Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
CF-Ray
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-Request-ID
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Buckets
Upgrade
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
X-CDN
Keep-Alive
Access-Control-Expose-Headers
X-Backend
Access-Control-Max-Age
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Server
X-Pingback
X-Via
X-Proxy-Cache
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
WPE-Backend
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
P3p
Cf-Railgun
X-Amz-Version-Id
X-Swift-SaveTime
X-Swift-CacheTime
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
X-OneAgent-JS-Injection
Server-Timing
Allow
X-Ac
X-Rq
X-Node
X-Host
X-Server-Id
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
X-CST
Report-To
X-Backend-Server
X-Cloud-Trace-Context
EagleEye-TraceId
X-Application-Context
Surrogate-Control
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Url
X-Origin-Cache
X-Readtime
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Type
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
X-EdgeConnect-Origin-MEX-Latency
X-Instart-Request-ID
X-EdgeConnect-MidMile-RTT
NEL
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
Pinterest-Generated-By
X-DataDome
X-Mod-Pagespeed
X-Origin-Upstream-Status
Edge-Control
X-Px
X-Goog-Hash
X-HW
Verso
X-Server-Name
Accept-CH
X-Upstream-Env
X-Dispatcher
X-ESI
X-Cdn
MS-Author-Via
X-VARITI-CCR
AR-PoweredBy
AR-ATIME
AR-CACHE
Arc-Version
PB-RID
PB-PID
X-Mobile-Rewrite
X-MS-InvokeApp
X-GitHub-Request-Id
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-DataStream-Cache-Status
X-ORACLE-DMS-RID
X-Cached
Public-Key-Pins
X-Powered-By-Plesk
X-Version
Content-MD5
X-TTL
Charset
Service-Worker-Allowed
X-Recruiting
AR-Request-ID
RTSS
Accept-CH-Lifetime
Ar-Sid
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-Amz-Server-Side-Encryption
X-Vname
X-TtlSet
X-PC
X-Ser
X-Varnish-TTL
X-Vcap-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-Proto
X-Trace
X-Client-IP
SPRequestGuid
Nginx-Cache
X-DynaTrace-JS-Agent
X-Server-ID
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Expires
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Oracle-Dms-Rid
DynaTrace
S
X-Amz-Rid
X-Amz-Meta-S3cmd-Attrs
X-VCache
X-Fastly-Request-ID
X-SharePointHealthScore
X-Debug
TCN
X-Hits
X-Dw-Request-Base-Id
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Arr-Disable-Session-Affinity
Pinterest-Version
X-Upstream-Proxy
X-Pinterest-Rid
X-Shield-Request-Id
X-Akam-SW-Version
SPRequestDuration
SPIisLatency
X-XRDS-Location
Access-Control-Request-Method
X-Powered-CMS
X-T
X-FTR-Cache-Host
X-B3-TraceId
X-Goog-Storage-Class
X-Id
X-Litespeed-Cache
Realpath
X-Aspnet-Version
X-Acc-Meta-Resource-Type
X-NF-Request-ID
X-MSEdge-Ref
Tracecode
Front-End-Https
X-Amzn-Trace-Id
X-Webkit-CSP
X-N
Fastcgi-Cache
X-Varnish-Age
X-Dns-Prefetch-Control
X-Content-Type
X-Forwarded-For
X-Ttl
Paypal-Debug-Id
X-Upstream
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
Alternate-Protocol
