Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Date
Content-Type
Server
Set-Cookie
Connection
Cache-Control
Vary
X-Powered-By
Expires
Content-Length
Link
Last-Modified
Pragma
Accept-Ranges
ETag
X-Content-Type-Options
X-Frame-Options
Strict-Transport-Security
X-XSS-Protection
CF-RAY
Age
X-Cache
P3P
Expect-CT
Content-Language
X-AspNet-Version
X-Pingback
Via
Upgrade
X-UA-Compatible
Access-Control-Allow-Origin
Content-Security-Policy
X-Cacheable
X-Xss-Protection
X-Varnish
Referrer-Policy
X-Adblock-Key
X-Request-Id
X-Check
X-Generator
X-Language
X-Template
X-Type
WPE-Backend
X-Buckets
X-Cache-Group
X-Pass-Why
X-Drupal-Cache
Alt-Svc
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Permitted-Cross-Domain-Policies
X-Download-Options
X-Ac
X-Hacker
X-Cache-Hits
Host-Header
X-AspNetMvc-Version
X-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-Dc
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Via
X-Served-By
X-Powered-By-Plesk
X-Runtime
X-Contextid
X-PC-Hit
X-PC-Key
X-PC-AppVer
X-ServedBy
X-UA-Device
X-Amz-Cf-Id
X-Ua-Compatible
X-PC-Host
X-PC-Date
MS-Author-Via
Content-Location
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-IPLB-Instance
X-Timer
X-Powered-CMS
X-Seen-By
X-Wix-Request-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Rid
Status
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
CF-Cache-Status
X-Tumblr-Pixel-1
Cartoon
X-FRAME-OPTIONS
X-Tumblr-Pixel-2
X-Backend
X-Iinfo
Access-Control-Allow-Credentials
X-Shopify-Stage
X-Cache-Status
X-Host
X-CST
X-WPE-Loopback-Upstream-Addr
Content-Encoding
X-Endurance-Cache-Level
X-Cache-Hit
Powered-By
X-Port
X-Cache-Enabled
X-Mod-Pagespeed
X-Tumblr-Pixel-3
X-Request-ID
X-CDN
X-Logged-In
X-Server-Powered-By
X-DIS-Request-ID
Keep-Alive
X-Drupal-Dynamic-Cache
X-Server
X-Nginx-Cache-Status
X-Robots-Tag
X-Accel-Version
X-Proxy-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Turbo-Charged-By
X-LiteSpeed-Cache
X-Page-Speed
P3p
X-Content-Powered-By
X-Content-Digest
Content-Security-Policy-Report-Only
X-GitHub-Request-Id
X-AH-Environment
X-Tumblr-Pixel-4
X-FW-Hash
X-Rack-Cache
Request-Context
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Type
X-Pad
X-Hits
X-Varnish-Cache
X-Webcom-Cache-Status
Access-Control-Expose-Headers
Edge-Control
X-Newrelic-App-Data
X-XRDS-Location
X-BC-Stapler
X-Trace
X-Node
SPRequestGuid
X-MS-InvokeApp
X-SharePointHealthScore
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-Request-Country
X-HS-Cache-Config
WP-Super-Cache
X-HS-Content-Id
Cf-Railgun
Timing-Allow-Origin
X-Amz-Request-Id
X-Amz-Id-2
X-CF-Powered-By
X-Content-Security-Policy
Charset
X-PHP-Backend
X-INKT-URI
X-INKT-SITE
X-Cache-Lookup
X-Died
X-FullPageCaching
Request-Id
X-HS-Combine-CSS
X-Fastly-Request-ID
Access-Control-Max-Age
X-Cnection
X-Backend-Server
SPIisLatency
X-Edge-Cache
X-Edge-Cache-Key
SPRequestDuration
X-SERVER
