Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Last-Modified
Pragma
Link
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Strict-Transport-Security
X-Cache
CF-RAY
P3P
X-AspNet-Version
Age
X-Pingback
Content-Language
Via
X-UA-Compatible
Expect-CT
Access-Control-Allow-Origin
Upgrade
X-Adblock-Key
X-Xss-Protection
Content-Security-Policy
X-Cacheable
X-Varnish
X-Check
X-Language
X-Template
X-Generator
Alt-Svc
X-Buckets
X-Request-Id
X-Drupal-Cache
X-Type
WPE-Backend
X-Cache-Group
X-Pass-Why
X-AspNetMvc-Version
X-Hacker
X-Ac
X-Cache-Hits
X-Permitted-Cross-Domain-Policies
X-Powered-By-Plesk
X-Download-Options
Content-Location
Host-Header
X-Runtime
X-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-Dc
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
MS-Author-Via
X-FRAME-OPTIONS
Cartoon
X-UA-Device
X-Powered-CMS
X-IPLB-Instance
X-Served-By
Access-Control-Allow-Headers
Status
Access-Control-Allow-Credentials
X-Amz-Cf-Id
Access-Control-Allow-Methods
P3p
X-Cache-Status
X-Via
X-Iinfo
X-Timer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
CF-Cache-Status
X-Contextid
X-Backend
Referrer-Policy
Powered-By
X-PC-Key
X-PC-Hit
X-ServedBy
X-Mod-Pagespeed
X-DIS-Request-ID
X-PC-AppVer
X-PC-Host
X-PC-Date
Content-Encoding
X-WPE-Loopback-Upstream-Addr
X-CST
X-Logged-In
X-Request-ID
Keep-Alive
X-Rid
X-Host
X-Cache-Hit
X-Server
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Port
X-CDN
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Server-Powered-By
X-Robots-Tag
X-Endurance-Cache-Level
X-Nginx-Cache-Status
X-Tumblr-Pixel-2
X-Wix-Request-Id
X-Seen-By
X-Wix-Server-Artifact-Id
X-Accel-Version
X-Turbo-Charged-By
X-Original-Date
X-Page-Speed
X-Drupal-Dynamic-Cache
X-Pad
X-Content-Powered-By
Content-Security-Policy-Report-Only
X-Content-Digest
WP-Super-Cache
X-Proxy-Cache
X-Rack-Cache
X-AH-Environment
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Tumblr-Pixel-3
X-Varnish-Cache
X-LiteSpeed-Cache
X-GitHub-Request-Id
X-Ua-Compatible
X-Request-Country
SPRequestGuid
X-SharePointHealthScore
Edge-Control
X-XRDS-Location
X-MS-InvokeApp
X-Cnection
MicrosoftSharePointTeamServices
X-Cache-Lookup
Timing-Allow-Origin
X-Died
Cf-Railgun
X-Amz-Request-Id
X-Amz-Id-2
X-FW-Hash
X-Node
X-Trace
Charset
X-FW-Static
X-FW-Type
X-FW-Serve
Request-Id
Edge-Cache-Tag
X-Webserver
X-FullPageCaching
X-Content-Security-Policy
X-HS-Cache-Config
X-Webcom-Cache-Status
X-HS-Content-Id
X-PhApp
MicrosoftOfficeWebServer
X-Hits
X-Safe-Firewall
SPIisLatency
X-CF-Powered-By
Request-Context
SPRequestDuration
Access-Control-Max-Age
X-Newrelic-App-Data
X-INKT-SITE
X-INKT-URI
X-BC-Stapler
X-PHP-Backend
Composed-By
Access-Control-Expose-Headers
Grace
