Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
ETag
Link
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-AspNet-Version
X-Xss-Protection
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Generator
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
CF-Ray
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
P3p
X-Age
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
WPE-Backend
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Swift-CacheTime
X-Swift-SaveTime
X-Device
X-OneAgent-JS-Injection
X-WebKit-CSP
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Type
X-CST
X-Ac
X-Rq
X-Host
X-Node
X-Server-Id
Feature-Policy
Content-Location
X-Response-Time
X-Cnection
Report-To
X-Backend-Server
Surrogate-Control
X-Application-Context
X-Iejgwucgyu
EagleEye-TraceId
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Url
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
NEL
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Upstream-Env
X-Ruxit-JS-Agent
X-Dns-Prefetch-Control
X-Mod-Pagespeed
Pinterest-Generated-By
X-Vhost
X-DynaTrace
X-Px
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Goog-Hash
X-Server-Name
Verso
X-ESI
Accept-CH
X-Dispatcher
X-HW
X-VARITI-CCR
X-GitHub-Request-Id
MS-Author-Via
X-MS-InvokeApp
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-Kinja-Build
X-Kinja
Charset
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Version
AR-ATIME
AR-CACHE
X-Cached
AR-PoweredBy
X-DataStream-Cache-Status
X-ORACLE-DMS-RID
X-Powered-By-Plesk
Content-MD5
X-Recruiting
Public-Key-Pins
X-D2id
Service-Worker-Allowed
Accept-CH-Lifetime
X-TtlSet
X-Vname
X-PC
X-TTL
X-Navigation-Version
AR-Request-ID
X-Abt-Application-Version
Ar-Sid
RTSS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ser
X-Trace
X-Varnish-TTL
SPRequestGuid
X-Forwarded-Proto
X-Client-IP
X-Vcap-Request-Id
X-DynaTrace-JS-Agent
X-Amz-Server-Side-Encryption
X-SharePointHealthScore
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Expires
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Amz-Rid
X-Goog-Stored-Content-Encoding
X-Fastly-Request-ID
S
Arr-Disable-Session-Affinity
Nginx-Cache
X-VCache
X-Debug
X-Amz-Meta-S3cmd-Attrs
TCN
X-Oracle-Dms-Rid
X-Server-ID
X-Shield-Request-Id
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Proxy
X-Id
X-Dw-Request-Base-Id
X-Hits
X-XRDS-Location
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
SPRequestDuration
SPIisLatency
X-Akam-SW-Version
DynaTrace
X-B3-TraceId
Front-End-Https
X-FTR-Cache-Host
X-T
Access-Control-Request-Method
X-Goog-Storage-Class
X-Powered-CMS
X-SERVER
Realpath
X-NF-Request-ID
Paypal-Debug-Id
Tracecode
X-Ttl
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Amzn-Trace-Id
X-Varnish-Age
Fastcgi-Cache
X-Aspnet-Version
X-Litespeed-Cache
X-Forwarded-For
X-N
X-Content-Type
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Alternate-Protocol
X-Upstream
X-RateLimit-Remaining
X-Accel-Buffering
X-PressLabs-Stats
Fusion-Component-Id
X-HS-Hub-Id
X-Logged-In
X-Frontend
X-HS-Content-Id
X-Content-Digest
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-Sol
