Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
CF-Cache-Status
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
CF-Ray
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
WPE-Backend
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-CST
X-Ac
X-Rq
X-Node
X-Host
Feature-Policy
Content-Location
X-Type
X-Server-Id
X-Cnection
X-Response-Time
Report-To
X-Backend-Server
X-Application-Context
Surrogate-Control
X-Cloud-Trace-Context
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Cache-Lookup
X-Country-Code
Rating
NEL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Dns-Prefetch-Control
X-Ruxit-JS-Agent
Pinterest-Generated-By
X-Vhost
X-Mod-Pagespeed
X-Upstream-Env
X-DynaTrace
X-Origin-Upstream-Status
X-Px
X-DataDome
Edge-Control
X-Goog-Hash
Verso
X-Server-Name
Accept-CH
X-Dispatcher
X-HW
X-ORACLE-DMS-RID
X-ESI
MS-Author-Via
X-DataStream-Cache-Status
X-GitHub-Request-Id
X-VARITI-CCR
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
AR-ATIME
X-MS-InvokeApp
AR-PoweredBy
AR-CACHE
Charset
X-Cdn-Fetch
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
X-Cached
X-Version
Content-MD5
X-Powered-By-Plesk
X-Recruiting
Public-Key-Pins
Service-Worker-Allowed
Accept-CH-Lifetime
AR-Request-ID
X-D2id
X-Navigation-Version
X-Abt-Application-Version
RTSS
Ar-Sid
X-TtlSet
X-Vname
X-PC
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ser
X-Server-ID
X-Varnish-TTL
X-Trace
X-TTL
X-Forwarded-Proto
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
Nginx-Cache
X-FTR-Cache-Status
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-FTR-Expires
X-SharePointHealthScore
X-VCache
X-Amz-Rid
X-Fastly-Request-ID
S
X-Amz-Meta-S3cmd-Attrs
Arr-Disable-Session-Affinity
X-Debug
X-XRDS-Location
TCN
X-Shield-Request-Id
X-Ttl
X-Dw-Request-Base-Id
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Hits
X-TEC-API-ROOT
SPRequestDuration
SPIisLatency
DynaTrace
Pinterest-Version
X-Oracle-Dms-Rid
X-Upstream-Proxy
X-Id
X-Pinterest-Rid
X-Akam-SW-Version
Access-Control-Request-Method
X-T
X-SERVER
X-Goog-Storage-Class
X-FTR-Cache-Host
Front-End-Https
X-Powered-CMS
X-Aspnet-Version
X-B3-TraceId
X-NF-Request-ID
X-Acc-Meta-Resource-Type
X-Amzn-Trace-Id
Tracecode
X-MSEdge-Ref
Realpath
Fastcgi-Cache
X-Varnish-Age
Paypal-Debug-Id
X-N
X-Forwarded-For
X-Content-Type
Alternate-Protocol
X-Upstream
X-RateLimit-Remaining
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Sol
X-Middleton-Display
Display
X-Frontend
X-PressLabs-Stats
X-Logged-In
X-HS-Hub-Id
X-HS-Content-Id
X-Content-Digest
X-Middleton-Response
Response
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
AMP-Access-Control-Allow-Source-Origin
X-Litespeed-Cache
X-Srv
X-Hostname
X-Accel-Buffering
X-Cache-Key
X-Webkit-CSP
X-Pad
X-Accel-Expires
X-Fastcgi-Cache
X-Kinsta-Cache
MicrosoftSharePointTeamServices
Server-Name
X-B3-Traceid
Host
X-User-Agent
X-Content-Options
X-Cdn
X-Analytics
Backend-Timing
X-Correlation-Id
Refresh
X-Revision
X-LB-Cache
X-Debug-Info
X-Activity-Id