X-Swift-CacheTime
X-Swift-SaveTime
X-SERVER
EagleId
Served-By
X-CDN-Pop
X-Tumblr-Pixel-4
X-CDN-Pop-IP
Liferay-Portal
X-Spip-Cache
X-Hyper-Cache
X-Backend-Server
X-Device
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-LiteSpeed-Cache-Control
X-Microcache
X-Server-Name
X-VCache
Rating
X-RateLimit-Remaining
X-ServerName
X-FB-Debug
X-RateLimit-Limit
X-Cloud-Trace-Context
X-Clacks-Overhead
Content-Style-Type
X-RateLimit-Reset
X-Wix-Renderer-Server
Content-Script-Type
X-Jimdo-Instance
X-Jimdo-Wid
Surrogate-Control
X-DDC-Arch-Trace
X-Firenze-Processing-Times
X-User-Agent
X-TNCMS
Real-Hostname
X-Loop
Front-End-Https
X-Acc-Exp
Public-Key-Pins
Refresh
X-Cache-Config
X-Tumblr-Content-Rating
X-XN-XNHTML
X-XN-Trace-Token
X-Age
Fpc-Cache-Id
X-Middleton-Response
X-Middleton-Display
Display
X-DNS-Prefetch-Control
X-Sol
Response
X-StackifyID
X-Hostname
X-HS-Combine-CSS
Xkey
X-SS-Location
X-SS-Conf
X-Vtex-Processado-Em
X-Microcachable
X-Cached
X-Generated-By
X-Tumblr-Pixel-5
X-Zen-Fury
X-Cdn
X-Px
X-N-OperationId
X-OneAgent-JS-Injection
PageSpeed
X-Topify-Platform
X-MiniProfiler-Ids
X-Correlation-Id
X-Servedby
X-Request-Time
X-Cached-By
X-Frame-Option
TCN
X-Kinsta-Cache
X-Url
X-WebKit-CSP
X-Amz-Version-Id
X-Whom
P-WS
X-CMS-Version
X-Handled-By
X-Ruxit-JS-Agent
P-LB
Rt-Fastcgi-Cache
X-Outils-CS
X-Varnish-TTL
X-URL
X-DynaTrace-JS-Agent
X-Magento-Tags
Product
X-Content-Options
X-VARNISH-Cache
Imagetoolbar
X-B-Cache
X-Via-JSL
Surrogate-Key
X-AspNetWebPages-Version
Powered
X-CacheServer
Edge-Control-Message
Access-Control-Request-Method
Host
X-Engine
X-SRCache-Fetch-Status
X-DynaTrace
X-SRCache-Store-Status
X-Track
Fastly-Debug-Digest
X-Vtex-Remote-Cache
X-Varnish-Cache-Hits
X-Vtex-Processed-At
X-Powered-By-VTEX-Janus-ApiCache
X-VTEX-Janus-Router-Backend-App
X-Debug-Info
X-VTEX-Cache-Status-Janus-ApiCache
No
X-Forwarded-For
ServedBy
X-Edge-Location
Fhost
X-HOST
X-Recruiting
X-Cache-Rule
Alternate-Protocol
X-FORWARDED-FOR
X-Umbraco-Version
X-Powered-By-VTEX-Janus-Edge
X-ApacheServer
X-PERF
X-LBLID
Public-Key-Pins-Report-Only
X-Goog-Hash
X-Msg-2-Log
X-NWS-LOG-UUID
X-Application-Context
X-Actual-URL
X-Returned-From-DLL
X-Original-Request
X-Returned-From
X-Passed-To-DLL
X-Passed-To
X-Returned-From-BeforeDispatch
Generator
X-Returned-From-PostProcessResponse
X-Signature
X-Passed-To-BeforeDispatch
X-From
X-Platform
X-Passed-To-PostProcessResponse
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
WZWS-RAY
X-Powered-By-360WZB
X-Accel-Expires
X-Stale
X-Location-Id
DynaTrace
X-Cache-Age
Dmn
X-Upstream
X-Response-Time
X-Hosted-By
X-Developer
X-Platform-Processor
X-Micro-Cache
X-Platform-Router
X-Tumblr-Pixel-6
Arr-Disable-Session-Affinity