X-Middleton-Display
Display
X-Srv
X-Middleton-Response
Response
X-Hostname
AMP-Access-Control-Allow-Source-Origin
X-Kinsta-Cache
X-Cache-Key
X-Pad
Server-Name
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Fastcgi-Cache
X-Content-Options
X-User-Agent
Refresh
Host
X-Analytics
Backend-Timing
X-Grace
X-DIS-Request-ID
X-Correlation-Id
X-Rid
X-B3-Traceid
X-LB-Cache
X-IPLB-Instance
X-AppVersion
X-Debug-Info
X-Activity-Id
X-Az
X-Revision
Accept-Charset
X-Amz-Apigw-Id
X-CF-Powered-By
X-FastCGI-Cache
X-Amzn-RequestId
X-B
FilterID
X-Cache-Hit
ServerID
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Cdn
Powered-By-ChinaCache
X-B3-Sampled
X-Cache-2
Surrogate-Key
X-Page-Id
X-Whom
Server-Info
X-PHP-Backend
TP-Cache
TP-L2-Cache
X-Varnish-Backend
X-Request-Received
X-Request-Processing-Time
MS-CV
Host-Header
X-Origin-Server
X-Akamai-Edgescape
X-F-Cache
X-Amz-Replication-Status
X-Content-Security-Policy-Report-Only
X-Cluster
X-TT
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Webkit-CSP
X-FW-Hash
VIX-Pulpo-Node
X-App-Environment
X-FW-Serve
VIX-Pulpo-Upstream-Status
X-FW-Static
X-FW-Server
X-Mobile
X-Platform-Server
X-UA-Device-Type
X-FW-Type
Source
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Grace
X-Instance
X-Framework
X-Drupal-Cache-Tags
X-Content-Powered-By
Cache-Status
X-RateLimit-Limit
X-Cache-Action
X-Handled-By
X-Request-Guid
Access-Control-Allow-Method
X-Ruxit-Js-Agent
X-Cached-By
X-SS-Set-Cookie
X-Geo-Country
X-Zen-Fury
CACHE
X-Magnolia-Registration
X-FB-Debug
X-Ezoic-Cdn
X-Shard
X-Cache-TTL
X-Forwarded-Host
X-ATG-Version
Edge-Cache-Tag
From-Origin
X-Wix-Server-Artifact-Id
X-App-Server
PageSpeed
DC
X-GUploader-UploadID
X-Varnish-Server
X-Cache-Age
Cleartype
X-Node-Name
X-Varnish-Hostname
X-AOL-HN
X-XRDS-LOCATION
Cache-Tags
X-BCube-Filmed-By
Payment
X-Cache-Control
X-Response-Served-From
X-B-Cache
X-Signature
X-RequestSource
X-Region
Filters
X-WebKit-CSP-Report-Only
X-GeoIP
Healthy
X-Generated-By
X-VG-WebCache
Ms-Operation-Id
NGB
X-Adobe-Loc
X-Adobe-Content
Webserver
Upgrade-Insecure-Requests
X-UUID
X-FW-Dynamic
Country
X-RTag
X-Tumblr-Pixel-1
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Drupal-Cache-Contexts
X-Jobs
Server-Node
X-TX-ID
Retry-After
X-TT-TIMESTAMP
X-Redis-Cache
GEO-INFO
X-Content-Age
X-Cacheable-TTL
X-Via-JSL
X-Seen-By
Actual-Object-TTL
X-Varnish-Hits
Liferay-Portal
X-Locale
X-Cache-Rule
X-Storage
ServedBy
X-Contextid
X-Guploader-Uploadid
X-Rendered-As
Fastly-Restarts
HitType
Powered
Frame-Options
X-Varnish-IP
X-Cache-TTL-Remaining
X-BACKEND-TTL
X-Oneagent-Js-Injection
X-Real-IP
Viewport
X-WA-Info
X-Wix-Request-Id
ViewerVersion
Content-Style-Type
S-Cnection
Content-Script-Type
X-NewRelic-App-Data
X-Cache-Server
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Upgrade-Enabled
NtCoent-Length
Datacenter
X-Mode
X-Cache-Config
X-ProcessESI
X-RemovedCookies
X-TA-CDN-Provider
Eomportal-Instance
Xserver
X-Esi
X-Endurance-Cache-Level
X-Varnish-Cache-Hits
X-Device-Type
X-Is-Bot
X-Detected-As
X-ES-SERVER
X-Path-Route
Meta-Geo
X-Zipkin-Id
Machine
X-Routing-Service