Ali-Swift-Global-Savetime
X-Swift-CacheTime
X-Swift-SaveTime
Allow
EagleId
Composed-By
MicrosoftOfficeWebServer
X-CDN-Pop
X-CDN-Pop-IP
Rating
X-Tumblr-Pixel-5
Grace
X-Server-Name
X-Safe-Firewall
X-Device
X-SS-Conf
X-SS-Location
X-NF-Request-ID
X-DDC-Arch-Trace
Served-By
X-Spip-Cache
X-Tumblr-Content-Rating
X-Dw-Request-Base-Id
Liferay-Portal
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-HeyJason
X-VCache
X-Hyper-Cache
P-LB
P-WS
X-LiteSpeed-Cache-Control
Front-End-Https
X-Cloud-Trace-Context
Surrogate-Control
X-RateLimit-Remaining
X-RateLimit-Limit
X-OneAgent-JS-Injection
X-Cluster-Node
X-Servedby
X-Middleton-Display
Display
X-Original-Date
X-Sol
X-RateLimit-Reset
X-Loop
X-TNCMS
X-Webserver
X-Clacks-Overhead
X-Kinsta-Cache
Response
X-Middleton-Response
X-FB-Debug
X-Acc-Exp
X-Jimdo-Wid
X-Jimdo-Instance
X-PhApp
X-Vtex-Processado-Em
Content-Style-Type
X-StackifyID
X-Firenze-Processing-Times
Public-Key-Pins
Content-Script-Type
X-Debug-Info
X-Tumblr-Pixel-6
X-DNS-Prefetch-Control
Feature-Policy
X-Age
X-Amz-Version-Id
X-LW-Cache
X-Ruxit-JS-Agent
X-Magento-Tags
X-Frame-Option
X-DynaTrace-JS-Agent
X-XN-XNHTML
X-XN-Trace-Token
X-WebKit-CSP
X-Zen-Fury
X-Cached
Fpc-Cache-Id
X-Version
Refresh
Xkey
X-User-Agent
X-Goog-Hash
X-N-OperationId
X-Px
X-Cache-Config
X-HOST
Retry-After
X-ARC
PageSpeed
X-Hostname
X-Upstream
X-Edge-Location
X-Generated-By
X-Topify-Platform
X-Handled-By
X-FORWARDED-FOR
X-Microcache
X-Url
X-Goog-Generation
X-Goog-Metageneration
X-EdgeConnect-Origin-MEX-Latency
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Rt-Fastcgi-Cache
Fastcgi-Cache
TCN
Access-Control-Request-Method
Powered
X-Source
X-Whom
X-Loopia-Node
X-EdgeConnect-MidMile-RTT
WPX
X-Outils-CS
X-B-Cache
Last-Published
X-Magento-Cache-Debug
X-MiniProfiler-Ids
X-RESOURCE
X-URLSCHEME
X-VTEX-Janus-Router-Backend-App
X-Vtex-Remote-Cache
X-Cached-By
X-Vtex-Processed-At
X-VTEX-Cache-Status-Janus-ApiCache
X-CacheServer
No
X-Powered-By-VTEX-Janus-ApiCache
X-Accel-Expires
X-ET-API-ORIGIN
X-ET-API-ROOT
X-ET-API-VERSION
X-CMS-Version
ServedBy
Pagespeed
X-Dns-Prefetch-Control
X-Request-Time
X-Varnish-Count
X-Varnish-HitMiss
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Product
X-Varnish-Cache-Hits
X-Engine
X-Platform-Server
X-PERF
X-Platform-Cluster
X-ApacheServer
X-Platform-Router
X-Platform-Processor
X-Application-Context
X-Fastcgi-Cache
X-NewRelic-App-Data
X-DynaTrace
X-AspNetWebPages-Version
X-From
X-Content-Options
Imagetoolbar
X-Developer
X-Cache-Info
Public-Key-Pins-Report-Only
X-S
X-Actual-URL
X-URL
X-Varnish-Host
X-LBLID
Warning
X-Location-Id
X-Returned-From-DLL
X-Original-Request
X-Passed-To
X-Returned-From
X-Passed-To-DLL
Dmn
X-Ezoic-Cdn
X-SSLUpstream
X-Signature
Fhost
X-SSLProxy
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-HS-Content-Campaign-Id
X-Cache-Key
X-Microcachable
X-Stale
Host
X-F-Cache
X-Shop-Id