Fastcgi-Cache
X-RESOURCE
X-LB
Akamai-IP
HTTPS
X-Platform-Cluster
X-UD-Method
X-Supported-By
X-Source
X-LW-Cache
X-Pantheon-Phpreq
Surrogate-Key-Raw
X-Pantheon-Environment
X-Varnish-Host
X-Pantheon-Site
X-URLSCHEME
X-Version
X-I-Sp
X-BS
X-Cache-Info
X-Rocket-Nginx-Bypass
Content-Hash
X-Device-Type
X-TransIP-Balancer
X-Varnish-HitMiss
X-Varnish-Count
X-Fastcgi-Cache
Retry-After
Cache-Provider
Origin
X-Rnd
X-Defender
X-Shop-Id
X-NetCat-Version
X-Cache-TTL
X-Instart-Request-ID
X-Magento-Cache-Debug
X-ATG-Version
X-Storage
X-EdgeConnect-Origin-MEX-Latency
X-Cache-Key
X-S
X-Powered-By-VelaWeb
X-F-Cache
X-HS-Content-Campaign-Id
X-Page-Cache
X-CSRF-Protection
X-App-Hosting
X-AOL-HN
USPLoggingUUID
Version
X-Art-Request-Id
Last-Published
X-TransIP-Backend
X-Matrix-Proxy
X-Dispatcher
X-Matrix-Server
X-Cache-Tags
X-EdgeConnect-MidMile-RTT
X-Translation
X-Microcache-Status
IBM-Web2-Location
X-Front
X-Daa-Tunnel
X-Gamma-Serve
Ohc-File-Size
Allow
X-Varnish-GracePeriod
X-Revision
X-Varnish-Seen-By
X-Varnish-ObjectSource
X-Varnish-RemainingLife
X-Varnish-RemainingTTL
X-Environment
X-Drupal-Cache-Tags
X-LB-Node
X-I
X-Server-ID
X-Expires-Orig
X-Vcap-Request-Id
Powered-By-ChinaCache
X-Hypernode
RTSS
X-Server-Upstream
X-ARC
X-Ua-Device
MIME-Version
Pool
X-Cache-Operation
Content-MD5
X-Dispatch
Pagespeed
X-Director
X-Platform-Server
Content-Disposition
X-Platform-Cache
X-Route-Server
X-SSL-Cipher
X-Content-Encoded-By
X-Flow-Powered
Cache-Key
X-SSL-Protocol
X-Loopia-Node
X-Cache-Only-Varnish
X-Lambda-Id
X-Cache-Debug
Page-Completion-Status
X-SV-Duration
X-SV-CreatedAt
X-SV-CacheTags
SSPAppContext
X-SV-Cacheable
X-SV-Edge
X-SV-FromDBCache
X-SV-Nginx-Duration
X-SV-Expires
X-Url-Base
X-SV-Pid
Node
X-Abgroup
Wsr-Cache
X-Varnish-Age
X-Drupal-Cache-Contexts
X-UPSTREAM
X-Cache-Lifetime
X-Varnish-Cacheable
X-ORACLE-DMS-ECID
X-NoCache
X-Github-Request-Id
Lsrequestid
Accept-Encoding
X-Edge-IP
X-Grace
X-Hiawatha-Cache
X-IsCacheURL
X-Cache-Server
Section-Io-Id
X-Debug
X-Ttl
X-Generated
X-Id
Pv
Proxy-Connection
X-Cache-Control-Orig
X-Nbs
X-CJ-Soft
X-SRCache-Key
X-Sapient
ServerID
X-Firenze-Processing-Time
X-Vhost
X-Proxy
X-Sentry-ID
X-Cache-Expires
X-Cache-Engine
X-GeoIP-Country-Code
X-RequestId
Content-Encoding-Handler
Srv
X-PwB-Node
Fw-Via
X-VTEX-Cache-Status-Janus-Edge
X-Ezoic-Cdn
X-Cache-Type
S-Cnection
X-ACMCache
Location
X-N
Cneonction
X-Client-IP
X-Server-Id
X-Dns-Prefetch-Control
ServerName
X-Litespeed-Cache
Backend
X-Amz-Meta-S3cmd-Attrs
X-SERVER-NAME
X-Duration
X-Browser
SN
X-Magento-Cache-Control
Author
Server-Name
X-TTL
X-Processing-Time
FAI-W-FLOW
X-Geo-Country
X-Cache-Control
X-Discourse-Route
X-Varnish-Url
X-Nginx-Cache
X-Middleware-Start