X-Akamai-Transformed
X-RN-RSRV
Load-Balancing
X-Proxied
X-Cache-Var-Map
X-Cache-Var
X-Proto
Cache-Hits
X-Status
X-Cache-NE
Access-Control-Request-Headers
X-VWS-Id
X-Hl-Ver
L5d-Success-Class
X-Hosted-By
Mail-Subject
X-LJ-Flow-ID
X-Origin-Hint
X-Proxy
X-VG-TLSProxy
TWC-GeoIP-LatLong
X-AWS-Id
X-Backend-Name
X-Cache-Enabled
TWC-GeoIP-Country
X-Section
X-Access
X-S
We-Hiring
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Connection-Speed
TWC-Device-Class
TWC-Privacy
OT-Force-Account-Verify
Property-Id
X-FW-Version
X-Format
Now
Azure-RegionName
Azure-SiteName
Azure-InstanceId
Mn-Server-Ip
Azure-SlotName
Vix-Hermes-Req-Id
X-L-Path
X-Via-Fastly
Azure-Version
S-Rt
X-Viewer-Country
X-EIG-Tracking-Id
X-Environment-Context
X-ServerID
X-Loop
X-Tb
X-FC-Vary-Parameters
X-Akamai-Request-ID
X-Origin-Response-Time
X-TNCMS
X-From
DB-Nickname
X-Time
Cache-Tag
X-ProxyCache-Key
X-Time-Microsecs
X-Timing-Wait
Cache-Key
X-Varnish-Cacheable
Selected-FE
Origin-Edge-Control
Origin-Cache-Control
X-BYPASS-REASON
X-Xfnlog-Site
X-NCache
X-Labrador-Cache-Channel
X-Debug-Cache
X-JoinUs
X-Birta-Cache-Post
X-Birta-Served
X-Proxy-Build
X-ProxyCache-Status
X-IP
X-Cache-Category-Id
Decoy-Debug-Key
X-Human
X-Tumblr-Pixel-3
X-CCM
X-Via-CDN
X-Internal-Host
X-MP-GENERATED-AT
X-Trace-Id
Served-By
Decoy-Debug-Status
X-Origin-Host
X-Web-Node
X-Www-Served-By
X-Grey
Decoy-Debug-TTL
X-GRACE
X-Cache-Operation
X-Site-Version
X-OCL
Uber-Trace-Id
X-PCL
X-Generated
X-FB-TRIP-ID
NGX
X-CDN-Cache
X-Rocket-Nginx-Bypass
User-Agent
X-Vgn-Hpd-Reason
AsisCache
LB
X-EdgeConnect-Cache-Status
X-VC-Cache
X-Dynatrace-Js-Agent
X-R9-Blue-Green-Version
X-Rule
X-NWS-LOG-UUID
X-UA
X-Cluster-Node
Rt-Fastcgi-Cache
X-Newrelic-App-Data
X-Sucuri-ID
X-App-Name
X-Cache-Remote
X-RCS-CacheZone
X-UnsetCookies
Release
X-TIME
Hostname
X-B3-Spanid
Nel
X-PERF
X-ApacheServer
X-Agile-Age
X-Agile
X-Agile-Id
X-Source
Pagespeed
X-Nginx-Cache
X-APP-VERSION
X-Varnish-Ttl
Cache-Name
X-Ua
X-Datadome
X-Edge-Location
X-App-Version
X-Edge-IP
X-Request-Time
X-CACHE-KEY
X-Protected-By
X-Pubstack
X-Ocache
X-Origin
X-Hit
X-OVcl-Cache
X-OVcl
X-Cdn-Forward
Fastcgi-Useragent
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-A-Dcw
X-A-Dam
X-A-Dgt
Node
Ec-Rule-Version
Fly-Cache
Fly-Request-Id
MD5-Digest
Cross-Origin-Window-Policy
Cache-Prefix
X-Goog-Meta-Goog-Reserved-File-Mtime
Ajk
Arc-Country
BehaviorPad-Version
Meta-Geo-Continent
N-Cache
Server-Surrogate-Control
UCS
Www
X-A
Server-Cache-Control
Request-Time
X-A-Wwc
Rendered-Blocks
Request-Country
Request-EU
X-A-Ccd
X-Date
X-Processor
X-Platform
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-Origin-TTL
X-Mobile-URL
X-Nginx-Cache-Key
X-NU-AKA-ACS-Version
X-Origin-CC
X-Rojux
X-S-Cookie
X-Varnish-Authentication
X-Up
X-VCT
X-VG-WebServer
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-ScT
X-Server-Group
X-SRCache-Key
X-Transaction
X-Logtrace-Id
X-Instart-Isnd
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Connection-Hash
X-Core-Value
X-D
X-Cache-Grace
X-Cache-ASPX
X-Aed
X-ARC
X-B-Cookie
X-BB-ID
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Generated-In
