Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Xss-Protection
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Request-ID
X-Cacheable
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
P3p
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
WPE-Backend
X-Varnish-Cache
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
X-Page-Speed
EagleId
X-UA-Device
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-Host
X-CST
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
X-Server-Id
Report-To
X-Type
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
NEL
X-Instart-Request-ID
X-Vhost
X-DynaTrace
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Pinterest-Generated-By
X-Origin-Upstream-Status
X-DataDome
X-Px
Edge-Control
X-Upstream-Env
X-Goog-Hash
Verso
X-Server-Name
X-ESI
Accept-CH
X-HW
X-Dispatcher
MS-Author-Via
X-VARITI-CCR
AR-ATIME
AR-CACHE
AR-PoweredBy
X-GitHub-Request-Id
X-DataStream-Cache-Status
PB-PID
X-MS-InvokeApp
X-Mobile-Rewrite
PB-RID
Arc-Version
X-ORACLE-DMS-RID
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Cached
X-Version
Charset
Content-MD5
X-Powered-By-Plesk
Public-Key-Pins
X-Recruiting
X-Server-ID
X-Dns-Prefetch-Control
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
Ar-Sid
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-Vname
X-PC
X-TtlSet
X-Ser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-TTL
X-Varnish-TTL
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Trace
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-FTR-Balancer
X-FTR-Realm
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-DC
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-FTR-Expires
X-Amz-Rid
X-VCache
X-Fastly-Request-ID
X-SharePointHealthScore
S
X-Amz-Meta-S3cmd-Attrs
X-Debug
X-Oracle-Dms-Rid
TCN
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-Hits
DynaTrace
X-TEC-API-ORIGIN
X-Dw-Request-Base-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-XRDS-Location
X-Ttl
X-Upstream-Proxy
X-Pinterest-Rid
Pinterest-Version
SPIisLatency
SPRequestDuration
X-Akam-SW-Version
Access-Control-Request-Method
X-Goog-Storage-Class
X-FTR-Cache-Host
X-T
X-Powered-CMS
Front-End-Https
X-SERVER
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Tracecode
X-MSEdge-Ref
X-Id
X-Amzn-Trace-Id
Realpath
X-Aspnet-Version
X-B3-TraceId
X-N
Fastcgi-Cache
X-Varnish-Age
Paypal-Debug-Id
X-Content-Type
X-Forwarded-For
X-Upstream
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Alternate-Protocol
Mrf-Cache-Status
X-RateLimit-Remaining
X-Frontend
X-Logged-In
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
X-Fastcgi-Cache
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Display
Fusion-Source
X-Content-Digest
X-Sol
X-Middleton-Display
Fusion-Template-Id
AMP-Access-Control-Allow-Source-Origin
X-Middleton-Response
Response
X-Hostname
X-Litespeed-Cache
X-Srv
X-Pad
X-B3-Traceid
X-Accel-Expires
X-Cache-Key
X-Kinsta-Cache
MicrosoftSharePointTeamServices
Host
Server-Name
X-Accel-Buffering
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Analytics