X-Speed-Cache
X-NB-Cached-Page
X-Speed-Cache-Key
X-Country-Code
X-Location
Server-Info
X-ServerID
SRV
Req-Id
If-Modified-Since
IM-Version
X-Dynatrace-Js-Agent
X-Orig-Vary
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Cookie-Domain
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Metageneration
X-Yadis-Location
X-Content-Age
X-Cache-CFC
X-GeoIP-Country-Name
AMF-Ver
X-Akamai-Device-Model
X-Sucuri-ID
X-Always-Cache
X-Akamai-Device-Characteristics
Nodo
PICS-Label
Use-Proxy
X-Magnolia-Registration
X-Time
X-Cache-Level
X-FW
X-Varnish-Backend
NnCoection
X-Worker
X-Real-Server
Cached
X-Pressidium-NinukisWP-Ver
X-Framework
X-Cache-Namespace
Cm-Server
X-Akamai-Transformed
HAVer
HCVer
X-Cache-Device-Type
X-Cache-PageType
X-Correlation-ID
X-Cache-Fix
X-DealerOn
X-App-Server
X-Sucuri-Cache
X-Drectory-Script
X-Shield-Request-Id
X-BackendServer
X-Webkit-CSP
Accept-Charset
X-LB-Server
Qs-Cache
X-Cluster-Node
X-BKSrc
SVR
X-Processed-By
X-SO
X-CF-Passed-Proto
S
X-High-Performance
X-Frontend
X-Varnish-Retries
X-Abuse
X-Forwarded-Proto
X-Ss-Conf
Pf.Web.Request.Id
Xc-Version
X-Srv
Cache
NetMindSessionID
X-Adobe-Content
X-Ss-Location
X-Purge-URL
X-Adobe-Loc
Thanks
X-Origin
Local-Info
MC
X-Server-IP
X-Runtime-Rack
Pics-Label
X-Config-Blacklist-Version
X-Session-ID
X-Amz-Storage-Class
X-CDN-Forward
X-JG-Page-Cache
X-Varnish-IP
X-DataDome
X-Purge-Host
Server-Timing
X-Last-Modified
X-Traffic
Magicmarker
X-Route-To
X-SRV
Tracecode
X-Disney-Akamai-Rule
A-Powered-By
SiteSpeed
SEOMOZ
X-Fastly-Request-Id
X-Sys-Req-ID
HitType
MJ12bot
Nitro-Cache
X-Litespeed-Cache-Control
X-Balanceador
X-PF-Uncompressing
X-Rocket-Nginx-Serving-Static
SBGI-Device
X-FastCGI-Cache
SBGI-RealPath
X-WR-Flags
X-LP
SBGI-9
X-Content-Type-Option
SBGI-5
SBGI-1
W
SBGI-10
X-NginX-Cache
SBGI-7
X-Cf-Powered-By
Content_type
X-Empowered-By
X-ClientSide-Caching
SBGI-RenderTime
X-Pagename
EagleEye-TraceId
X-HTML-Minification-Powered-By
Eomportal-Instance
From-Origin
X-VARITI-CCR
WN
X-SDS
X-Provisioner-Version
X-Sorting-Hat-Expire-Cache
X-Hit-Cache
X-RiS-UFDI
X-AF-Userserver
X-App-Status
P-ID
X-Content-Security-Policy-Report-Only
Keywords
X-Cache-Handler
X-Domain-Checked
X-WN-ClientGroup
Frame-Options
WWW-Authenticate
X-FTR-Request-ID
X-Cache-TTL-Remaining
X-Twitter-Response-Tags
Cache-Tag
X-FireWall-Port
CacheControlHeader
X-Mobilized-By
Content-Transfer-Encoding
X-Connection-Hash
AC-ELC
X-Transaction
X-Yottaa-Metrics
X-Runtime-Memory
X-Jphone-Copyright
X-Varnish-ID
X-Yottaa-Optimizations
X-OpenCart-Lightning
X-HW
Ufe-Result
X-Redman-Backend
X-AVG-Country-Code
X-Rq
ServerTokens
ServerSignature
X-AEM
X-ORACLE-DMS-RID
Web-App-Origin-Name
X-Varnish-Hits
X-Avg-Cookie-Expires