Cache-Key
X-Defender
Alternate-Protocol
X-SVR-IIS
X-Returned-From-BeforeDispatch
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
Cache-Provider
X-Svr-Proxy
X-Response-Time
X-Passed-To-PostProcessResponse
X-NWS-LOG-UUID
Generator
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Device-Type
X-Gateway-Cache-Key
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Cache-Rule
X-Powered-By-360WZB
X-Magento-Cache-Control
X-Cache-Age
X-Platform
X-Via-JSL
Arr-Disable-Session-Affinity
Origin
X-Umbraco-Version
X-Cdn
Content-Hash
X-Translation
X-Microcache-Status
X-Msg-2-Log
X-Varnish-TTL
X-Sapient
Version
X-Hosted-By
X-Micro-Cache
X-Platform-Cache
X-Instart-Request-ID
X-Cache-Tags
X-Track
Surrogate-Key
X-Rnd
X-GUploader-UploadID
X-Forwarded-For
X-Dispatcher
X-Akam-SW-Version
S-Cnection
X-Guploader-Uploadid
X-Environment
X-CSRF-Protection
X-Abgroup
USPLoggingUUID
X-Lambda-Id
DynaTrace
X-Supported-By
WZWS-RAY
Content-Disposition
X-DealerOn
X-Dealeron-Backend
X-Dealeron-Original-Url
SSPAppContext
X-SO
X-BS
X-ORACLE-DMS-ECID
MIME-Version
X-I-Sp
X-Powered-By-VTEX-Janus-Edge
X-Cache-Namespace
X-Duration
X-Server-ID
X-Drupal-Cache-Tags
X-App-Status
X-TransIP-Balancer
X-Powered-By-VelaWeb
X-Gamma-Serve
X-UD-Method
RTSS
X-SSL-Cipher
X-Cache-TTL
X-Director
X-Correlation-Id
X-Generated
FAI-W-FLOW
X-Server-Upstream
X-NetCat-Version
X-Correlation-ID
X-Art-Request-Id
X-TransIP-Backend
X-Matrix-Server
Pool
X-Matrix-Proxy
X-Debug
X-SSL-Protocol
Wsr-Cache
X-Expires-Orig
X-App-Hosting
X-VARITI-CCR
X-Sucuri-ID
X-Varnish-Seen-By
X-Varnish-ObjectSource
X-Varnish-GracePeriod
X-Varnish-RemainingTTL
X-Varnish-RemainingLife
X-Edge-IP
X-Front
Src-Update
X-Client-IP
Update-Time
X-I
Node
Req-Id
X-Cache-Control-Orig
X-Hypernode
X-Grace
X-Daa-Tunnel
Powered-By-ChinaCache
X-Sucuri-Cache
X-Storage
X-Cache-Lifetime
X-ATG-Version
X-Now-Id
X-Helper-Autoassign-All
X-Vcap-Request-Id
SN
X-Cache-Server
X-Page-Cache
X-Env
X-TTFB
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Cacheable
X-SmugMug-Values
Smug-CDN
X-Route-Server
X-Drupal-Cache-Contexts
X-TTFB-L
X-SmugMug-Hiring
Cache
X-NoCache
X-Pressidium-NinukisWP-Ver
X-Github-Request-Id
X-Rocket-Nginx-Bypass
X-Cache-Level
Content-Encoding-Handler
X-Esi
X-Server-Id
X-Cache-Debug
X-Content-Encoded-By
Edge-Control-Message
X-Last-Modified
X-Geo-Country
X-Rocket-Nginx-Serving-Static
X-SRV
Cache-Tags
ServerID
X-Flow-Powered
Cneonction
CF-Worker-Script
X-ServerName
X-Revision
X-Varnish-Age
Service-Worker-Allowed
X-Cache-Handler
X-UPSTREAM
X-Varnish-Url
X-Country-Code
X-LB-Server
X-Vhost
Contao-Page-Layout
X-Cache-Engine
X-Recruiting
X-Url-Base
SiteSpeed
X-ORACLE-DMS-RID
X-FTR-Request-ID
X-SV-Edge
X-SV-Duration
X-SV-CreatedAt
X-SV-CacheTags
X-SV-Expires
X-SV-FromDBCache
X-Forwarded-Proto
X-TTL
X-SV-Nginx-Duration
X-SV-Cacheable
X-SV-Pid
X-CJ-Soft
Accept-Encoding
X-Firenze-Processing-Time