X-Content-Options
Backend-Timing
X-User-Agent
X-Correlation-Id
X-Debug-Info
X-LB-Cache
X-Revision
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Az
X-AppVersion
X-Activity-Id
X-Rid
X-Cdn
FilterID
Accept-Charset
X-IPLB-Instance
Refresh
X-B3-Sampled
X-Cache-2
X-Cache-Hit
Surrogate-Key
Powered-By-ChinaCache
X-B
X-DIS-Request-ID
X-Grace
X-CF-Powered-By
ServerID
X-Ruxit-Js-Agent
X-Page-Id
X-Whom
Server-Info
TP-Cache
TP-L2-Cache
X-PHP-Backend
X-Request-Processing-Time
Host-Header
X-Request-Received
MS-CV
X-FastCGI-Cache
X-Cached-By
X-Content-Security-Policy-Report-Only
X-TT
X-Kong-Proxy-Latency
X-Origin-Server
X-Kong-Upstream-Latency
X-Amz-Replication-Status
VIX-Pulpo-Node
Source
Cache-Status
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
X-App-Environment
X-Framework
X-Akamai-Edgescape
X-UA-Device-Type
X-Cache-Action
X-Cluster
X-Mobile
X-Platform-Server
Access-Control-Allow-Method
X-Content-Powered-By
X-Webkit-CSP
X-F-Cache
X-FW-Server
X-FW-Type
X-FW-Hash
X-Tumblr-User
X-Drupal-Cache-Tags
X-Request-Guid
X-FW-Static
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Varnish-Grace
X-FW-Serve
X-Instance
X-SS-Set-Cookie
X-Zen-Fury
X-FB-Debug
X-RateLimit-Limit
X-Shard
X-Ezoic-Cdn
X-Geo-Country
X-Handled-By
X-GUploader-UploadID
X-Forwarded-Host
X-Cache-TTL
X-Magnolia-Registration
Edge-Cache-Tag
From-Origin
X-Node-Name
X-ATG-Version
PageSpeed
X-Cache-Age
X-Varnish-Hostname
X-App-Server
X-Varnish-Server
Cache-Tags
DC
Cleartype
X-BCube-Filmed-By
CACHE
X-AOL-HN
X-Cache-Control
X-XRDS-LOCATION
Payment
Healthy
Upgrade-Insecure-Requests
X-RequestSource
X-WebKit-CSP-Report-Only
Filters
X-Generated-By
X-Region
X-Response-Served-From
X-TX-ID
X-Adobe-Content
Fastly-Restarts
Server-Node
X-Adobe-Loc
X-RTag
X-VG-WebCache
X-Cache-Rule
Cache-Tv-Group
X-Redis-Cache
Webserver
Ms-Operation-Id
X-TT-TIMESTAMP
X-GeoIP
Country
X-Storage
NGB
X-UUID
X-Signature
X-B-Cache
X-FW-Dynamic
Actual-Object-TTL
X-Jobs
Retry-After
X-Drupal-Cache-Contexts
X-Locale
X-Content-Age
X-Tumblr-Pixel-2
X-Cacheable-TTL
X-Tumblr-Pixel-1
X-Varnish-Hits
GEO-INFO
X-TA-CDN-Provider
ServedBy
Powered
Liferay-Portal
X-Contextid
X-Seen-By
Frame-Options
X-Wix-Server-Artifact-Id
HitType
X-Rendered-As
X-Cache-TTL-Remaining
X-Oneagent-Js-Injection
X-Via-JSL
X-Varnish-IP
X-Guploader-Uploadid
X-WA-Info
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Real-IP
X-BACKEND-TTL
Viewport
S-Cnection
X-ProcessESI
Eomportal-Instance
X-RemovedCookies
X-Upgrade-Enabled
X-Cache-NE
X-Cache-Server
NtCoent-Length
X-Mode
Xserver
Content-Style-Type
Content-Script-Type
Nel
X-Esi
Datacenter
X-GRACE
X-Cache-Config
X-Akamai-Transformed
Cache-Key
X-Time
X-Proto
X-Path-Route
Meta-Geo
Machine
Load-Balancing
X-RN-RSRV
X-Detected-As
OT-Force-Account-Verify
X-Cache-Var-Map
X-Cache-Var
X-Device-Type
X-Varnish-Cache-Hits
X-From
X-Routing-Service
X-ES-SERVER
Cache-Hits
X-Proxied
X-Is-Bot
X-Zipkin-Id
X-S
X-Hl-Ver
Mn-Server-Ip
X-L-Path
X-Environment-Context
X-Viewer-Country
TWC-Locale-Group
X-LJ-Flow-ID
