Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
ETag
Link
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
X-CDN
Upgrade
Xkey
X-Turbo-Charged-By
P3p
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Robots-Tag
X-Nginx-Cache-Status
X-Server-Powered-By
X-Varnish-Cache
WPE-Backend
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Swift-CacheTime
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-CST
X-Ac
X-Rq
X-Node
X-Host
Feature-Policy
Content-Location
X-Type
X-Server-Id
X-Cnection
X-Response-Time
Report-To
X-Backend-Server
X-Application-Context
X-Cloud-Trace-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Cache-Lookup
X-Country-Code
Rating
NEL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Instart-Request-ID
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-Ruxit-JS-Agent
X-Vhost
X-Mod-Pagespeed
X-Upstream-Env
X-Origin-Upstream-Status
X-DynaTrace
X-Px
X-DataDome
Edge-Control
X-Goog-Hash
Verso
X-Server-Name
Accept-CH
X-Dispatcher
X-HW
X-ORACLE-DMS-RID
X-ESI
MS-Author-Via
X-GitHub-Request-Id
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
X-MS-InvokeApp
X-DataStream-Cache-Status
AR-CACHE
AR-ATIME
X-VARITI-CCR
AR-PoweredBy
Charset
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Cached
X-Kinja-Build
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Version
Content-MD5
X-Powered-By-Plesk
X-Recruiting
Public-Key-Pins
Service-Worker-Allowed
Accept-CH-Lifetime
AR-Request-ID
X-D2id
X-Navigation-Version
X-Abt-Application-Version
RTSS
X-TtlSet
X-Vname
X-PC
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ser
X-Server-ID
Ar-Sid
X-Varnish-TTL
X-Trace
X-Forwarded-Proto
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
X-TTL
X-Ttl
Nginx-Cache
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-FTR-Balancer
X-Country-Code-Real
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Amz-Rid
X-SharePointHealthScore
X-VCache
X-FTR-Expires
X-Fastly-Request-ID
S
X-Amz-Meta-S3cmd-Attrs
Arr-Disable-Session-Affinity
X-Debug
X-Shield-Request-Id
TCN
X-XRDS-Location
X-Dw-Request-Base-Id
X-Hits
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
SPIisLatency
SPRequestDuration
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Proxy
X-Id
X-Oracle-Dms-Rid
X-Akam-SW-Version
Access-Control-Request-Method
X-SERVER
X-T
X-Goog-Storage-Class
X-FTR-Cache-Host
Front-End-Https
DynaTrace
X-Powered-CMS
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Tracecode
X-Amzn-Trace-Id
Realpath
X-MSEdge-Ref
Fastcgi-Cache
X-Varnish-Age
X-N
X-Forwarded-For
Paypal-Debug-Id
X-B3-TraceId
X-Content-Type
X-Upstream
Alternate-Protocol
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-Middleton-Display
X-Sol
Display
X-Logged-In
X-Frontend
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
Response
X-Content-Digest
X-Middleton-Response
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
AMP-Access-Control-Allow-Source-Origin
X-Litespeed-Cache
X-Srv
X-Hostname
X-B3-Traceid
X-Accel-Buffering
X-Cache-Key
X-Pad
X-Kinsta-Cache
X-Accel-Expires