X-DataStream-MidMile-RTT
X-Amz-Apigw-Id
X-DataStream-Origin-MEX-Latency
X-Amzn-RequestId
X-AppVersion
X-DIS-Request-ID
X-IPLB-Instance
X-Rid
X-Az
X-B
FilterID
Accept-Charset
X-Cache-2
X-Cache-Hit
X-B3-Sampled
ServerID
Surrogate-Key
Powered-By-ChinaCache
X-CF-Powered-By
X-FastCGI-Cache
X-Grace
X-Page-Id
X-Whom
Server-Info
X-PHP-Backend
TP-Cache
TP-L2-Cache
Host-Header
X-Request-Processing-Time
MS-CV
X-Request-Received
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-Varnish-Backend
X-Origin-Server
X-TT
VIX-Pulpo-Upstream-Status
X-Amz-Replication-Status
X-Akamai-Edgescape
VIX-Pulpo-Node
Source
X-Kong-Proxy-Latency
X-App-Environment
X-Kong-Upstream-Latency
X-Cache-Action
X-Cluster
X-Framework
X-UA-Device-Type
Cache-Status
X-GUploader-UploadID
X-Content-Powered-By
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Cached-By
X-Tumblr-User
X-Mobile
X-Platform-Server
Access-Control-Allow-Method
X-Request-Guid
X-FW-Server
X-FW-Type
X-Drupal-Cache-Tags
X-RateLimit-Limit
X-Instance
X-FW-Static
X-FW-Serve
X-F-Cache
X-FW-Hash
X-Varnish-Grace
X-Shard
X-Ezoic-Cdn
X-Handled-By
X-Zen-Fury
X-Geo-Country
X-SS-Set-Cookie
X-FB-Debug
X-Magnolia-Registration
X-Cache-TTL
X-Forwarded-Host
Edge-Cache-Tag
PageSpeed
From-Origin
X-ATG-Version
X-App-Server
X-Node-Name
X-Cache-Age
DC
X-Varnish-Hostname
X-Varnish-Server
CACHE
Cleartype
Cache-Tags
X-BCube-Filmed-By
X-AOL-HN
X-Cache-Control
Payment
X-Wix-Server-Artifact-Id
X-Region
Healthy
X-RequestSource
X-Response-Served-From
X-WebKit-CSP-Report-Only
Filters
X-Generated-By
Upgrade-Insecure-Requests
X-GeoIP
X-TX-ID
X-Adobe-Content
X-Adobe-Loc
X-TT-TIMESTAMP
X-Storage
X-VG-WebCache
Country
X-RTag
Webserver
X-UUID
Ms-Operation-Id
NGB
Cache-Tv-Group
X-Redis-Cache
Actual-Object-TTL
X-B-Cache
X-Signature
X-Tumblr-Pixel-1
Server-Node
X-Tumblr-Pixel-2
Retry-After
X-Jobs
X-FW-Dynamic
X-Drupal-Cache-Contexts
X-Locale
X-XRDS-LOCATION
X-Varnish-Hits
GEO-INFO
X-Content-Age
X-Cacheable-TTL
ServedBy
X-Cache-Rule
X-Seen-By
Liferay-Portal
Fastly-Restarts
X-Contextid
X-Esi
X-Via-JSL
Powered
X-Rendered-As
X-Oneagent-Js-Injection
Frame-Options
HitType
X-Cache-TTL-Remaining
X-Varnish-IP
X-Real-IP
X-TA-CDN-Provider
S-Cnection
X-Yottaa-Optimizations
X-Yottaa-Metrics
Viewport
X-BACKEND-TTL
X-WA-Info
X-Guploader-Uploadid
Content-Script-Type
Content-Style-Type
X-Cache-Server
X-GRACE
X-Upgrade-Enabled
X-ProcessESI
X-RemovedCookies
Eomportal-Instance
NtCoent-Length
X-Mode
ViewerVersion
Datacenter
X-Wix-Request-Id
X-Time
X-Cache-NE
X-Cache-Config
Xserver
X-Varnish-Cache-Hits
X-Akamai-Transformed
X-Routing-Service
X-Is-Bot
X-Zipkin-Id
X-RN-RSRV
X-Path-Route
X-Hl-Ver
X-Proxied
X-Proto
X-Detected-As
Machine
Load-Balancing
Cache-Key
Cache-Hits
Meta-Geo
Mn-Server-Ip
X-Device-Type
X-Cache-Var-Map
X-Cache-Var
X-Endurance-Cache-Level
X-ES-SERVER
X-From
X-S
X-Cache-Enabled
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
X-Backend-Name
X-Environment-Context
TWC-Connection-Speed
X-FC-Vary-Parameters
X-AWS-Id