X-Redman-Final-Url
X-Amz-Meta-Cb-Modifiedtime
Max-Age
X-Akamai-Edgescape
X-Directory-Script
X-EPiphany-Vid
VANITY-HOST
X-Varnish-Debug-Age
X-Cache-Doesi
Cache-Tags
X-ID
X-Client-Vid
Adm-Server
X-Varnish-Debug-TTL
X-ASAP-Cache
X-Clara-ASAP
X-Client-Image-Vid
X-VNode
Description
SERVER-ID
X-Unbounce-Variant
X-Unique-ID
NODE
Contao-Page-Layout
X-Unbounce-PageId
X-Analytics
X-Unbounce-VisitorID
X-Resty-Request-Id
X-Fedora-School-Id
X-Esi
Proxy-Agent
X-Varnish-Ttl
X-Generated-Time
X-LW-Web-Server
Backend-Timing
X-Server-Instance
X-Webstats-RespID
X-Garden-Version
X-WPL-DATA
X-ARRServer
X-Key
X-Force
X-Wikidot-Backend
X-HP-Trace-ID
X-Atraveo-Zone
X-Atraveo-Set-Cookie
X-Atraveo-TTL
X-Atraveo-Varnish-Server-Id
X-HP-Trace-Project
X-ServerIndex
Play-Detected-Device
X-PRAM
X-Hrouter
Play-Detected-UserAgent
X-Atraveo-Param-Rm
X-MCB-Server
Paypal-Debug-Id
X-Hstore
X-Mobile-URL
Front
X-Varnish-Hostname
X-Atraveo-From-Varnish-Cache
X-Cache-Keep
X-CacheResult
X-MAT-GEO
X-CB-Server
Dispatcher
X-Debug-Token
X-Page
X-CAPServer
Noq
Ram
X-GoCache-CacheStatus
Ramp
X-Webkit-Csp
X-GeoIP
X-Source-ID
Hname
X-HOSTNAME
X-Remote-Addr
X-Desc
X-Atraveo-Cache-Control
BALANCEDTO
X-Atraveo-Expires
X-Wikidot-Static-Cache
X-Atraveo-ETag
X-CACHE-TTL
X-Dev
X-Backend-Status
Worker
X-Nginx-Host
NLCacheNote
Cmstype
X-App-Runtime
X-Runtime-Affili
Beyond-Iis
Machine
Cmsid
X-SH-Cache-Status
X-Culture
X-Cms-Mode
Dis-Env
X-TTFB-L
X-Trace-Id
X-Frames-Options
X-Varnish-Server
X-Real-IP
X-Resolver-IP
X-TTFB
X-SmugMug-Values
X-Symfony-Cache
TC-S-Cache-M
Cteonnt-Length
X-App
Og
Resin-Trace
X-Distributor
X-Compressed-By
X-WebKit-CSP-Report-Only
Disablevcache
SHInfo
X-NginX-Server
X-Plat
TC-S-Cache
COMMERCE-SERVER-SOFTWARE
X-Env
X-GSL-Server
TC-Cache-U
Smug-CDN
TC-Cache
TC-Cache-IC
X-SmugMug-Hiring
X-Smartcache-Timeout
From
Access-Control-Allow-Header
X-HydroSheep
X-WP
X-Detected-Device
X-Smartcache-Keys
XDomainRequestAllowed
Strikingly-Cached-Version
X-Cache-Node
Nginx-Cache
Strikingly-Cache-Region
Strikingly-Cached
X-Autoru-LB
Web
X-Autoru-Host
X-AutoRu-App-Id
X-Stage
AMP-Access-Control-Allow-Source-Origin
X-KoobooCMS-Version
Device
X-Proto
X-Avvio-Cms-Cacheload
Custom-Header
X-V
X-Dynamic-Cache
X-Varnish-Ip
Lb
X-A
X-Fstrz
Bios
X-VC-Enabled
MW-Webserver
X-IIJ-Cache
MS-CV
Fastly-Backend-Name
X-Airee-Node
Id
X-VC-TTL
Arrnode
X-Server-Generated
ClientIP
X-WR-MODIFICATION
X-Session-Reinit
Yoncu-Errno
X-Refresh
Hostname
X-Forwarded-Host
X-ENV
X-CDN-COMPRESS
Content-Server
X-Machine-Name
Gzip
F5-IpCliente
X-EC2-Instance-Id
X-Batcache
X-E
X-Batcache-Reason
X-ETag
X-SDE-Name
X-Render-Time
X-RDP
X-Reflector-Cache
X-Captured
X-Cache-On
Ibf5scheme
Hamster
Identity