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-FC-Vary-Parameters
X-Hosted-By
X-Cache-Operation
X-Tb
TWC-Device-Class
X-AWS-Id
Property-Id
TWC-Connection-Speed
Access-Control-Request-Headers
TWC-Privacy
Mail-Subject
X-Cache-Enabled
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Origin-Hint
X-VWS-Id
X-VG-TLSProxy
We-Hiring
Vix-Hermes-Req-Id
L5d-Success-Class
X-Akamai-Request-ID
X-Backend-Name
X-Time-Microsecs
X-Birta-Cache-Post
Origin-Cache-Control
X-Web-Node
Azure-RegionName
Azure-SiteName
Azure-Version
Azure-InstanceId
X-Access
Azure-SlotName
S-Rt
Origin-Edge-Control
X-Birta-Served
X-ServerID
X-Section
X-Loop
X-Debug-Cache
X-Format
X-FW-Version
X-Labrador-Cache-Channel
X-Proxy
X-FB-TRIP-ID
X-EIG-Tracking-Id
X-Origin-Response-Time
X-TNCMS
NGX
X-Endurance-Cache-Level
X-Via-CDN
X-Proxy-Build
X-OCL
X-PCL
X-Xfnlog-Site
X-Via-Fastly
Now
X-NCache
X-Varnish-Cacheable
X-Trace-Id
Selected-FE
X-IP
X-Timing-Wait
X-Human
X-CCM
Cache-Tag
DB-Nickname
X-ProxyCache-Key
X-ProxyCache-Status
X-JoinUs
X-BYPASS-REASON
X-Www-Served-By
X-Tumblr-Pixel-3
X-Status
X-Cache-Category-Id
X-Site-Version
X-Generated
X-Vgn-Hpd-Reason
X-Rocket-Nginx-Bypass
X-Grey
Decoy-Debug-TTL
Decoy-Debug-Status
X-NWS-LOG-UUID
Decoy-Debug-Key
X-MP-GENERATED-AT
Uber-Trace-Id
X-Wix-Request-Id
ViewerVersion
X-RCS-CacheZone
X-VC-Cache
X-R9-Blue-Green-Version
X-Internal-Host
Served-By
X-CDN-Cache
X-EdgeConnect-Cache-Status
X-Newrelic-App-Data
X-Dynatrace-Js-Agent
X-UA
X-Rule
X-NewRelic-App-Data
X-Cache-Remote
LB
Release
AsisCache
X-UnsetCookies
X-Origin-Host
X-Sucuri-ID
X-Cluster-Node
Rt-Fastcgi-Cache
X-TIME
X-App-Name
X-ApacheServer
Pagespeed
X-PERF
User-Agent
X-Source
X-Nginx-Cache
X-APP-VERSION
X-Agile
X-Agile-Id
X-Agile-Age
X-Request-Time
X-Ua
X-B3-Spanid
X-Datadome
Hostname
Cache-Name
X-App-Version
X-Edge-Location
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hit
X-OVcl
X-OVcl-Cache
X-Origin
X-VCT
X-Pubstack
Warning
X-Origin-TTL
X-Origin-CC
X-Edge-IP
UCS
X-A
Www
X-Aed
X-Application
X-ARC
X-B-Cookie
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
Rendered-Blocks
Ec-Rule-Version
Fly-Cache
Fly-Request-Id
MD5-Digest
Cross-Origin-Window-Policy
Cache-Prefix
Ajk
Arc-Country
BehaviorPad-Version
Meta-Geo-Continent
Node
Server-Cache-Control
Server-Surrogate-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Request-Time
Request-EU
On-Server
Origin
Request-Country
Thinkindot-Control
X-G
X-Request-UUID
X-Region-Sid
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-Processor
X-Platform
X-NodeID
X-NU-AKA-ACS-Version
X-NX-Host
X-PAYTM-SRV-ID
X-ScT
X-Secret
X-Var-Ttl
X-Up
X-Varnish-Authentication
X-VG-WebServer
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-Server-Group
X-SRCache-Key
X-Thinkindot-L3
X-Transaction
X-Mobile-URL
X-Matched-Rule
X-Date
X-D
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Core-Value
X-CF-Lambda-Version
X-Cache-ASPX
X-Cache-Expires
X-Cache-Grace
X-CF-Lambda-Fn
X-Debug-Cookies
X-Debug-Log
X-IN-APIGATEWAY
X-Hp-Webp
X-IN-WAF
X-Instart-Isnd
X-Logtrace-Id