Webcakes-App-Name
We-Hiring
Vix-Hermes-Req-Id
Webcakes-App-Version
Webcakes-Region
TWC-Locale-Group
X-Access
Property-Id
X-Hosted-By
TWC-Privacy
X-Section
Mail-Subject
Access-Control-Request-Headers
X-VG-TLSProxy
L5d-Success-Class
X-VWS-Id
X-Origin-Hint
X-L-Path
OT-Force-Account-Verify
X-LJ-Flow-ID
X-Viewer-Country
Decoy-Debug-Key
Decoy-Debug-Status
Now
S-Rt
Origin-Edge-Control
Origin-Cache-Control
Decoy-Debug-TTL
X-Birta-Served
X-Time-Microsecs
X-Status
X-ServerID
X-TNCMS
X-Via-CDN
X-Tb
X-Web-Node
X-Origin-Response-Time
X-Loop
X-Debug-Cache
DB-Nickname
X-Birta-Cache-Post
X-EIG-Tracking-Id
X-Format
X-Labrador-Cache-Channel
X-FW-Version
X-Akamai-Request-ID
X-Proxy
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
Azure-Version
X-OCL
X-ProxyCache-Key
X-Proxy-Build
X-JoinUs
X-PCL
X-Human
X-CCM
Cache-Tag
X-BYPASS-REASON
Selected-FE
X-IP
X-ProxyCache-Status
X-Xfnlog-Site
X-NCache
NGX
X-FB-TRIP-ID
X-Varnish-Cacheable
X-Via-Fastly
X-Timing-Wait
X-Tumblr-Pixel-3
X-Trace-Id
X-Site-Version
X-Cache-Category-Id
X-Newrelic-App-Data
X-Generated
X-MP-GENERATED-AT
X-Grey
X-Internal-Host
X-Www-Served-By
X-Cache-Operation
Uber-Trace-Id
X-Vgn-Hpd-Reason
Served-By
X-Rocket-Nginx-Bypass
X-Dynatrace-Js-Agent
X-VC-Cache
X-NewRelic-App-Data
X-Origin-Host
X-Sucuri-ID
X-EdgeConnect-Cache-Status
X-R9-Blue-Green-Version
X-Rule
X-RCS-CacheZone
X-CDN-Cache
X-NWS-LOG-UUID
LB
AsisCache
X-UA
X-Cache-Remote
X-Cluster-Node
User-Agent
X-UnsetCookies
Release
Rt-Fastcgi-Cache
Nel
X-App-Name
X-PERF
X-ApacheServer
X-TIME
X-Datadome
X-Agile-Id
Pagespeed
X-Ua
X-Agile-Age
X-Agile
X-Source
X-Nginx-Cache
X-B3-Spanid
Hostname
X-APP-VERSION
Cache-Name
X-App-Version
X-Request-Time
X-Edge-Location
X-Sucuri-Cache
X-Ocache
X-Edge-IP
X-Pubstack
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl
X-OVcl-Cache
X-Hit
Warning
X-ElasticPress-Search
X-Cdn-Forward
X-Protected-By
X-Origin-CC
X-Origin-TTL
X-VCT
X-Transaction
X-Trv-Group
On-Server
X-Debug-Cache-Expiry
Origin
X-Varnish-Authentication
Node
Ajk
X-D
Thinkindot-Control
X-Date
UCS
X-VG-WebServer
X-Debug-Log
Request-EU
X-Destination
X-Developer
Request-Time
X-Developers
Request-Country
X-Debug-Cookies
Thinkindot-CacheControl
X-Core-Value
Server-Surrogate-Control
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Rendered-Blocks
Thinkindot-CacheControl-Type
N-Cache
X-A-Dgt
X-BB-ID
X-B-Cookie
X-A-Dcw
Ec-Rule-Version
X-A-Ccd
X-A-Dam
X-ARC
X-A-Wwc
X-Application
X-Twitter-Response-Tags
Fly-Request-Id
X-Aed
Fly-Cache
X-Accel-Expires-Debug
X-A
Cross-Origin-Window-Policy
X-CF-Lambda-Fn
BehaviorPad-Version
Arc-Country
Meta-Geo-Continent
X-Up
X-CF-Lambda-Version
Cache-Prefix
X-Thinkindot-L3
Www
X-Var-Ttl
MD5-Digest
X-Cache-ASPX
X-Cache-Grace
X-Cache-Expires
X-Connection-Hash
X-External-Request-Id
X-Request-UUID
X-Server-Group
X-Processor
X-IN-WAF
X-S-Cookie
X-IN-APIGATEWAY
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-Hp-Webp
X-NX-Host
X-NU-AKA-ACS-Version
X-ScT
X-Logtrace-Id
X-Matched-Rule
X-Instart-Isnd