X-Viator-Tapersistentcookie
N365rili
X-Hosting-Env
X-Bip
X-CDN-RULE
X-Origin-Server
X-DN-Cache-Control
X-Gyrobase-Publication
X-Varnish-Cache-Local
OriginServer
X-B2f-Not-Route
X-Aramark-SID
Il-Cl
Proxy-Cache
X-Akamai-3PM-SW-Version
X-Apm-Telemetry-Syncmark
PagesDisplayed
Traffic-Origin
X-Dw-Trace-Id
X-Confluence-Request-Time
X-TB-M
X-Rewrite
X-Amcomm-Site
ViewMode
X-Data-Request
X-HashTwo
X-OPNET-Transaction-Trace
X-Pj-Cache-Status
Home
Ews
IISExport
X-SmartBan-Host
X-SmartBan-URL
ScoreTracker
X-MSEdge-Ref
X-Highwire-SessionId
WebServer
X-Cache-Dispatchercachecontrol
X-Cache-Dispatcherpragma
X-Highwire-RequestId
X-Info
X-Cdn-Forward
CLMOB
Myheader
X-Map-Context
X-Req-Head-Response
X-Adnet
Service-Worker-Allowed
X-DTC
X-Proxy-Cache-Key
X-Webcelerate
X-Reflector
X-FPC
SG
X-CacheID
X-Machine
FRONT-END-SECUREBROWSER
X-Magento-Action
X-Sc-Cache
Xc
Server-Id
X-Rack-CORS
AsisCache
X-UA
X-WA-Info
Url
X-W3TC-Minify
X-Cocoon-Version
X-HP-CAM-COLOR
X-PM-ID
Serverid
X-Unique-Id
NtCoent-Length
X-RealServer
Cleartype
X-Rack-Cors
X-Grid-Server
X-HostName
RN-Server
Warning
X-Protected-By
X-Goog-Meta-Replace
X-Header
X-Goog-Meta-Policy
BackendServer
X-Powered-By-Home.Pl
X-Depends
X-ProcessESI
X-Magento-Lifetime
X-Zendesk-User-Id
X-Zendesk-Origin-Server
X-Tag-Playlist
X-RemovedCookies
X-Cache-TTL-Age
Aoestatic
X-Environment-Context
X-Catalyst
X-Ghost-Cache-Status
X-Cache-Id
PServer
X-L-Path
X-JAVAX-PORTLET-FACES-NAMESPACED-RESPONSE
X-Instance-Id
X-Cache-FS-Status
X-Old-Content-Length
X-Cache-TTL-Current
Access-Control-Request-Headers
X-Secret
X-Src-Webcache
X-LBPoolMember
Session-From
NS-VaryByCustom-Key
X-Author
ServerIP
X-Cache-Via
X-Flex-Lastmod
X-ASAP-Age
X-Goog-Meta-Goog-Reserved-File-Mtime
X-JSESSIONID
X-M
X-Beatles
X-Would-Your-GrandPa-Wait
X-Your-GrandPa-Would-Wait
Hummingbird-Cache
X-Nginx
X-We-Are-Hiring
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
XX
X-Gateway-Cache-Key
SB-Site-Device
CommunityServer
SB-Cache-Life
SB-Cache-Remaining
X-Varnish-Id
X-TTL-Age
X-Flex-Tag
X-Flex-Tags
X-Origin-Cache
X-Flex-Lang
X-Flex-Evstart
SS
X-Flex-Community
X-Flex-Evend
X-VC-Cache
Accept-Language
X-Does-He-Have-Time
X-DSMX-Render-MS
X-DSMX-Rewrite-MS
X-Cache-Time
X-Cache-Set
Hosted-By
User-Agent
X-Amz-Meta-S3b-Last-Modified
Edgecast
X-Beatles-Hits
X-Upstream-Status
X-Middleton-PageSpeed
X-PBS-Appsvrip
TP-L2-Cache
X-CRA-DC
X-Upstream-Backend
X-NewsFlow-Sitename
X-PBS-Appsvrname
X-Timestamp
X-Streams-Distribution
X-PBS-Fwsrvname
TP-Cache
X-Ser
VServer
X-Rebelmouse-Surrogate-Control
X-PHP-Response-Code
X-Backend-Host
X-Response
X-Redirector
X-Cluster
Ctx
X-Bcwwwid
X-IP
X-Rebelmouse-Cache-Control
DNNOutputCache
X-Application
Provider
VC-NoCache