CF-Worker-Version
X-Unbounce-VisitorID
X-Unbounce-PageId
X-Server-Instance
X-Unbounce-Variant
X-GeoIP-Country-Code
X-Locale
Author
X-TransIP-Reserved
X-Cache-Control
X-Ttl
Lsrequestid
X-PwB-Node
X-Discourse-Route
X-Cache-Type
X-Hiawatha-Cache
X-Trace-Id
X-IsCacheURL
If-Modified-Since
W
X-Time
X-Storage-Cache-Expires
X-N
X-Storage-Cache-Date
X-GeoIP-Country-Name
X-FIRSTBase
Akamai-IP
Section-Io-Id
X-Storage-Cache
X-Middleware-Start
X-Cache-Operation
X-Nginx-Cache
X-Varnish-Backend
X-SDS
X-Content-Type-Option
Strikingly-Cached
Proxy-Connection
X-Service-Id
X-NA-CachePolicy
Strikingly-Cache-Region
Strikingly-Cached-Version
X-Speed-Cache-Key
X-Speed-Cache
X-Magnolia-Registration
Custom-Header
Srv
X-Amz-Rid
X-Cache-Expires
X-Dispatch
X-Varnish-IP
MC
X-Rq
AMF-Ver
PICS-Label
Server-Name
Location
X-Twitter-Response-Tags
X-LB-Node
X-Transaction
X-Connection-Hash
Page-Completion-Status
Backend
Use-Proxy
X-LB
X-NginX-Cache
Https
Content-MD5
X-CF-Passed-Proto
Pv
X-Akamai-Device-Characteristics
X-Dynamic-Cache
X-Varnish-Retries
X-Processing-Time
X-Cache-Only-Varnish
X-Now-Cache
X-Akamai-Device-Model
X-Fastly-Request-Id
Dtk-Cache-Check-0
X-High-Performance
X-Empowered-By
Nodo
Accept-Charset
X-SRCache-Key
From-Origin
X-Cache-Device-Type
S
MJ12bot
SEOMOZ
Server-Timing
X-Wikidot-Backend
FindLaw
X-Content-Age
NnCoection
X-Wikidot-Static-Cache
X-Config-Blacklist-Version
IBM-Web2-Location
X-FW
X-Real-Server
X-PF-Uncompressing
X-Litespeed-Cache-Control
X-ServerID
ServerName
X-Cookie-Domain
X-TB-M
Qs-Cache
Prama
X-Frontend
Local-Info
X-Sedo-Request-Id
X-Amz-Storage-Class
X-BKSrc
X-Cache-Miss-From
X-CacheFROM
X-Cache-Fix
X-Shard
X-Cache-PageType
NetMindSessionID
X-Worker
X-Srv
X-BackendServer
X-Content-Security-Policy-Report-Only
X-WR-MODIFICATION
X-SP-Farm
X-SP-UniqueName
Ohc-File-Size
X-Browser
X-HW
Edit
X-Disney-Akamai-Rule
X-Adobe-Loc
X-Adobe-Content
X-Cache-2
X-ACMCache
X-Nbs
X-Hrouter
X-A
X-Varnish-Server
X-ARRServer
X-Hstore
Swift-Performance
X-Webkit-CSP
Tracecode
Pics-Label
X-Distributor
X-Amz-Meta-Content-Md5
X-Stage
Drupal-Pagecache-Memcache
X-Origin
X-4ormat-Cacheable
X-Server-IP
X-Orig-Vary
Content-Transfer-Encoding
Xc-Version
Cm-Server
X-Key
X-ID
X-Processed-By
X-Analytics
X-Symfony-Cache
X-Ruxit-Js-Agent
X-WEBSERVER
X-WR-Flags
Backend-Timing
Lookup-Cache-Hit
X-RealServer
HCVer
X-Cache-TTL-Remaining
A-Powered-By
X-App-Server
X-RequestId
X-Webstats-RespID
X-CB-Server
CacheControlHeader
Content_type
Cached
HAVer
X-EPiphany-Vid
Proxy-Agent
X-Proxy-Backend
RequestId
X-LP
X-Role
Server-Info
Pf.Web.Request.Id
Frame-Options
X-Drectory-Script
Request-Country
X-Avg-Cookie-Expires
X-AVG-Country-Code
X-Sys-Req-ID
X-Redman-Final-Url
X-Redman-Backend
X-Forwarded-Host
Referer
X-Akamai-Edgescape
X-Nitro-Cache
X-Client-Image-Vid
X-AEM
Adm-Server
X-Client-Vid
X-Cache-CFC
Request-EU
Hummingbird-Cache
X-FireWall-Port