X-G
X-Hp-Webp
X-IN-APIGATEWAY
X-IN-WAF
X-External-Request-Id
X-DPWN-IS-SECURE
X-Debug-Cache-Store
X-Destination
X-Developer
X-Developers
X-Accel-Expires-Debug
X-Application
Warning
Section-Io-Cache
X-Device-Os
X-Debug-Log
X-Dispatcher-Server
X-CUA
X-Distil-CS
X-Debug-Cookies
X-Epic-Correlation-Id
X-Geo-Header
X-Hash
X-Gannett-Site-Version
X-F5-Cache
X-Crawler
X-Eu-Site
X-Distributor
X-CGP
Server-Host
Thinkindot-CacheControl
RNT-Time
RNT-Machine
Origin
Pramga
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Cache-Miss-From
X-Info
X-Cache-FS-Status
X-Cache-Expires
X-C
X-Cache-Debug
X-Cms-Context
X-Li-Pop
X-Secret
X-Sedo-Request-Id
X-Refresh
X-Reboot
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-SIPLIST1
X-Skip-Cache
X-Var-Ttl
X-Webstats-RespID
X-TT-LOGID
X-Thinkindot-L3
X-SN
X-Qloud-Router
X-Proxy-Upstream
X-Matched-Rule
X-No-Session
X-Location
X-LI-UUID
On-Server
X-LI-Proto
X-Node-Id
X-NodeID
SRV
X-Proxy-Cache-Status
X-Origin-Expires
X-Origin-Date
X-NX-Host
X-Irp-Debug
X-Li-Fabric
Kp-EeAlive
Fastly-Soc-X-Request-Id
Content-Disposition
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Apple-News-Services-Handled
Cache-Cookie-Set-Lfrom
Lfy
Magicmarker
Heartbleed
Memcached
IsBot
X-ElasticPress-Search
Apple-News-Services-Parsed-Url
AKAMAI
Ha-Gx-Prefs
Apple-News-Services-Host
Apple-News-Services-Request-Url
Country-Code
Fastly-Backend-Name
Backend
HA-Ipaddr
X-Real-Ip
X-Cache-Backend
X-GZip
X-Cache-Info
X-Cache-Id
HTTPS
X-Planisys-CDN-Cache
X-Backend-Host
X-Auto-Login
X-Planisys-CDN-Rules
X-Gateway-Cache-Status
X-Backend-State
X-Backend-Url
X-Page-Type
X-Bip
X-BBXSRF
X-PHP-Host
X-Cache-Host
X-MSEdge-Flight
X-GeoIP-Country-Code
X-Fastly-Cache
Fastly-SIE
X-Fetched-On
X-GeoIP-City
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Generated-On
X-Dc
Fastly-SSL
X-MSEdge-Features
X-Policy
X-Core-Mission
CDCHOST
X-Level-Front-Cache
Fastly-SWR
X-Key
X-LAGOON
X-Cdn-Srv
X-Planisys-CDN-TTL
SD-X-WS
X-Sorting-Hat-ShopId
X-ServiceProvider
X-Swa-Ws
X-Thanos
X-S-Maxage
X-Ah-Environment
X-Server-IP
Server-Int
X-Sf
Is-Eu
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShopId
X-Amzn-Remapped-Date
X-ShardId
True-Client-Country-4JS
X-User
X-Variation
X-Sucuri-Cache
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Adler-Geo
X-Alternate-Cache-Key
X-Amzn-Remapped-Content-Length
X-Amzn-Remapped-Connection
X-Amz-Meta-Cache-Control
X-Request-URI
X-Servername
Platform
Powered-By
Proxy-Connection
X-Varnish-Url
Pagetype
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-WPE-Loopback-Upstream-Addr
X-FireWall-Port
X-Nc
X-TrackingId
X-Block-Status
X-Varnish-Beresp-Ttl
X-Hnp-Log
Pragrma
X-Cache-Bucket
Web-Mar-Node
X-Via-SSL
User-Cache-Control
X-Micro-Cache
X-Server-Time
X-Via-Edge
X-Owner
X-Gen-Mode
X-Passed-To-PostProcessResponse
X-Returned-From
X-RateLimit-Reset
X-Returned-From-DLL
X-Svr
X-Stale
X-Original-Request
X-Server-By
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Passed-To
X-Returned-From-BeforeDispatch
X-Passed-To-DLL
X-Actual-URL
Server-ID
X-Unique-ID
X-HS-Cache-Config