X-Pagely-Cache
X-Server-Addr
X-RAMCache
X-HAProxy
X-Resource
X-ACCELERATE
X-DB-Content-Length
X-SV
X-Lw-Cache
NZSpeedy
X-ReqId
X-HS-Status
Viewport
X-Netrix-ID
X-Varnish-Action
X-CSRF-Token
X-4ormat-Cacheable
Mime-Version
X-Served-Server
Server-Ip
X-FORWARDED-PROTO
X-Dynatrace
X-Serv
X-Header-Treatment
X-Litespeed-Tag
X-Instart-Cache-Id
X-Route
X-VC-Hash
X-Nginx-Request-Time
X-Enabled2
X-Enabled3
X-SuperCache
WP-AdvCache-MemCached
X-Router
X-Client-Ip
AR-CACHE
AR-PoweredBy
AR-ATIME
!~Request-OOB-Work
Session-Id
SB-Site-IE-VERSION
X-7d-Trace-Id
X-Enabled1
Fastly-Restarts
X-Container
X-Hash
Ec-Machine
INFO
Ec-CorrId
X-Domino-CacheValidationWithETagResult
X-Domino-CacheValidationWithETagReason
X-FIRSTBase
X-Amz-Meta-Content-Md5
X-CCM
X-Via-NSCOPI
X-Geo-IP
X-DDM-SERVER-UPDATED
X-DDM-SERVER
AR-SID
X-Cache-Me-Harder
X-MidCOM-Meta-Cache
X-Custom-Header
X-DevSrv-CMS
Ttl
EQ-Cache
X-AppVersion
X-Agent
X-Hosting
X-Az
X-Activity-Id
Uuri
PB-PID
X-MainProfileCategory
Quri
Tesla.Performance
X-Cache-Detail
X-Debug-Message
X-Amz-Id-1
X-Mobile-Rewrite
X-UT-Cache
Note
X-CH-Device
X-Box
X-DynamicCache
X-FastCGI-Cache-Status
X-HA
X-VC-Debug
Generate-Time
Referer
RSB-LINK
Tempo
Provided-Host
Microcache
X-REDIRECTSERVER
RequestId
X-7d-Instance-Id
X-Cache-Extended
Upgrade-Insecure-Requests
X-Cname-TryFiles
X-Say-Cacheable
X-Upgrade-Enabled
X-Served
X-Server-Ip
X-Say-TTL
X-SayCDN-TTL
X-Skip-Cache
X-Deity
X-Made-On
Control-Cache
PB-RID
X-Instance
X-Node-Name
X-SilverStripe-Cache
X-Status
X-LOCATION
X-Gannett-Site-Version
X-Not-Cacheable
X-DS1D
X-Enhanced-By
X-AMAZEEIO
X-Artvisual-Server
X-D-Time
X-Config-By
Access-Control-Allow-Method
CDCHOST
X-UnsetCookies
X-RequesterIP
X-Generation-Time
X-Nginx-Request-Processing-Time
X-NodeID
MwpReleaseVersion
MachineName
X-AISO-Cacheable
X-AISO-Server
X-MainProfileName
X-Cache-V
X-AISO-Cache
X-VC-Cacheable
X-MainProfileID
StatusCode
Cache-Status
EN-User
X-XHR-Current-Location
DrivedBy
X-S-Misc
Debug-Status
Expiries
ReqUrl
X-MainProfileURL
X-Time-Microsecs
Services
X-Node-ID
X-Blog
Server-ID
X-AppServer-Cache-Rule
ServerNode
Www.Aujourdhui.Com
Cacheid
Kanooh-Host
X-Test-Debug
X-Search-Id
X-Backend-Name
X-Cache-Original-TTL
Progma
X-Uncacheable
X-Full-Url
X-Max-Age
X-Turpentine-Esi
X-Cjtype
X-Rewritten-By
X-XHTML-Minification-Powered-By
X-Cache-Varnish
X-Pixelsilk-Version
X-SCM-Server-Number
X-ManagedFusion-Rewriter-Version
X-Distil-CS
X-Pubstack
X-Pixelsilk-Server
X-Oracle-DMS-ECID
X-Cache-Ttl
X-Oneagent-Js-Injection
X-Lb
X-ESI
Dynatrace
X-Ssl-Cipher
X-Ruxit-Js-Agent
X-Cache-Date
Language
X-AWS
CpuTime
X-Request-Received
GranicusServer
X-Archive-Orig-Server
X-Built-By
X-NewRelic-App-Data
X-Compress-Hint