X-Generated-In
X-Gannett-Site-Version
X-Destination
X-Developer
X-DPWN-IS-SECURE
X-External-Request-Id
X-BB-ID
X-Connection-Hash
X-Protected-By
X-Sucuri-Cache
X-Ocache
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-ElasticPress-Search
X-Cache-Backend
User-Cache-Control
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Qloud-Router
Web-Mar-Node
X-Proxy-Cache-Status
X-Policy
X-Amzn-Remapped-Date
X-Page-Type
X-Amzn-Remapped-Connection
X-PHP-Host
X-Cdn-Forward
X-RateLimit-Remaining-Second
X-Rebelmouse-Surrogate-Control
RNT-Time
Server-Host
RNT-Machine
X-Servername
X-Sf
X-ServiceProvider
Server-Int
X-Sedo-Request-Id
X-Origin-Expires
True-Client-Country-4JS
X-Reboot
X-Request-URI
SRV
X-Rebelmouse-Cache-Control
X-C
X-Device-Os
X-Dispatcher-Server
X-Developers
X-Info
X-Key
X-Irp-Debug
X-Distil-CS
X-Distributor
X-Geo-Header
X-Gen-Mode
X-Eu-Site
X-Epic-Correlation-Id
X-Hnp-Log
X-Hash
X-LAGOON
X-Li-Fabric
X-Nginx-Cache-Key
X-Cache-Host
X-Cache-Debug
X-No-Session
X-Block-Status
Proxy-Connection
X-Cache-Id
X-Cache-Miss-From
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Crawler
X-CGP
X-WPE-Loopback-Upstream-Addr
X-Origin-Date
X-Refresh
X-Cache-Info
Cache-Cookie-Set-From
Fastly-Backend-Name
Backend
IsBot
X-Varnish-Url
Magicmarker
Kp-EeAlive
Heartbleed
HA-Ipaddr
Memcached
Fastly-SWR
Lfy
CDCHOST
Cache-Cookie-Set-Lfrom
Ha-Gx-Prefs
Cache-Cookie-Set-Idcheck
X-TT-LOGID
X-Swa-Ws
X-F5-Cache
Pagetype
Country-Code
Apple-News-Services-Request-Url
Pramga
Fastly-SIE
X-SIPLIST1
X-Webstats-RespID
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-SN
N-Cache
Apple-News-Services-Handled
X-FireWall-Port
X-Varnish-Ttl
DSUID
X-CACHE-KEY
X-Wikidot-Static-Cache
X-MSEdge-Features
X-Via-SSL
X-MSEdge-Flight
X-Cache-FS-Status
X-Wikidot-Backend
Content-Disposition
X-Level-Front-Cache
X-Fetched-On
X-GeoIP-City
X-Generated-On
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-GeoIP-Country-Code
Adler-Geo
X-Core-Mission
X-Cms-Context
X-Location
X-Cache-Bucket
AKAMAI
X-Micro-Cache
Fastly-SSL
X-Thanos
X-Sorting-Hat-ShopId
X-Gateway-Cache-Status
Is-Eu
HTTPS
X-TrackingId
X-Ah-Environment
X-Sorting-Hat-PodId
X-S-Maxage
Platform
X-Server-IP
X-Shopify-Stage
SD-X-WS
X-Skip-Cache
X-ShopId
X-User
X-ShardId
X-Amzn-Remapped-Content-Length
X-Variation
X-Via-Edge
X-Backend-State
X-BBXSRF
X-Amz-Meta-Cache-Control
X-Real-Ip
Fastly-Soc-X-Request-Id
X-Bip
X-Alternate-Cache-Key
Cteonnt-Length
FNAC-ModuleRouting
ServerName
X-Node-Id
X-Fastly-Cache
X-Cdn-Srv
X-Owner
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Server-Time
X-Planisys-CDN-Cache
X-Backend-Host
X-Auto-Login
X-Backend-Url
X-GZip
X-Varnish-Beresp-Ttl
Server-ID
X-RateLimit-Reset
Gh-Request-Id
X-Org
Powered-By
X-CUA
Section-Io-Cache
X-CDN-Forward
X-Nc
V-Age
REQUESTUUID
X-Apm-Inst-Hash
X-FPC
Pragrma
X-Pjax-Url
X-Load-Cache
X-Apm-Svc-Key
X-Apm-App-Name
MIME-Version
VivaBuild
X-Sn-Servicetimems
Viewtype
X-Cdn-Origin
Cache
X-Dc
X-NC
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Original-Request
X-Svr
X-Returned-From