X-Frontend
X-PressLabs-Stats
X-Content-Digest
X-RateLimit-Remaining
X-Logged-In
X-HS-Content-Id
X-HS-Hub-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
X-Sol
X-Middleton-Response
Response
Display
X-Middleton-Display
X-Cache-Key
X-Hostname
X-Fastcgi-Cache
X-Srv
AMP-Access-Control-Allow-Source-Origin
X-Pad
X-Accel-Expires
Host
MicrosoftSharePointTeamServices
X-SERVER
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-B3-Traceid
Server-Name
X-Kinsta-Cache
X-Analytics
Backend-Timing
X-Correlation-Id
X-Content-Options
X-AppVersion
X-LB-Cache
X-Az
X-Activity-Id
X-Debug-Info
X-Revision
X-User-Agent
X-IPLB-Instance
X-Amz-Apigw-Id
X-Amzn-RequestId
X-B3-Sampled
X-Rid
X-Cache-Hit
Surrogate-Key
FilterID
X-Cache-2
Accept-Charset
X-Grace
ServerID
Refresh
X-B
X-CF-Powered-By
Powered-By-ChinaCache
X-Accel-Buffering
X-Page-Id
X-DIS-Request-ID
X-Request-Processing-Time
X-Whom
X-Request-Received
TP-L2-Cache
TP-Cache
Server-Info
X-FastCGI-Cache
MS-CV
Host-Header
X-PHP-Backend
X-Ruxit-Js-Agent
X-Cached-By
Cache-Status
X-Varnish-Backend
X-Akamai-Edgescape
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-F-Cache
Source
X-Amz-Replication-Status
X-Cache-Action
X-App-Environment
X-TT
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Tumblr-User
X-UA-Device-Type
X-Tumblr-Pixel-0
X-Platform-Server
X-Framework
X-Mobile
X-Tumblr-Pixel
X-Cluster
X-GUploader-UploadID
X-Content-Powered-By
X-Kong-Upstream-Latency
X-Varnish-Grace
Access-Control-Allow-Method
X-Kong-Proxy-Latency
X-FW-Server
X-FW-Hash
X-FW-Static
X-FW-Type
X-Request-Guid
X-Instance
X-Drupal-Cache-Tags
X-FW-Serve
X-FB-Debug
X-Forwarded-Host
PageSpeed
X-Oneagent-Js-Injection
X-RateLimit-Limit
X-Geo-Country
Edge-Cache-Tag
X-Cache-TTL
X-Zen-Fury
X-TA-CDN-Provider
X-SS-Set-Cookie
X-Shard
X-Node-Name
X-Ezoic-Cdn
X-Handled-By
X-Magnolia-Registration
From-Origin
X-Varnish-Hostname
X-ATG-Version
X-Cache-Age
Cache-Tags
Fastly-Restarts
X-BCube-Filmed-By
X-XRDS-LOCATION
X-Cache-Control
X-AOL-HN
X-Varnish-Server
DC
X-App-Server
Cleartype
Healthy
Upgrade-Insecure-Requests
X-Cache-Rule
Payment
Server-Node
X-RequestSource
X-Signature
X-Region
Filters
X-Response-Served-From
X-B-Cache
X-WebKit-CSP-Report-Only
X-Adobe-Loc
X-Adobe-Content
X-TX-ID
Country
Actual-Object-TTL
X-Storage
X-Redis-Cache
X-UUID
X-Generated-By
X-GeoIP
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Webserver
Ms-Operation-Id
X-RTag
X-VG-WebCache
X-TT-TIMESTAMP
Retry-After
X-Jobs
X-Drupal-Cache-Contexts
X-FW-Dynamic
Cache-Tv-Group
X-Varnish-Hits
Powered
X-Cacheable-TTL
X-Locale
X-Content-Age
NGB
CACHE
GEO-INFO
ServedBy
Frame-Options
Liferay-Portal
X-Contextid
X-WA-Info
HitType
X-Rendered-As
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-IP
X-Real-IP
X-Cache-NE
X-Cache-TTL-Remaining
X-Seen-By
Eomportal-Instance
X-ProcessESI
X-RemovedCookies
X-Guploader-Uploadid
Nel
S-Cnection
X-Via-JSL
Viewport
X-Esi
X-BACKEND-TTL
X-Upgrade-Enabled
X-Cache-Operation
X-Mode
NtCoent-Length
Xserver
X-Varnish-Cache-Hits
X-Cache-Server
OT-Force-Account-Verify
X-Hl-Ver
X-Zipkin-Id