X-Remote-Addr
Accept-CH
X-Akamai-Transformed
X-HydroSheep
X-Pantheon-Site
X-LW-Web-Server
X-Runtime-Affili
X-Pantheon-Phpreq
X-Pantheon-Environment
X-Cache-Ttl
Surrogate-Key-Raw
X-Pantheon-Az
Url
X-CLOUD-TRACE-CONTEXT
X-Pagename
IM-Version
X-App-Runtime
X-Hit-Cache
Front
SHInfo
X-JG-Page-Cache
X-VCS-Cacheable
X-Request-Uri
X-ClientSide-Caching
X-Path-Route
X-PRAM
X-Source-ID
X-HTML-Minification-Powered-By
X-VCS-Ttl
Report-To
Environment
X-Appmachine-Environment
X-Force
X-Varnish-Hostname
X-Yottaa-Optimizations
X-Cache-Dispatchercachecontrol
X-Span
X-Cache-Dispatcherpragma
X-Unique-ID
X-Generated-Timestamp
SRV
X-NginX-Server
X-Shield-Request-Id
X-Yottaa-Metrics
IISExport
X-CDN-Forward
X-VC-Enabled
X-Culture
X-E
Cteonnt-Length
X-CAPServer
X-RiS-PX
Accept-Language
X-Via-NSCOPI
X-Backend-Status
X-Cacheable-TTL
X-Runtime-Memory
X-Oneagent-Js-Injection
X-UnsetCookies
Server-ID
WWW-Authenticate
Web-App-Origin-Name
X-Framework
X-Distil-CS
CDN-Cache
XDomainRequestAllowed
Access-Control-Allow-Method
CDN-PullZone
Ramp
X-Unique-Id
Ram
CDN-RequestId
X-Balanceador
CDN-Uid
X-Yadis-Location
AsisCache
X-Jphone-Copyright
X-Qnm-Cache
Firespring-Website-Id
X-Proxy
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Noq
X-JSESSIONID
X-Varnish-Hits
RN-Server
Copyright
CDN-CachedAt
X-GeoIP
X-WPL-DATA
X-SDE-Name
X-Hosting-Env
Max-Age
ScoreTracker
Nginx-Cache
X-Plat
NODE
X-Envoy-Upstream-Service-Time
Eomportal-Instance
X-Proxy-Cache-Key
X-ZSITES-DNS
SVR
X-SERVER-ID
X-M-Reqid
X-GoCache-CacheStatus
X-CACHE-TTL
X-M-Log
X-Atraveo-Zone
X-Atraveo-Varnish-Server-Id
X-Atraveo-Set-Cookie
X-Atraveo-TTL
X-Atraveo-Param-Rm
X-Detected-Device
X-FastCGI-Cache
X-Nginx-Host
X-Vcache
X-Real-IP
X-HeBS-Cache-Status
X-NWS-UUID-VERIFY
Disablevcache
Pramga
Identity
X-Atraveo-From-Varnish-Cache
X-Resource
Machine
Lb
X-Consent-Required
X-NginX-Upstream
X-Debug-Token
X-AOL-HN
X-Atraveo-Cache-Control
X-Atraveo-ETag
X-Atraveo-Expires
X-Amz-Id-1
X-Amcomm-Site
Access-Control-Allow-Header
X-Middleton-PageSpeed
TC-Cache-IC
X-Highwire-SessionId
Arrnode
X-Highwire-RequestId
BALANCEDTO
X-Upstream-Backend
TC-S-Cache
TC-Cache-U
X-CRA-DC
X-Cache-Varnish
XX
X-SmartBan-URL
X-MCB-Server
X-SmartBan-Host
X-Purge-Host
X-Purge-URL
X-Refresh
Locale
X-Rebelmouse-Cache-Control
X-SAPP
X-Batcache
Filters
CLMOB
TC-Cache
X-Response
X-App
X-WebNode
Worker
X-GSL-Server
X-Cms-Mode
X-Proxy-Cache-Control
X-Soro
X-Secret
X-Via-S
X-Dev
Paypal-Debug-Id
X-MAT-GEO
VServer
WP-FROM-CACHE
X-Confluence-Request-Time
X-Ms-Request-Id
X-Compress-Hint
X-Desc
Access-Control
X-Session-Reinit
X-Amzn-RequestId
X-HostName
X-Amzn-Trace-Id
Nitro-Cache
YF-ID
X-Garden-Version
X-Origin-Date
Cleartype
X-Amz-Meta-S3b-Last-Modified
Access-Control-Request-Headers
X-RiS-UFDI
X-Fedora-School-Id
X-Amz-Apigw-Id
X-Location
X-Varnish-Debug-Age
X-Varnish-Debug-TTL
Yoncu-Errno
AMP-Redirect-To
AETN-Country-Name