X-Stale
X-Passed-To
X-Actual-URL
Fastcgi-Useragent
X-Exp-Se
Rt-Proxy-Cache
X-Geo
X-Returned-From-PostProcessResponse
X-Server-By
X-Parent-Response-Time
X-Aicache-OS
X-Returned-From-DLL
X-ND-Cache
X-Returned-From-BeforeDispatch
Host-ID
X-Gdpr
X-HS-Cache-Config
X-Served-From
X-VServer
X-Croise-Owner
Cdn-Host
X-Ua-Device
Cdn-Request-Time
X-CSRF-TOKEN
HostName
X-Edge-Server
X-Unique-ID
X-B3-Parentspanid
Memory
X-Microcachable
PICS-Label
Time
X-DC
Mime-Version
SID
X-Oss-Hash-Crc64ecma
Wxu-Next-Region
X-Oss-Server-Time
Wxu-Next-Hostname
Wxu-Next-Commit
X-Wa
X-Oss-Storage-Class
X-Git-Hash
X-Servedbyhost
X-Oss-Request-Id
Resin-Trace
X-Oss-Object-Type
ProcessTime
X-Newrelic-Synthetics
X-V
X-Tb-Optimization-Total-Bytes-Saved
CF-IPCountry
X-From-Cache
X-Req
X-Optimization
X-ID
X-Cache-HT
AR-SID
Cf-Ipcountry
Odigeo-Trace-Id
Cdn
X-Lb-Id
X-Release
X-Host-Name
X-WebServer
X-TH-Server
X-HTML-Minification-Powered-By
X-Varnish-Beresp-TTL
CF-Cached-On
X-Fstrz
X-Phone
X-Atg-Version
X-Daa-Tunnel
X-Instart-Info
Processtime
XServer
X-APP
Proxy-Firewall
X-Response-By
X-Upstream-HT
Public-Key-Pins-Report-Only
X-Upstream-CT
X-WR-MODIFICATION
Backend-Name
X-LB-ID
X-Vcl-Version
GMS-Ver
X-Check-Cacheable
X-Ratelimit-Remaining
X-Ratelimit-Limit
WZWS-RAY
X-Worker
X-Fastly-Backend-Reqs
X-CACHE-AGE
X-GEO
X-CLOUD-TRACE-CONTEXT
X-Zone
Fastcgi-X-Cache-Version
Xxline
X-Server-W
225prxHost
188prxHost
219prxHost
189phosttRef
178proxuri
X-B3-SpanId
409pxxline
352pxline
286prxHost
355prline
X-Backend-TTL
X-WA
X-Nananana
X-IPS-LoggedIn
X-Vcache
X-NGINX-Cache
X-Amz-Meta-Surrogate-Control
Version
Pics-Label
X-Ratelimit-Reset
Countrycode
GW-Server
X-UE-Client-Country
Mobile-Detection-Method
X-Clientip
X-We-Are-Hiring
X-CSRF-Token
X-ServedByHost
X-URL
X-HS-Status
Lb
Esi-Enabled
SN
X-Fastly-Country-Code
SS
X-UPSTREAM-Address
GeoIp-Country-Code
X-Hyper-Cache
Geoip-Latitude
WP-Super-Cache
Ohc-File-Size
DataCenter
Geoip-City
X-Contensis-Viewer-Groups
X-Akamai-Request-ID2
X-AssetVersion
X-SERVER-NAME
X-VCL-Version
X-GZIP
X-SRV
X-Dynatrace
Accept-Language
X-HS-Combine-CSS
X-BE
GeoIP-Country-Code
GeoIP-City
FSS-Cache
GeoIP-Latitude
FSS-Proxy
X-Be
X-PF-Uncompressing
X-Request-Start
URI
X-Via-Ucdn
X-Render-Time
Serverid
X-NWS-UUID-VERIFY
X-Vtex-Remote-Cache
X-GDPR
X-CS
X-Vtex-Processado-Em
X-RequestId
X-LiteSpeed-Cache-Control
X-Unique-Id
X-Via-NSCOPI
X-Reqid
X-Fpc
X-Urbn-Context-Path
X-Urbn-Site-Id
Ohc-Cache-HIT
Locale
X-Gen-Id
X-PJAX-URL
CDN
X-ZONE
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
Dynatrace
FastCGI-Cache
X-HostName
X-Flog
X-ABtesting
X-Hello
X-Pf-Uncompressing
X-UCC
X-Fastly-Cache-Hits
RequestUuid
X-Html-Edge-Cache
Cneonction
X-Cdn-Cache
X-Cache-Ttl
X-Generation-Time
X-Request-Url
X-Varnish-Action
Dnion-Transfer-Encoding
IBM-Web2-Location
X-LiteSpeed-Tag
Accept-Ch
A
X-Store
Who
Server-Id
X-Akamai-SSL-Client-Sid
Frontcache
NnCoection
X-Serial
X-ServerName
X-Dw-Trace-Id
X-HTML-Edge-Cache
X-Cdn-Request-ID
Get-Access-Time
Is-Session-Tracking
X-Port
X-EC-Lua
X-Cache-URL
Ohc-Response-Time