X-Request-Processing-Time
X-Server-App
X-Server-Instance-Name
Powered-By-VeryCDN
X-WebNode
X-PBY
X-Debug-Serve
X-WHO
X-Cache-Warmer
WP-FROM-CACHE
X-Instance-Name
X-LB-Backend
X-Meta-Imagetoolbar
X-LB-Frontend
Realaction
MSThemeCompatible
Actioncode
X-Varnish-Cached-TTL
CS-SERVER
Httpd-Identifier
MSSmartTagsPreventParsing
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
Memento-Datetime
X-UPSTREAM-Address
X-Archive-Guessed-Charset
X-Archive-Orig-Connection
X-Archive-Orig-Date
X-Archive-Orig-Content-Length
TTL
CD4
X-Server-Vrn
X-Restarts
X-Wm-1
X-Wm-VIP
Actual-Object-TTL
X-Archive-Orig-ETag
MageStack-Cache-Hits
Key
X-S-V
X-S-C
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
Head
X-T
X-Serverid
AMFplus-Ver
CommercePlatform-Version
X-Transaction-Name
X-Q-S
X-B
X-Mw-Workerstats
X-M-V
X-Nocache
X-Pageid
X-Pool-Info
X-M-T
X-M-P
X-Beresp-Ttl
X-Cachable
X-Cacheable-TTL
X-I-V
X-Healthy
X-Varnish-Cached
MageStack-Area
X-Varnish-Store
MageStack-Cache
MageStack-Cache-Lifetime
MageStack-Cache-Status
X-MyName
X-Varnish-Esi-Method
X-OCTOPOD
X-Fastly-Backend-Reqs
X-Varnish-Currency
X-Varnish-Esi-Access
MageStack-Cacheable
MageStack-Config
X-Backend-TTL
X-Middleton-Pagespeed
X-NewCloud-V-Cache
X-Origin-Upstream-Status
X-ProBase-Server
MageStack-Web-Node
MageStack-Tag
MageStack-Debug
MageStack-Loadbalancer
MageStack-Magento-Version
MageStack-PageSpeed
Response-Time
VAR-Cache
X-EBAY-C-REQUEST-ID
X-FG-RequestId
Cache-Ctrol
RlogId
Copyright
X-PG
X-9XB-Server
Requested-Host
X-ELB
X-PROCESSED-BY
WSCLoggingUUID
Page-Template
X-Accel-Cache-Control
X-Powered-Developer
X-Server-Ident
X-Title
X-ServiceProvider
X-ZORequestID
X-Server-FQDN
ATI-Server-Id
X-Czt
X-Layout
X-Memcached
AccessControlAllowOrigin
X-Varnish-Grace
X-Who
Apple-Itunes-App
X-MSU-SOURCE
X-Cache-Served
X-Ar-Debug
UrlWatchModule-Time
X-VG-WebCache
X-ACLR-Version
X-This-Proto
X-SID
X-SE-Debug
X-Svr
OutputRewritten
X-Clx-Request
Accept-CH
X-ZSITES-DNS
SINA-LB
X-Country
SINA-TS
Aurora-Node
X-Varnish-URL
X-BC
X-Ants-Machine-Id
X-Ants-Host
Y-Trace
Yola-ID
X-Service-Id
X-Proxy-Id
Countrycode
Cookie
DB-Nickname
X-Distributed-By
Webserver
Content-Cache
DbServerName
FindLaw
Rewriter
IES-Server
Load-Balancer
X-Nitro-Cache
X-MCF-ID
X-Script
X-ServerAddr
X-Sn-Servicetimems
X-Fpc
X-CPU-Time
Request-Time
X-B3-Spanid
X-B3-Traceid
X-Built-With
CmsfirstPublishTimestamp
X-Sid
X-CO-Host
X-Cache-2
X-IP-Address
X-COUNTRY-CODE
X-VCS-Cacheable
X-BeResp-Ttl
X-VLoc
Fw-Cache-Status
X-Nginx-Page-Cache
X-Time-Zone
X-Varnish-Instance
X-VCS-Ttl
X-WAF-Proxy
X-DeliveryServer
X-Dynamic
X-Rocket-Nginx-File
X-Rocket-Nginx-Reason
X-DEBUG
X-Config-Version
XDisk
X-Cache-Bypass
E-TAG
X-Brought-To-You-By
X-UPServer