AETN-Country-Code
AETN-Continent-Code
AETN-DEVICE
X-Timestamp
Load-Balancer
AETN-EU
AETN-City
Resin-Trace
X-AF-Userserver
X-Upstream-Status
X-ACCELERATE
X-Cache-On
X-Varnish-Grace
AETN-Area-Code
X-Resolver-IP
IES-Server
DNNOutputCache
*
X-PBY
X-FPC
CS-SERVER
X-Server-Addr
AKA-DEVICE
AETN-State-Code
AETN-Postal-Code
X-Adnet
X-Actindo-Request-Id
VANITY-HOST
Myheader
AETN-Latitude
AETN-Longitude
X-Actindo-Thread-Id
X-Actindo-Rs
TC-S-Cache-M
X-FastCGI-Cache-Status
Prot
X-Fstrz
Dispatcher
X-CacheDebug
X-Goog-Meta-Replace
Dis-Env
Serverid
X-Always-Cache
NLCacheNote
Magicmarker
Beyond-Iis
Nopic
X-Goog-Meta-Policy
X-Smartcache-Keys
X-Bip
X-Dw-Trace-Id
X-V
MICROSOFTOFFICEWEBSERVER
X-Cocoon-Version
X-Smartcache-Timeout
X-Session-ID
X-WP
X-WEBMGR-CACHE
X-Flex-Lastmod
GranicusServer
Now
FRONT-END-SECUREBROWSER
X-Map-Context
X-Req-Head-Response
Actual-Object-TTL
X-VC-TTL
X-Flex-Tags
X-Flex-Tag
X-Now-Trace
Home
X-Wodby-Node
X-Instance-Id
X-Domain-Checked
X-CacheID
X-Nginx-Dummy
AC-ELC
X-Served-Server
X-Provisioner-Version
PB-RID
PB-PID
X-Instance
X-Mobile-Rewrite
X-Origin-Upstream-Status
X-Origin-Cache
X-Static
Fastly-Backend-Name
X-Cdn-Forward
Pragrma
DrivedBy
X-7d-Trace-Id
X-7d-Instance-Id
X-Route
X-Mobilized-By
X-Hit
N365rili
X-Captured
X-UA-Bot
X-Rule
X-ETag
X-Autoru-App-Id
X-Autoru-Host
X-Cache-Doesi
X-Client-Id
Srv-Name
X-SH-Cache-Status
X-PHP-Response-Code
Upgrade-Insecure-Requests
X-Flex-Community
X-Flex-Evstart
X-Flex-Evend
X-Upgrade-Enabled
CommercePlatform-Version
X-Varnish-Backend-Beresp-Backend
X-Status
X-Custom-Name
Edgecast
OracleCommerceCloud-Sandiego
OracleCommerceCloud-Version
X-Flex-Lang
X-Id
Cmsid
X-Varnish-Ttl
Aurora-Node
Cf-Ipcountry
Xc
X-Varnish-Action
X-LBPoolMember
X-Reflector
X-Reflector-Cache
X-Geo
X-Appid
Num
X-Header
X-Info
X-Layout
X-Title
X-HashTwo
X-HA-Frontend
Traffic-Origin
X-Data-Request
X-Generated-Time
X-HA-Backend
X-Cache-Me-Harder
Viewport
X-Et-Api-Version
X-Lb
IP-Addr
MageStack-Area
X-Et-Api-Root
X-Et-Api-Origin
X-SERVER-NAME
X-Dynatrace-Js-Agent
X-Varnish-Id
X-WebServer
MageStack-Cache
MageStack-Cache-Hits
MageStack-Magento-Version
MageStack-PageSpeed
MageStack-Tag
MageStack-Web-Node
MageStack-Loadbalancer
MageStack-Debug
MageStack-Cache-Lifetime
MageStack-Cache-Status
MageStack-Cacheable
MageStack-Config
X-TKP-SRV-ID
Cmstype
X-Depends
X-Webcelerate
X-Country
X-Pageid
X-Proxy-Skip
X-Proto
TP-Cache
X-Nginx
X-ESI
X-Directory-Script
X-IP
X-We-Are-Hiring
X-UUID
X-Xml-Http-Blocked
NZSpeedy
X-Varnish-ID
Provider
X-DevSrv-CMS
CommunityServer
X-DataDome
X-Cache-Extended
TP-L2-Cache
X-Access-Control-Allow-Origin
Device
Description
X-ServerIndex
X-Gateway-Rate-Limit-Delayed
Og
Keywords
X-ReqId
Bios
X-FromPodPressCache
X-Grid-Server
X-Global-Transaction-ID
X-Firefox-Spdy
X-Backside-Transport
X-Beget-Proxy
X-Origin-Server
X-ProcessESI
ProxiaInstanceId
X-Nginx-Request-Processing-Time