MicrosoftSharePointTeamServices
Server-Name
X-FastCGI-Cache
X-User-Agent
Host
Backend-Timing
X-Content-Options
X-Analytics
X-Correlation-Id
X-LB-Cache
X-Revision
X-Debug-Info
X-Fastcgi-Cache
X-AppVersion
X-IPLB-Instance
X-Rid
X-Az
X-Activity-Id
Refresh
X-Amz-Apigw-Id
X-Amzn-RequestId
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-DIS-Request-ID
FilterID
Accept-Charset
X-B
X-Cache-2
X-Cache-Hit
X-B3-Sampled
ServerID
Surrogate-Key
Powered-By-ChinaCache
X-CF-Powered-By
X-Grace
X-Page-Id
X-Whom
Server-Info
X-PHP-Backend
TP-Cache
TP-L2-Cache
X-Webkit-CSP
MS-CV
Host-Header
X-Request-Processing-Time
X-Content-Security-Policy-Report-Only
X-Request-Received
X-Varnish-Backend
X-Ruxit-Js-Agent
X-Akamai-Edgescape
VIX-Pulpo-Node
Source
X-Amz-Replication-Status
X-TT
VIX-Pulpo-Upstream-Status
X-Kong-Upstream-Latency
X-Cache-Action
X-Cluster
X-UA-Device-Type
X-Origin-Server
X-Kong-Proxy-Latency
X-App-Environment
X-Framework
Access-Control-Allow-Method
X-Content-Powered-By
X-Tumblr-User
Cache-Status
X-Platform-Server
X-GUploader-UploadID
X-Tumblr-Pixel
X-Mobile
X-Cached-By
X-Tumblr-Pixel-0
X-FW-Static
X-Drupal-Cache-Tags
X-Varnish-Grace
X-RateLimit-Limit
X-FW-Serve
X-F-Cache
X-FW-Server
X-FW-Type
X-Request-Guid
X-FW-Hash
X-Instance
X-Ezoic-Cdn
X-Shard
X-Geo-Country
X-SS-Set-Cookie
X-Handled-By
X-Zen-Fury
X-FB-Debug
X-Magnolia-Registration
X-Forwarded-Host
X-Cache-TTL
Edge-Cache-Tag
PageSpeed
From-Origin
X-ATG-Version
X-App-Server
X-Node-Name
X-Cache-Age
X-Varnish-Hostname
X-Varnish-Server
CACHE
DC
Cache-Tags
Cleartype
X-AOL-HN
X-BCube-Filmed-By
X-Cache-Control
Payment
X-Region
X-Wix-Server-Artifact-Id
X-Generated-By
Filters
X-WebKit-CSP-Report-Only
X-Response-Served-From
Healthy
Upgrade-Insecure-Requests
X-RequestSource
X-TX-ID
X-GeoIP
X-Adobe-Loc
X-Adobe-Content
Webserver
Ms-Operation-Id
X-TT-TIMESTAMP
X-RTag
Country
X-UUID
X-VG-WebCache
X-Storage
Cache-Tv-Group
NGB
X-Tumblr-Pixel-1
X-Signature
X-Redis-Cache
Actual-Object-TTL
X-B-Cache
X-Tumblr-Pixel-2
X-Drupal-Cache-Contexts
X-Jobs
X-FW-Dynamic
Retry-After
GEO-INFO
X-XRDS-LOCATION
X-Cacheable-TTL
X-Content-Age
Server-Node
X-Varnish-Hits
X-Cache-Rule
ServedBy
Liferay-Portal
X-Seen-By
X-Locale
Fastly-Restarts
X-Esi
X-Contextid
X-Via-JSL
Powered
X-Rendered-As
X-Oneagent-Js-Injection
Frame-Options
HitType
X-Cache-TTL-Remaining
X-Real-IP
X-Varnish-IP
X-TA-CDN-Provider
S-Cnection
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-BACKEND-TTL
X-WA-Info
X-Guploader-Uploadid
Content-Script-Type
Content-Style-Type
Viewport
X-GRACE
X-Cache-Server
X-Upgrade-Enabled
Eomportal-Instance
X-Time
Datacenter
X-Wix-Request-Id
X-Mode
ViewerVersion
NtCoent-Length
X-RemovedCookies
X-ProcessESI
X-Cache-Config
Xserver
X-Cache-NE
X-Akamai-Transformed
X-Varnish-Cache-Hits
X-Cache-Var-Map
X-ES-SERVER
Load-Balancing
Machine
X-Path-Route
X-Is-Bot
X-Hl-Ver
Cache-Hits
Cache-Key
X-From
Meta-Geo
X-Zipkin-Id
X-Routing-Service
X-Device-Type
X-Detected-As
X-Cache-Var
X-RN-RSRV
X-Endurance-Cache-Level
X-Proto
X-Proxied
Mn-Server-Ip
X-S