Host-ID
X-Croise-Owner
X-VServer
X-CDN-Forward
Cteonnt-Length
X-Microcachable
Cdn-Request-Time
Cdn-Host
Mime-Version
VivaBuild
Viewtype
DSUID
REQUESTUUID
X-Org
ServerName
X-Pjax-Url
FNAC-ModuleRouting
X-Edge-Server
X-Load-Cache
Gh-Request-Id
X-Parent-Response-Time
X-Aicache-OS
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
SID
X-NC
X-FPC
X-V
X-Gdpr
X-Ua-Device
Time
Memory
X-CSRF-TOKEN
X-From-Cache
Rt-Proxy-Cache
X-Sn-Servicetimems
X-ND-Cache
X-Apm-App-Name
X-Req
PICS-Label
X-Cdn-Origin
X-Apm-Inst-Hash
V-Age
X-Exp-Se
X-Apm-Svc-Key
ProcessTime
MIME-Version
X-Geo
X-Served-From
X-Servedbyhost
Odigeo-Trace-Id
X-URL
X-Tb-Optimization-Total-Bytes-Saved
X-HTML-Minification-Powered-By
X-Wa
Public-Key-Pins-Report-Only
X-Fstrz
X-Lb-Id
HostName
CF-IPCountry
Resin-Trace
X-Git-Hash
Cdn
X-GEO
X-Optimization
X-Cache-HT
Cf-Ipcountry
AR-SID
X-B3-Parentspanid
Wxu-Next-Region
Wxu-Next-Commit
X-Newrelic-Synthetics
X-Response-By
Wxu-Next-Hostname
X-Webkit-Csp
Fastcgi-X-Cache-Version
X-DC
GMS-Ver
Cache
X-Varnish-Beresp-TTL
X-Atg-Version
X-Release
XServer
Processtime
X-WR-MODIFICATION
Proxy-Firewall
WZWS-RAY
X-NODE
X-Fastly-Backend-Reqs
X-WebServer
X-Daa-Tunnel
X-Vcl-Version
X-Amz-Meta-Surrogate-Control
X-TH-Server
X-APP
X-Ratelimit-Remaining
X-UE-Client-Country
Mobile-Detection-Method
GW-Server
X-We-Are-Hiring
X-Phone
X-Clientip
X-Ratelimit-Limit
Countrycode
X-LB-ID
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
X-WA
SS
X-Instart-Info
CF-Cached-On
X-Nananana
X-Hyper-Cache
Ohc-File-Size
X-Fastly-Country-Code
Backend-Name
X-HS-Status
X-Vcache
X-Host-Name
X-NGINX-Cache
X-Check-Cacheable
X-Upstream-CT
FSS-Proxy
X-Ratelimit-Reset
X-Worker
X-Upstream-HT
X-CSRF-Token
X-HS-Combine-CSS
X-PF-Uncompressing
X-Zone
FSS-Cache
Pics-Label
Lb
178proxuri
189phosttRef
188prxHost
X-Backend-TTL
X-ServedByHost
GeoIp-Country-Code
Geoip-Latitude
219prxHost
355prline
Xxline
X-Server-W
352pxline
409pxxline
225prxHost
286prxHost
Amp-Access-Control-Allow-Source-Origin
DataCenter
X-Be
X-VHOST
SN
X-SERVER-NAME
Geoip-City
X-IPS-LoggedIn
URI
Ohc-Cache-HIT
X-Fpc
X-Dynatrace
X-GZIP
X-Request-Start
X-LiteSpeed-Cache-Control
Esi-Enabled
X-UPSTREAM-Address
X-UCC
X-Render-Time
WP-Super-Cache
X-Gen-Id
X-BE
Version
X-B3-SpanId
X-CS
Who
X-Varnish-Action
X-NGENIX-Cache
X-ID
X-Unique-Id
CDN
X-AssetVersion
X-Contensis-Viewer-Groups
X-Html-Edge-Cache
X-VCL-Version
X-Cache-URL
X-PJAX-URL
X-FORWARDED-FOR
X-HostName
Dynatrace
X-LiteSpeed-Tag
X-GDPR
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
X-Fastly-Cache-Hits
X-Via-Ucdn
X-SRV
X-Pf-Uncompressing
RequestUuid
Cneonction
X-Cache-Ttl
Serverid
X-Cdn-Cache
X-NWS-UUID-VERIFY
X-Vtex-Processado-Em
Accept-Ch
X-Store
X-ZONE
X-Vtex-Remote-Cache
X-RequestId
Server-Id
Accept-Language
X-Request-Url
X-Servedby
X-Akamai-Request-ID2
X-ServerName
A
X-Via-NSCOPI
RequestId
X-Pc-Key
X-Pc-Hit
X-Pc-Appver
X-Akamai-SSL-Client-Sid
Frontcache
Is-Session-Tracking
X-Serial
Ohc-Response-Time
X-HTML-Edge-Cache
X-Reqid
Get-Access-Time
X-Dw-Trace-Id
X-Cdn-Request-ID
X-Generation-Time
IBM-Web2-Location
X-Port
X-EC-Lua
NnCoection