X-Highwire-Sitecode
X-Highwire-Smart-Code
X-IIJ-Cache
X-InDy-Memory
X-Cache-Via
X-Router
X-Varnish-URL
X-Meta-Imagetoolbar
X-Meta-MSSmartTagsPreventParsing
X-Meta-MSThemeCompatible
X-Instance-Name
X-Firewall
X-Cache-TTL-Age
X-Cache-TTL-Current
X-Vol-Correlation
X-GZip
SINA-LB
X-Scheme
X-FORWARDED-PROTO
Session-Id
X-InDy-Time
X-InDy-Query
X-DynamicCache
X-Reqid
X-SSL-Host
X-Proxy-Server
MachineName
MwpReleaseVersion
SS
HSTS
X-PBS-Appsvrname
X-PBS-Appsvrip
X-Podname
Response-Time
Ssl-Proxy-Server
X-W3TC-Minify
Gzip
X-Render-Time
X-Protected-By
X-Rewritten-By
X-CH-Device
X-Src-Webcache
Thanks
X-RAMCache
X-PBS-Fwsrvname
X-Cache-HT
X-Vid
ClientIP
F5-IpCliente
X-Cache-Date
X-Mighty-Proxy
X-PM-ID
ViewMode
VSID
X-Optimization
X-WA-Info
X-NodeID
X-Zendesk-User-Id
X-Zendesk-Origin-Server
From
X-Rack-CORS
HitType
PBS
X-Ghost-Cache-Status
REFRESH
PROGMA
X-Serv
X-Server-Generated
X-SE-Debug
VC-NoCache
X-ManagedFusion-Rewriter-Version
X-Gannett-Site-Version
X-Netrix-ID
X-MyName
Apachenode
X-Middleton-Pagespeed
X-Built-By
X-Airee-Node
X-Blog
X-BPool-Back
X-BServer
X-RemovedCookies
X-Vary-Options
X-Fastly-Backend-Reqs
X-Cluster
X-Policy
CF-Cache-Key
X-Application
Content
X-Compressed-By
X-AppServer-Status
X-AppServer-Cache-Rule
X-ProBase-Server
X-Page
X-Oferteo-Domain
X-Proxy-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Action
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Record
X-Nx-All
X-Beluga-Trace
Proxy-Cache
X-Agent
Origin-Vm
X-Server-Hostname
X-Cache-Detail
X-AppServer-Cache-Exception
X-Amzn-Remapped-Date
X-Phpwcms-Release
X-Phpwcms-Page-Processed-In
X-WN-ClientGroup
Amfplus-Ver
X-Rack-Cors
X-V-Cache
X-Time-Spent
X-Domino-CacheValidationWithETagReason
X-UT-Cache
X-ENV
X-HS-Status
X-Box
X-Varnish-Cache-Local
X-B2f-Not-Route
X-Requestid
X-Aramark-CSID
SBSS
UrlWatchModule-Time
Webserver
D
X-Aramark-SID
X-Sid
X-Domino-CacheValidationWithETagResult
X-SilverStripe-Cache
X-SV
Content-Sn
X-Beluga-Response-Time-X
MageStack-Last-Modified
X-Varnish-Cached-TTL
MageStack-Cache-Warning
X-Catalyst
MageStack-Cache-Lifetime-Sent
X-Varnish-Cached
X-UPServer
X-GeoIP-Country
SINA-TS
X-Nx
X-Streams-Distribution
Generate-Time
X-Node-App
Server-Ip
MSThemeCompatible
ServerIP
Session-From
StatusCode
MSSmartTagsPreventParsing
Id
Debug-Status
X-Vol-Mrp
Hosted-By
Httpd-Identifier
X-Frames-Options
X-Beresp-Ttl
Play-Detected-Device
NGX
TYPO3-Sitename
Play-Detected-UserAgent
Web
X-Avvio-Cms-Cacheload
X-Batcache-Reason
TYPO3-Pid
Il-Cl
ModuleCacheType
X-Cache-FS-Status
WN
X-MCF-ID
Provided-Host
X-EC2-Instance-Id
X-Beluga-Cache-Status
X-Cdn-Origin
X-Beluga-Node
Z
X-MSU-SOURCE
X-Appversion
X-Cache-Warmer
AMP-Access-Control-Allow-Source-Origin
X-OpenCart-Lightning
X-CACHE-KEY
PServer
X-WHO
X-Clx-Request
X-Ms-Version
X-Serverid
CACHE
X-Served-From
X-Shopware-Cache-Id
X-Shopware-Allow-Nocache
X-Az
Ews
X-DB-Content-Length