TWC-GeoIP-LatLong
Mail-Subject
OT-Force-Account-Verify
L5d-Success-Class
X-Section
Access-Control-Request-Headers
Property-Id
TWC-Connection-Speed
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Device-Class
Vix-Hermes-Req-Id
X-Access
X-Origin-Hint
X-VG-TLSProxy
X-LJ-Flow-ID
X-L-Path
We-Hiring
X-Environment-Context
X-Cdn
X-VWS-Id
X-Viewer-Country
X-Cache-Enabled
X-Hosted-By
X-AWS-Id
X-FC-Vary-Parameters
X-Backend-Name
Webcakes-Region
Webcakes-App-Name
Webcakes-App-Version
X-Tb
X-Format
X-Origin-Response-Time
X-Loop
Azure-Version
Decoy-Debug-Status
Decoy-Debug-Key
X-Labrador-Cache-Channel
DB-Nickname
X-FW-Version
Now
X-Status
X-Debug-Cache
X-Birta-Served
X-Birta-Cache-Post
X-Akamai-Request-ID
X-ServerID
X-EIG-Tracking-Id
X-Time-Microsecs
X-Via-CDN
X-Proxy
Origin-Cache-Control
Origin-Edge-Control
S-Rt
X-TNCMS
X-Web-Node
Decoy-Debug-TTL
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Azure-SiteName
X-JoinUs
X-OCL
X-PCL
X-IP
X-BYPASS-REASON
Cache-Tag
X-Proxy-Build
X-CCM
X-Human
X-Timing-Wait
X-NCache
NGX
X-FB-TRIP-ID
X-Tumblr-Pixel-3
X-Trace-Id
X-ProxyCache-Status
Selected-FE
X-ProxyCache-Key
X-Xfnlog-Site
X-Newrelic-App-Data
X-Cache-Category-Id
X-MP-GENERATED-AT
X-Internal-Host
X-Generated
X-Grey
X-Varnish-Cacheable
X-Cache-Operation
X-Via-Fastly
X-Rocket-Nginx-Bypass
Served-By
X-Vgn-Hpd-Reason
Uber-Trace-Id
X-Dynatrace-Js-Agent
X-Www-Served-By
X-Site-Version
X-Origin-Host
X-NewRelic-App-Data
X-VC-Cache
X-R9-Blue-Green-Version
X-Sucuri-ID
X-EdgeConnect-Cache-Status
X-CDN-Cache
X-Rule
X-RCS-CacheZone
X-NWS-LOG-UUID
LB
AsisCache
X-UA
X-Cache-Remote
User-Agent
X-Cluster-Node
X-UnsetCookies
Rt-Fastcgi-Cache
Release
Nel
X-App-Name
X-PERF
X-ApacheServer
X-B3-Spanid
X-TIME
X-Datadome
X-Agile-Id
X-Agile-Age
X-Agile
Pagespeed
X-Ua
X-Source
X-Nginx-Cache
Hostname
X-APP-VERSION
Cache-Name
X-Request-Time
X-Edge-Location
X-App-Version
X-Edge-IP
X-Ocache
X-Sucuri-Cache
X-Pubstack
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl-Cache
Warning
X-OVcl
X-Hit
X-VCT
X-Origin-CC
X-Origin-TTL
X-ElasticPress-Search
BehaviorPad-Version
X-Debug-Cache-Expiry
X-Date
X-Debug-Cache-Fetch
Arc-Country
X-Debug-Cookies
X-Debug-Cache-Store
X-D
Cache-Prefix
Cross-Origin-Window-Policy
Ec-Rule-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Core-Value
X-Connection-Hash
X-Debug-Log
X-Destination
X-Request-UUID
X-DPWN-IS-SECURE
X-External-Request-Id
X-G
X-Generated-In
X-Gannett-Site-Version
X-Rewrite-Enabled
X-S-Cookie
Ajk
X-Developer
X-Developers
X-Server-Group
X-ScT
X-Secret
X-Cache-Grace
Fly-Cache
Origin
Www
On-Server
X-A
Node
X-A-Ccd
UCS
Thinkindot-Control
Request-Time
Thinkindot-CacheControl
Request-EU
Request-Country
Thinkindot-CacheControl-Type
Rendered-Blocks
N-Cache
X-A-Dam
X-B-Cookie
X-ARC
X-BB-ID
X-Trv-Group
Fly-Request-Id
X-Cache-Expires
X-Application
X-Aed
X-A-Dcw
Meta-Geo-Continent
X-A-Dgt
MD5-Digest
X-Accel-Expires-Debug
X-A-Wwc
X-Hp-Webp
X-Rojux
X-NX-Host
X-Logtrace-Id
X-Region-Sid
X-NU-AKA-ACS-Version
X-Thinkindot-L3
X-PAYTM-SRV-ID
X-Mobile-URL
X-Transaction