X-Detected-As
X-Device-Type
X-Is-Bot
X-Path-Route
X-Proxied
X-Proto
X-From
X-Cache-Var-Map
X-Cache-Var
Cache-Key
Load-Balancing
Meta-Geo
Cache-Hits
X-Routing-Service
X-Cache-Enabled
X-RN-RSRV
Mn-Server-Ip
X-ES-SERVER
Machine
Content-Script-Type
X-S
Content-Style-Type
X-Akamai-Transformed
X-Time
NGX
Mail-Subject
X-FC-Vary-Parameters
Property-Id
X-Environment-Context
X-FB-TRIP-ID
X-L-Path
X-Origin-Hint
X-Proxy
X-LJ-Flow-ID
TWC-Connection-Speed
L5d-Success-Class
X-Hosted-By
TWC-GeoIP-LatLong
Webcakes-Region
Webcakes-App-Version
X-AWS-Id
X-Backend-Name
X-Cache-Config
Webcakes-App-Name
We-Hiring
X-Rocket-Nginx-Bypass
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
Vix-Hermes-Req-Id
TWC-Device-Class
Access-Control-Request-Headers
X-Tb
X-VWS-Id
X-VG-TLSProxy
X-NWS-LOG-UUID
X-Viewer-Country
Datacenter
Azure-SlotName
Azure-SiteName
Azure-InstanceId
X-Labrador-Cache-Channel
X-TNCMS
Azure-Version
Azure-RegionName
DB-Nickname
X-Format
X-Tumblr-Pixel-3
Now
Origin-Cache-Control
X-Vgn-Hpd-Reason
Origin-Edge-Control
S-Rt
X-Loop
X-FW-Version
X-ServerID
X-Access
X-Section
X-Akamai-Request-ID
X-Debug-Cache
X-EIG-Tracking-Id
X-Time-Microsecs
X-NCache
X-MP-GENERATED-AT
X-Web-Node
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Origin-Response-Time
X-Birta-Served
X-BYPASS-REASON
X-Via-Fastly
X-Xfnlog-Site
Selected-FE
X-Via-CDN
X-CCM
X-Birta-Cache-Post
X-Trace-Id
X-Timing-Wait
X-Human
X-PCL
X-IP
X-JoinUs
X-OCL
X-Proxy-Build
X-ProxyCache-Key
X-ProxyCache-Status
X-Www-Served-By
X-Site-Version
X-Generated
X-Endurance-Cache-Level
LB
Uber-Trace-Id
Cache-Tag
X-Cache-Category-Id
X-Internal-Host
X-Grey
X-Cache-Remote
X-Varnish-Cacheable
Decoy-Debug-Status
X-Status
Decoy-Debug-TTL
Decoy-Debug-Key
X-VC-Cache
X-UA
X-Dynatrace-Js-Agent
X-GRACE
Served-By
X-Newrelic-App-Data
X-Rule
X-UnsetCookies
X-EdgeConnect-Cache-Status
X-Wix-Server-Artifact-Id
Release
X-TIME
X-CDN-Cache
AsisCache
X-Cluster-Node
ViewerVersion
X-Wix-Request-Id
Rt-Fastcgi-Cache
X-APP-VERSION
X-B3-Spanid
X-Origin-Host
X-Request-Time
X-Sucuri-ID
X-App-Name
X-NewRelic-App-Data
X-PERF
X-Nginx-Cache
X-ApacheServer
X-Source
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl-Cache
X-OVcl
X-Hit
X-Origin
X-Agile-Id
X-Agile-Age
X-Agile
DSUID
X-VCT
X-Ua
Cache-Name
SRV
X-App-Version
Warning
X-ElasticPress-Search
X-Origin-TTL
X-Origin-CC
User-Agent
X-VG-WebServer
X-A
Www
X-A-Ccd
X-A-Dcw
X-A-Dam
X-ARC
X-Application
UCS
X-B-Cookie
X-Cache-ASPX
X-Aed
X-Var-Ttl
X-A-Wwc
X-Accel-Expires-Debug
X-Varnish-Authentication
X-A-Dgt
Request-EU
FNAC-ModuleRouting
Fly-Request-Id
Lfy
MD5-Digest
Memcached
Fly-Cache
Ec-Rule-Version
Arc-Country
BehaviorPad-Version
Cache-Prefix
Cross-Origin-Window-Policy
Meta-Geo-Continent
Node
Thinkindot-CacheControl
Server-Surrogate-Control
Thinkindot-CacheControl-Type
Xc-Version
X-Webstats-RespID
Server-Cache-Control
Request-Time
Origin
Rendered-Blocks
Request-Country
X-Up
Thinkindot-Control
X-Cache-Info
X-Instart-Isnd
X-D
X-IN-WAF
X-IN-APIGATEWAY
X-Date
X-Logtrace-Id
X-Matched-Rule
X-NU-AKA-ACS-Version
X-NX-Host
