CloudBurst-Backend
X-We-Are-Hiring
X-NWS-UUID-VERIFY
X-From-Cache
X-Pagely-Cache
X-Server-Response-Time
X-Global-Transaction-ID
Prot
X-Gateway-Rate-Limit-Delayed
X-Appmachine-CreatedOn
Sl-Pgid
REFRESH
X-Appmachine-Duration
X-SiteDistrict-Cache
X-InDy-Memory
X-W3TC-Minify
X-SV
X-Backside-Transport
X-Grid-Server
X-Appmachine-Name
X-Vary-Options
X-Firefox-Spdy
LB
X-WebKit-CSP-Report-Only
X-InDy-Query
MSThemeCompatible
X-Skip-Cache
X-Origin-Upstream-Status
X-Geo-IP
X-Trans-Id
Requested-Host
X-MSU-SOURCE
X-GEO
X-Clx-Request
X-Compressed-By
Lookup-Cache-Hit
X-MainProfileID
X-MainProfileCategory
X-Len
X-MainProfileName
X-MainProfileURL
X-NewsFlow-Sitename
X-Ms-Request-Id
X-Newrelic-Synthetics
X-SID
X-VC-Debug
MSSmartTagsPreventParsing
Httpd-Identifier
X-Instance-Name
X-Meta-Imagetoolbar
X-Meta-MSThemeCompatible
X-Meta-MSSmartTagsPreventParsing
X-Origin-Date
X-Envoy-Upstream-Service-Time
End-User-Country
Backend-Powered-By
X-VG-WebCache
Progma
X-D-Time
X-S-Misc
X-Generation-Time
X-HP-CAM-COLOR
X-Avvio-Cms-Cacheload
X-HEAD
X-From-Varnish-Deploy
X-From-Varnish
X-RunCloud-Cache
X-SSL
X-Cname-TryFiles
X-Cache-LB
GranicusServer
X-CSRF-Token
X-Cache-ID
Ews
Content-Generator
X-Wodby-Node
NGX
Plateforme
X-Boot
RSB-LINK
X-Deity
X-Processed
X-Front-Cache
X-Content-Type
X-BeResp-Ttl
X-Stiffia-Cache
X-Tradeindia-Request-GUID
Nitro-Cache
X-Tradeindia-SMgmt
X-Amzn-Remapped-Content-Length
RSL-Trace-ID
X-This-Proto
X-Served
X-SCProxy
X-Web-Node
Prototype-RootPath
X-ProBase-Server
X-Cache-Me-Harder
X-Varnish-Cache-Control
X-S-V
X-Server-Hostname
X-AppServer-Cache-Rule
Webserver
Content-Sn
DB-Nickname
Request-Time
ModuleCacheType
UrlWatchModule-Time
Nd
X-Geo
X-Dynamic
X-Lb
X-Sid
DbServerName
X-VTEX-Cache-Status-Janus-Edge
X-B3-Spanid
X-B3-Traceid
CDN-RequestId
CDN-PullZone
CDN-Uid
CommercePlatform-Version
OracleCommerceCloud-Sandiego
Ctx
CDN-CachedAt
X-Varnish-Cached-TTL
X-MCF-ID
X-Fpc
X-Ruby-Cluster-ID
X-Sn-Servicetimems
X-Varnish-Cached
X-UPServer
X-Brought-To-You-By
X-Backend-Host
X-Cachable
Key
X-V-Cache
X-CPU-Time
X-Header
X-M-P
X-I-V
X-UT-Cache
X-AppVersion
X-Shopware-Allow-Nocache
X-NoIndex
X-Shopware-Cache-Id
X-Powered-By-Home.Pl
Tesla.Performance
Generate-Time
X-M-T
X-M-V
X-UPSTREAM-Address
X-Netrix-ID
HSTS
VAR-Cache
RM-Cache-Control
X-Sorting-Hat-Expire-Cache
X-Machine
X-Catalyst
X-Q-S
X-Mw-Workerstats
X-S-C
X-Transaction-Name
ProxiaInstanceId
NS-VaryByCustom-Key
OracleCommerceCloud-Version
X-AISO-Cache
ORIGIN-SITE
ORIGIN-SERVER
Cf-Ipcountry
V-TTL
ViewMode
Www.Aujourdhui.Com
VSID
Arrow-RequestId
X-XHTML-Minification-Powered-By
X-Node-Id
X-ManagedFusion-Rewriter-Version
X-Render-Time
X-Rewritten-By
X-Varnish-Grace
X-Test-Debug
X-ACCELERATE
X-Blog
X-Pass-Through
X-NodeID
X-PM-ID
X-PressLabs-Stats
X-Src-Webcache
X-Search-Id
X-Nginx
X-Max-Age
X-Cjtype
X-CD
X-Csrf-Token
X-Device-Item
X-Gate-Blk
X-Gate
X-EPiphany-Vid
X-Client-Vid
X-Cache-Warmer
Session-From
ServerIP
X-Distil-CS
MachineName
X-ReqId
MwpReleaseVersion
Expiries
DrivedBy
X-AISO-Server
X-AISO-Cacheable
X-Hit
X-Nginx-Page-Cache
Debug-Status
X-Protected-By
X-Serv
Provider
X-Zendesk-Origin-Server
X-WA-Info
X-Zendesk-User-Id
CDCHOST
X-Client-Image-Vid
X-Built-By
X-UnsetCookies
X-RequesterIP
X-Directory-Script
X-Cache-Via
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-Proxy-Cache-Key
X-Nginx-Request-Processing-Time
X-Time-Microsecs