X-Cdn-Forward
X-Twitter-Response-Tags
X-Matched-Rule
X-Instart-Isnd
X-VG-WebServer
X-Var-Ttl
X-IN-WAF
X-IN-APIGATEWAY
Xc-Version
X-Platform
X-NodeID
X-Processor
X-SRCache-Key
X-Up
X-Varnish-Ttl
X-Protected-By
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Cache-Backend
X-Rebelmouse-Cache-Control
X-Amzn-Remapped-Date
X-Block-Status
X-Cache-ASPX
X-Cache-Debug
X-SIPLIST1
X-Origin-Expires
X-Origin-Date
X-Amzn-Remapped-Connection
X-Rebelmouse-Surrogate-Control
X-RateLimit-Remaining-Second
X-PHP-Host
X-Varnish-Url
True-Client-Country-4JS
X-Proxy-Cache-Status
SRV
Server-Int
Server-Surrogate-Control
X-Via-Edge
User-Cache-Control
X-RateLimit-Limit-Second
X-Page-Type
X-ServiceProvider
X-Qloud-Router
X-Proxy-Upstream
Web-Mar-Node
X-Varnish-Authentication
X-Sf
Server-Host
X-Servername
X-Key
X-Irp-Debug
X-Policy
X-Distributor
X-Distil-CS
X-TT-LOGID
X-Device-Os
X-Dispatcher-Server
X-Sedo-Request-Id
X-Epic-Correlation-Id
X-Refresh
X-Hash
X-Hnp-Log
X-Gen-Mode
X-F5-Cache
X-Eu-Site
X-Request-URI
X-Info
X-LAGOON
X-Li-Fabric
X-Cache-Miss-From
X-SN
X-Nginx-Cache-Key
X-Cache-Info
X-Cache-Id
X-Reboot
X-No-Session
X-Cache-Host
X-Via-SSL
X-CGP
X-LI-Proto
X-Swa-Ws
X-Li-Pop
X-LI-UUID
X-Location
X-Cms-Context
X-Crawler
X-Webstats-RespID
X-Node-Id
X-C
HA-Ipaddr
Heartbleed
Fastly-Backend-Name
Server-Cache-Control
Fastly-SIE
Pagetype
Memcached
Magicmarker
Fastly-SWR
Apple-News-Services-Handled
Country-Code
Kp-EeAlive
Lfy
Content-Disposition
CDCHOST
X-Ah-Environment
Apple-News-Services-Request-Url
Backend
RNT-Machine
RNT-Time
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
IsBot
Proxy-Connection
Cache-Cookie-Set-Lfrom
Ha-Gx-Prefs
Pramga
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Fastly-Soc-X-Request-Id
X-FireWall-Port
X-Wikidot-Static-Cache
X-Cache-Bucket
Fastly-SSL
X-Wikidot-Backend
X-Cache-FS-Status
X-Server-IP
X-Core-Mission
Adler-Geo
AKAMAI
X-WPE-Loopback-Upstream-Addr
X-Variation
X-Cdn-Srv
X-Sorting-Hat-ShopId
X-ShardId
X-TrackingId
X-Backend-Host
X-Gateway-Skip-Cache
X-Shopify-Stage
X-Gateway-Cache-Status
X-Skip-Cache
X-Gateway-Cache-Key
X-Sorting-Hat-PodId
Platform
X-Generated-On
X-Thanos
SD-X-WS
X-Level-Front-Cache
X-GeoIP-Country-Code
X-Geo-Header
X-Fastly-Cache
X-ShopId
X-Backend-State
X-Auto-Login
X-Backend-Url
X-BBXSRF
X-Bip
X-Fetched-On
X-Alternate-Cache-Key
X-S-Maxage
X-MSEdge-Features
X-Amz-Meta-Cache-Control
X-MSEdge-Flight
X-Amzn-Remapped-Content-Length
Is-Eu
Section-Io-Cache
X-GZip
X-CACHE-KEY
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-RateLimit-Reset
X-CUA
HTTPS
X-Micro-Cache
X-Planisys-CDN-TTL
Powered-By
X-User
X-GeoIP-City
X-Server-Time
X-Owner
X-Real-Ip
X-Varnish-Beresp-Ttl
DSUID
Fastcgi-Useragent
FNAC-ModuleRouting
Cteonnt-Length
Server-ID
Pragrma
ServerName
X-Returned-From
X-Svr
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Stale
X-Passed-To-BeforeDispatch
X-Original-Request
Gh-Request-Id
X-Passed-To
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Returned-From-PostProcessResponse
X-Server-By
X-Org
X-Actual-URL
