The correct header to send out is Cache-Control: no-cache, no-store. This will cause the back button to work correctly, when you press back the page will be fetched again from the server. Don't do anything else (expires in the past, pragma) since they'll only confuse the browser and probably screw up the back button.