X-Core-Value
X-NodeID
X-Mobile-URL
X-Hp-Webp
X-Debug-Cache-Expiry
X-Debug-Cookies
X-Debug-Cache-Store
Ajk
X-Debug-Log
X-Destination
X-DPWN-IS-SECURE
X-External-Request-Id
X-Gannett-Site-Version
X-Generated-In
X-Debug-Cache-Fetch
X-G
X-F5-Cache
X-PAYTM-SRV-ID
X-Platform
X-Server-Group
X-ServiceProvider
X-Sedo-Request-Id
X-Secret
X-ScT
X-SRCache-Key
X-Thinkindot-L3
X-Transaction
X-Trv-Group
X-Cache-Expires
X-Cache-Grace
X-Developer
X-S-Cookie
X-Rojux
X-CF-Lambda-Version
X-Reboot
X-Connection-Hash
X-Pubstack
X-Processor
X-Refresh
X-Region-Sid
X-Cache-Miss-From
X-Rewrite-Enabled
X-CF-Lambda-Fn
X-Request-UUID
X-Twitter-Response-Tags
On-Server
Hostname
X-Cache-Backend
X-Varnish-Ttl
User-Cache-Control
X-Device-Os
X-Dispatcher-Server
X-Distil-CS
Cache
Web-Mar-Node
True-Client-Country-4JS
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Developers
X-RateLimit-Remaining-Second
X-Request-URI
X-Servername
X-Swa-Ws
X-SN
Proxy-Connection
Pramga
Pagetype
RNT-Machine
RNT-Time
ServerName
X-RateLimit-Limit-Second
Server-Int
X-Li-Pop
X-Location
X-Distributor
X-Amzn-Remapped-Connection
X-Cdn-Srv
X-CGP
X-PHP-Host
X-Cache-Id
X-Cache-Host
X-LI-Proto
X-Origin-Expires
X-Nginx-Cache-Key
X-Micro-Cache
X-LI-UUID
X-Crawler
X-Origin-Date
X-Cache-Debug
X-Cache-Bucket
X-Amzn-Remapped-Date
X-Proxy-Cache-Status
X-Amzn-Remapped-Content-Length
Cteonnt-Length
X-Proxy-Upstream
X-Edge-Location
X-Protected-By
X-Ah-Environment
X-Block-Status
X-Policy
X-BB-ID
X-Qloud-Router
X-SIPLIST1
Backend
IsBot
Cache-Cookie-Set-From
Fastly-SWR
Kp-EeAlive
X-Ocache
CDCHOST
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Gen-Mode
Server-Host
X-Info
Ha-Gx-Prefs
X-Hash
HA-Ipaddr
X-Irp-Debug
Country-Code
X-Eu-Site
X-Epic-Correlation-Id
X-Hnp-Log
X-Li-Fabric
Fastly-SIE
Apple-News-Services-Handled
X-Key
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-LAGOON
Apple-News-Services-Host
X-WPE-Loopback-Upstream-Addr
X-FireWall-Port
Pagespeed
X-Datadome
X-C
Content-Disposition
X-Backend-State
X-Backend-Url
X-Gateway-Skip-Cache
X-Bip
X-BBXSRF
X-Page-Type
X-No-Session
X-Core-Mission
X-MSEdge-Flight
X-MSEdge-Features
Adler-Geo
AKAMAI
X-GeoIP-City
X-Cms-Context
X-Planisys-CDN-Rules
X-Cache-FS-Status
X-Planisys-CDN-Cache
X-Backend-Host
X-Geo-Header
X-Planisys-CDN-TTL
X-Amz-Meta-Cache-Control
X-ShopId
X-Shopify-Stage
X-Fastly-Cache
X-ShardId
X-Sf
Is-Eu
X-Via-Edge
X-Server-IP
SD-X-WS
X-Skip-Cache
X-Thanos
Platform
X-TrackingId
X-User
X-Sorting-Hat-ShopId
X-Variation
X-Sorting-Hat-PodId
X-S-Maxage
HTTPS
Fastly-SSL
X-TT-LOGID
X-Alternate-Cache-Key
Fastly-Soc-X-Request-Id
X-Level-Front-Cache
X-Auto-Login
X-Gateway-Cache-Key
X-Generated-On
X-Sucuri-Cache
Heartbleed
X-GeoIP-Country-Code
X-Via-SSL
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Fetched-On
Gh-Request-Id
X-Gateway-Cache-Status
X-GZip
X-Edge-IP
V-Age
X-Apm-Svc-Key
X-Varnish-Url
N-Cache
X-Server-Time
X-Cdn-Origin
Magicmarker
X-Apm-App-Name
X-Apm-Inst-Hash
X-RateLimit-Reset
X-Owner
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Sn-Servicetimems
X-Cdn-Forward