X-NodeID
X-Secret
Server-Cache-Control
X-Region-Sid
X-Platform
X-Mobile-URL
X-Generated-In
Xc-Version
X-DPWN-IS-SECURE
X-Rojux
X-SRCache-Key
X-Gannett-Site-Version
X-G
X-Varnish-Beresp-Status
X-Cache-Backend
X-Varnish-Beresp-Grace
X-Varnish-Ttl
X-Distil-CS
X-LI-UUID
X-F5-Cache
X-LI-Proto
X-Request-URI
Web-Mar-Node
X-Irp-Debug
X-Info
Server-Host
X-Proxy-Cache-Status
Server-Int
X-Sedo-Request-Id
X-RateLimit-Remaining-Second
X-Proxy-Upstream
User-Cache-Control
X-No-Session
True-Client-Country-4JS
X-RateLimit-Limit-Second
X-Dispatcher-Server
X-Refresh
X-Device-Os
X-Node-Id
X-Qloud-Router
X-Eu-Site
SRV
X-Epic-Correlation-Id
X-Nginx-Cache-Key
X-Amzn-Remapped-Connection
X-Reboot
X-Origin-Date
X-Location
X-Li-Pop
X-CGP
X-SN
X-Swa-Ws
X-Cache-Info
X-Cache-Miss-From
X-Cms-Context
X-PHP-Host
X-Hnp-Log
X-Geo-Header
X-Li-Fabric
X-Sf
X-Policy
X-Crawler
X-Cache-Id
X-Cache-Host
X-LAGOON
X-Gen-Mode
X-Rebelmouse-Cache-Control
X-Servername
X-Hash
X-Amzn-Remapped-Date
X-Rebelmouse-Surrogate-Control
X-Block-Status
X-C
X-Page-Type
X-SIPLIST1
X-Cache-Debug
X-Distributor
X-ServiceProvider
X-Origin-Expires
X-Key
X-Via-Edge
Fastly-Backend-Name
Country-Code
Content-Disposition
CDCHOST
Fastly-SIE
Fastly-Soc-X-Request-Id
Heartbleed
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SWR
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Varnish-Url
X-Via-SSL
X-Webstats-RespID
X-Ah-Environment
Apple-News-Services-Handled
Apple-News-Services-Host
Cache-Cookie-Set-From
Backend
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
IsBot
AKAMAI
Proxy-Connection
Memcached
X-TT-LOGID
RNT-Machine
Pagetype
Magicmarker
Lfy
RNT-Time
Kp-EeAlive
Pramga
X-FireWall-Port
X-Wikidot-Backend
X-Wikidot-Static-Cache
Is-Eu
X-Variation
X-GeoIP-City
X-Core-Mission
X-Skip-Cache
X-Level-Front-Cache
Adler-Geo
X-Fastly-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Planisys-CDN-Rules
X-Generated-On
X-Planisys-CDN-Cache
SD-X-WS
X-Planisys-CDN-TTL
X-TrackingId
X-ShopId
X-Sorting-Hat-ShopId
X-Fetched-On
X-GeoIP-Country-Code
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShardId
X-Amzn-Remapped-Content-Length
X-Bip
X-Cache-Bucket
X-Thanos
X-Auto-Login
X-Server-IP
X-User
X-Backend-Host
Fastly-SSL
X-Backend-State
X-Backend-Url
X-BBXSRF
X-Alternate-Cache-Key
X-Amz-Meta-Cache-Control
X-Cdn-Srv
X-S-Maxage
X-Cache-FS-Status
X-MSEdge-Features
Platform
X-WPE-Loopback-Upstream-Addr
HTTPS
X-MSEdge-Flight
X-GZip
X-CACHE-KEY
Section-Io-Cache
X-Server-Time
Powered-By
X-RateLimit-Reset
X-CUA
X-Owner
X-Micro-Cache
DSUID
X-Real-Ip
Fastcgi-Useragent
X-Varnish-Beresp-Ttl
ServerName
FNAC-ModuleRouting
Pragrma
Server-ID
Cteonnt-Length
X-Passed-To
X-Original-Request
X-Passed-To-BeforeDispatch
X-Org
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
Gh-Request-Id
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Actual-URL
X-Returned-From-DLL
X-Svr
X-Returned-From
X-Stale
X-Server-By
X-Dc
X-Nc
X-Load-Cache
X-NC
Host-ID
X-Croise-Owner
VivaBuild
Viewtype
X-CDN-Forward