X-NC
X-Load-Cache
X-Dc
X-Nc
X-Parent-Response-Time
X-CDN-Forward
X-Aicache-OS
X-VServer
Host-ID
X-Pjax-Url
VivaBuild
AR-SID
Viewtype
X-HS-Cache-Config
X-Croise-Owner
MIME-Version
X-Unique-ID
X-Edge-Server
X-FPC
X-Sn-Servicetimems
V-Age
X-Cdn-Origin
Cdn-Host
X-Apm-Inst-Hash
X-Apm-App-Name
X-Apm-Svc-Key
REQUESTUUID
Cdn-Request-Time
X-Microcachable
X-Ua-Device
X-Exp-Se
Cache
Rt-Proxy-Cache
X-Gdpr
X-ND-Cache
X-Geo
X-CSRF-TOKEN
SID
PICS-Label
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Served-From
X-Oss-Server-Time
Mime-Version
Time
X-Wa
X-Servedbyhost
HostName
X-V
ProcessTime
Memory
X-B3-Parentspanid
X-Req
X-DC
X-From-Cache
CF-IPCountry
X-Tb-Optimization-Total-Bytes-Saved
Wxu-Next-Hostname
Wxu-Next-Commit
Resin-Trace
Wxu-Next-Region
Odigeo-Trace-Id
X-Cache-HT
X-Newrelic-Synthetics
X-Git-Hash
X-Optimization
X-HTML-Minification-Powered-By
Cf-Ipcountry
X-Fstrz
X-Lb-Id
Cdn
X-Varnish-Beresp-TTL
X-Response-By
Public-Key-Pins-Report-Only
X-Release
X-Atg-Version
GMS-Ver
Proxy-Firewall
X-WebServer
XServer
X-TH-Server
X-Dynatrace
X-GEO
Fastcgi-X-Cache-Version
X-WR-MODIFICATION
Processtime
X-Phone
X-LB-ID
X-Fastly-Backend-Reqs
X-Ratelimit-Remaining
X-Host-Name
X-APP
X-Vcl-Version
X-Instart-Info
CF-Cached-On
WZWS-RAY
X-Ratelimit-Limit
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
X-Daa-Tunnel
X-Amz-Meta-Surrogate-Control
Backend-Name
X-Check-Cacheable
X-Upstream-HT
X-Upstream-CT
X-Worker
Countrycode
Mobile-Detection-Method
X-We-Are-Hiring
X-UE-Client-Country
X-NGINX-Cache
X-Nananana
X-Vcache
X-Clientip
GW-Server
X-Backend-TTL
352pxline
X-Server-W
Xxline
409pxxline
355prline
188prxHost
X-HS-Status
178proxuri
X-WA
SN
189phosttRef
225prxHost
219prxHost
286prxHost
X-Ratelimit-Reset
X-Hyper-Cache
X-URL
X-ID
X-Zone
X-Fastly-Country-Code
SS
Lb
Ohc-File-Size
Dynatrace
X-CSRF-Token
Pics-Label
X-IPS-LoggedIn
X-ServedByHost
Version
DataCenter
X-B3-SpanId
X-HS-Combine-CSS
Geoip-Latitude
X-PF-Uncompressing
X-SERVER-NAME
FSS-Proxy
GeoIp-Country-Code
FSS-Cache
X-GZIP
Geoip-City
Esi-Enabled
X-Render-Time
X-VCL-Version
X-UPSTREAM-Address
X-Request-Start
X-BE
URI
X-Fpc
X-CS
GeoIP-Country-Code
X-Be
X-LiteSpeed-Cache-Control
WP-Super-Cache
GeoIP-City
GeoIP-Latitude
Ohc-Cache-HIT
X-AssetVersion
X-Unique-Id
X-Gen-Id
X-UCC
CDN
X-Akamai-Request-ID2
X-ZONE
X-Contensis-Viewer-Groups
X-PJAX-URL
X-Via-Ucdn
X-GDPR
X-Cdn-Cache
X-HostName
X-FORWARDED-FOR
Accept-Language
Amp-Access-Control-Allow-Source-Origin
X-Vtex-Remote-Cache
Who
X-Vtex-Processado-Em
Cneonction
X-SRV
RequestUuid
X-Fastly-Cache-Hits
X-Varnish-Action
X-RequestId
X-NWS-UUID-VERIFY
X-Html-Edge-Cache
X-Pf-Uncompressing
X-Cache-Ttl
Serverid
X-LiteSpeed-Tag
Accept-Ch
X-Store
X-Request-Url
X-Via-NSCOPI
X-Flog
Server-Id
X-Hello
A
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Reqid
X-Cache-URL
Locale
X-ABtesting
X-NGENIX-Cache
X-Akamai-SSL-Client-Sid
X-Dw-Trace-Id
Frontcache
Get-Access-Time
Is-Session-Tracking
X-Serial
X-Port
X-HTML-Edge-Cache
X-ServerName
NnCoection
X-Cdn-Request-ID
Ohc-Response-Time
X-EC-Lua