X-Expires
X-RunCloud-Cache
X-CSRF-Token
ID
X-Cache-ID
X-Cache-Time
NS-VaryByCustom-Key
X-Tag-Playlist
EQ-Cache
Tesla.Performance
X-TLS-Version
X-Test
Tempo
MS-CV
X-Varnish-Ip
HTTPS
X-Activity-Id
X-Container
X-Built-With
NtCoent-Length
Apple-Itunes-App
X-TNCMS-Bot-Tier
Page-Template
X-Clara-ASAP
X-ASAP-Cache
X-ASAP-Age
AddDefaultCharset
X-ServiceProvider
X-Thanos
X-SuperCache
X-Newrelic-Synthetics
X-VG-WebCache
No-Cache
X-Croise-Owner
X-AWS
Progma
X-Enhanced-By
X-LAKANA-AB
X-VC-Hash
X-VC-Debug
X-VC-Cacheable
CINC-Endpoint
NEL
X-Svr
Amp-Access-Control-Allow-Source-Origin
X-HS-Content-Group-Id
X-VC-Cache
X-Pool
HitInfo
X-Request-Received
X-Request-Processing-Time
Language
Www.Aujourdhui.Com
X-InstanceId
X-Cjtype
X-DDM-SERVER-UPDATED
X-DDM-SERVER
X-Bitrix-Composite
X-B
X-ZORequestID
X-Req-Counter
X-T
X-Dispatcher-Number
NB-Cache
X-Transaction-Name
X-This-Proto
X-Served
X-Deity
X-Debug-Message
X-Cname-TryFiles
X-HA
X-Pj-Cache-Status
X-Resty-Request-Id
X-Processed
X-OCTOPOD
X-Stiffia-Cache
AR-ATIME
Xxline
X-Nws-Log-Uuid
AR-CACHE
AR-PoweredBy
X-Amz-Meta-Cb-Modifiedtime
Requested-Host
AR-SID
X-Author
Powered-By-115
135prxHost
129prxHost
X-UPSTREAM-Address
196prxHost
259pxline
316pxxline
262prline
X-Cache-LB
X-Rocket-Nginx-Reason
Origin-Cache-Control
X-UA
Origin-Edge-Control
SB-Cache-Life
SB-Cache-Remaining
X-Old-Content-Length
X-LB-Frontend
Expiries
X-Cache-Bypass
X-DODN-Id
X-DODN-Region
X-LB-Backend
SB-Site-Device
SB-Site-IE-VERSION
X-Nginx-VM-RT
X-Machine
X-Obvious-Info
X-Obvious-Tid
X-Page-Cacheable
X-Client-Ip
X-Apache2-RT-MicroSec
ServerTokens
ServerSignature
Tk
TTL
X-AMAZEEIO
X-Sn-Servicetimems
SERVER-NAME
X-SSLTerm-Server
X-TEST
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-Geo-IP
BackendServer
RSL-Trace-ID
X-Cache-Node
X-Skip-Cache
Fw-Via
Fastly-Drupal-Html
Ibf5scheme
X-Itkg-Cache-Tags
X-CacheLoc
X-Block-RuleID
X-Accel-Cache-Control
X-Fpc
Prototype-RootPath
X-Block-Rule
X-B3-Sampled
WP-AdvCache-MemCached
X-Front-Cache
X-Build-Id
Backend-Powered-By
DB-Nickname
X-RequesterIP
X-SATserver
X-MainProfileName
X-MainProfileURL
X-MainProfileID
X-MainProfileCategory
Sl-Pgid
Cache-Ctrol
X-NewsFlow-Sitename
X-PressLabs-Stats
X-ORIKEY
X-ROUTING
X-Search-Id
X-Varnish-Debug-Hits
X-From-Cache
X-Healthy
X-DN-Cache-Control
X-Custom-Header
X-DSMX-Render-MS
X-DSMX-Rewrite-MS
X-Gyrobase-Publication
X-Beatles
VAR-Cache
COMMERCE-SERVER-SOFTWARE
X-Telligent-Evolution
Fastly-Debug-Digest
TestCC
Ttl
X-Max-Age
X-ENDPOINT
X-Node-Id
X-NMT-Proxy
X-Pass-Through
X-Powered-By-ADS
X-Rocket-Nginx-File
X-Dck
X-Abuse
CDCHOST
X-User-Agent-Tier
HA-Status
X-No-Session
Ohc-Response-Time
X-SCM-Server-Number
X-Test-Debug
X-Tradeindia-Request-GUID
Value-Of-Url
X-APIAUTH-VAL
X-APIVERSION
X-Tradeindia-SMgmt
Purge-Cache-Tags
Hit-Count
X-Varnish-Cache-Ttl
X-WebKit-CSP-Report-Only
X-XHTML-Minification-Powered-By
Fastly-Restarts
X-NoIndex