X-Aicache-OS
X-Parent-Response-Time
X-HS-Cache-Config
REQUESTUUID
X-Pjax-Url
X-VServer
MIME-Version
X-Unique-ID
X-Cdn-Origin
X-Sn-Servicetimems
X-Apm-App-Name
X-Apm-Svc-Key
X-Apm-Inst-Hash
X-FPC
Cdn-Request-Time
Cdn-Host
X-Edge-Server
V-Age
X-Microcachable
X-Gdpr
X-ND-Cache
Rt-Proxy-Cache
Cache
X-Geo
X-CSRF-TOKEN
X-Exp-Se
X-Ua-Device
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
SID
X-Served-From
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
Mime-Version
X-Servedbyhost
PICS-Label
Memory
X-Wa
Time
HostName
ProcessTime
X-V
X-B3-Parentspanid
X-From-Cache
X-Req
X-DC
CF-IPCountry
Wxu-Next-Region
X-Tb-Optimization-Total-Bytes-Saved
Resin-Trace
Wxu-Next-Hostname
Odigeo-Trace-Id
Wxu-Next-Commit
X-Optimization
X-Newrelic-Synthetics
X-Git-Hash
X-Cache-HT
AR-SID
X-HTML-Minification-Powered-By
Cf-Ipcountry
Cdn
X-Lb-Id
X-Fstrz
X-Varnish-Beresp-TTL
Public-Key-Pins-Report-Only
X-Release
X-Response-By
X-Atg-Version
X-TH-Server
XServer
GMS-Ver
Proxy-Firewall
X-WebServer
X-GEO
X-Phone
Processtime
Fastcgi-X-Cache-Version
X-Fastly-Backend-Reqs
X-LB-ID
X-WR-MODIFICATION
X-Host-Name
X-Ratelimit-Remaining
WZWS-RAY
X-Ratelimit-Limit
X-Vcl-Version
X-Instart-Info
X-APP
CF-Cached-On
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
X-Daa-Tunnel
Backend-Name
X-Amz-Meta-Surrogate-Control
X-Check-Cacheable
X-Upstream-HT
X-Upstream-CT
X-Backend-TTL
X-NGINX-Cache
X-Vcache
X-We-Are-Hiring
X-Nananana
Countrycode
X-Clientip
Mobile-Detection-Method
X-Worker
GW-Server
X-UE-Client-Country
X-B3-SpanId
352pxline
SN
355prline
X-Server-W
Xxline
409pxxline
219prxHost
178proxuri
X-ID
X-WA
188prxHost
189phosttRef
225prxHost
X-URL
286prxHost
X-Ratelimit-Reset
X-Hyper-Cache
X-Zone
X-Fastly-Country-Code
SS
Pics-Label
X-HS-Status
Lb
Ohc-File-Size
X-CSRF-Token
X-ServedByHost
X-IPS-LoggedIn
Version
DataCenter
FSS-Proxy
Geoip-Latitude
X-PF-Uncompressing
X-SERVER-NAME
GeoIp-Country-Code
X-HS-Combine-CSS
FSS-Cache
X-GZIP
X-Dynatrace
X-BE
X-Request-Start
Geoip-City
X-Render-Time
X-VCL-Version
URI
Esi-Enabled
X-UPSTREAM-Address
X-Contensis-Viewer-Groups
GeoIP-Country-Code
GeoIP-Latitude
GeoIP-City
X-Fpc
X-LiteSpeed-Cache-Control
Ohc-Cache-HIT
WP-Super-Cache
X-Be
X-CS
X-AssetVersion
X-Unique-Id
X-Akamai-Request-ID2
X-Via-Ucdn
X-GDPR
X-UCC
X-ZONE
X-PJAX-URL
X-Gen-Id
CDN
X-Cdn-Cache
X-FORWARDED-FOR
Accept-Language
X-HostName
Amp-Access-Control-Allow-Source-Origin
Dynatrace
X-NWS-UUID-VERIFY
X-Fastly-Cache-Hits
X-RequestId
Who
X-Html-Edge-Cache
X-Vtex-Remote-Cache
X-SRV
RequestUuid
Cneonction
X-Pf-Uncompressing
X-Vtex-Processado-Em
X-Varnish-Action
Serverid
X-Cache-Ttl
X-Via-NSCOPI
X-LiteSpeed-Tag
X-Hello
X-Reqid
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Flog
X-ABtesting
Locale
Accept-Ch
X-Cache-URL
Server-Id
A
X-Request-Url
X-Store
X-NGENIX-Cache
X-Akamai-SSL-Client-Sid
X-Serial
X-Port
X-HTML-Edge-Cache
NnCoection
Get-Access-Time
X-Dw-Trace-Id
X-Cdn-Request-ID
Ohc-Response-Time
Is-Session-Tracking
Frontcache
X-ServerName
X-EC-Lua