Fastly-Backend-Name
X-Real-Ip
X-ND-Cache
Server-ID
X-Geo
REQUESTUUID
X-Exp-Se
Rt-Proxy-Cache
X-NC
X-CDN-Forward
X-Node-Id
X-Org
X-Served-From
X-FPC
MIME-Version
X-B3-Parentspanid
X-Pjax-Url
X-Gdpr
VivaBuild
HostName
Viewtype
X-Load-Cache
X-Dc
X-Aicache-OS
Powered-By
X-CUA
X-Varnish-Beresp-Ttl
X-Parent-Response-Time
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
X-Git-Hash
X-Nc
Pragrma
CF-IPCountry
Section-Io-Cache
X-Passed-To-BeforeDispatch
X-Actual-URL
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-CSRF-TOKEN
X-Stale
X-Svr
PICS-Label
Memory
X-Server-By
Time
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Passed-To
X-Returned-From
X-Returned-From-DLL
X-Original-Request
X-Host-Name
X-DC
X-CACHE-KEY
X-Croise-Owner
X-VServer
Host-ID
X-HS-Cache-Config
Resin-Trace
X-Release
Cdn-Request-Time
X-Edge-Server
Cdn-Host
X-Oss-Object-Type
X-Servedbyhost
X-Wa
Mime-Version
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-WebServer
X-TH-Server
X-Daa-Tunnel
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-HT
AR-SID
X-Varnish-Beresp-TTL
X-Optimization
X-Unique-ID
X-Lb-Id
SID
X-Microcachable
ProcessTime
X-Phone
X-Upstream-HT
X-Upstream-CT
X-Newrelic-Synthetics
Fastcgi-Useragent
X-From-Cache
Cdn
X-Instart-Info
Cf-Ipcountry
CF-Cached-On
Backend-Name
X-APP
X-Req
X-V
X-Atg-Version
Odigeo-Trace-Id
X-Worker
X-Fastly-Backend-Reqs
XServer
Processtime
Proxy-Firewall
X-ID
X-HTML-Minification-Powered-By
X-Vcl-Version
188prxHost
Xxline
352pxline
355prline
178proxuri
189phosttRef
286prxHost
409pxxline
X-Server-W
225prxHost
219prxHost
X-Ratelimit-Remaining
X-B3-SpanId
X-Zone
Version
X-Ratelimit-Limit
X-WR-MODIFICATION
X-Fstrz
X-Backend-TTL
X-LB-ID
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
X-Response-By
X-IPS-LoggedIn
X-Nananana
X-Check-Cacheable
GMS-Ver
X-UPSTREAM-Address
X-Vcache
X-WA
X-Akamai-Request-ID2
X-NGINX-Cache
Esi-Enabled
Accept-Language
X-Contensis-Viewer-Groups
SN
X-AssetVersion
X-ServedByHost
X-CSRF-Token
X-VCL-Version
X-Request-Handler-Origin-Region
X-Microsite
Public-Key-Pins-Report-Only
X-Ratelimit-Reset
X-URL
WZWS-RAY
GeoIP-City
Geoip-Latitude
X-Hyper-Cache
GeoIP-Country-Code
GeoIP-Latitude
GeoIp-Country-Code
Fastcgi-X-Cache-Version
Pics-Label
X-HS-Status
DataCenter
Geoip-City
X-Be
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Amz-Meta-Surrogate-Control
X-RequestId
X-SERVER-NAME
GW-Server
X-Fastly-Country-Code
X-ZONE
X-Dynatrace
X-Clientip
X-Request-Start
Countrycode
Mobile-Detection-Method
X-Via-NSCOPI
X-Via-Ucdn
X-GEO
X-UE-Client-Country
X-Urbn-Context-Path
X-We-Are-Hiring
X-Urbn-Site-Id
Locale
X-Reqid
X-Render-Time
WP-Super-Cache
Lb
X-Cdn-Cache
X-NWS-UUID-VERIFY
X-ABtesting
X-Hello
X-GDPR
X-Flog
URI
X-LiteSpeed-Cache-Control
SS
X-BE
X-CS
X-Unique-Id
Ohc-File-Size
X-PJAX-URL
CDN
IBM-Web2-Location
Dnion-Transfer-Encoding
Dynatrace
X-GZIP
X-HostName
X-SRV
FastCGI-Cache
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
X-Generation-Time
X-Test
FSS-Proxy
Serverid
RequestUuid
X-Fpc
FSS-Cache
X-Gen-Id
Cneonction
X-HS-Combine-CSS
X-PF-Uncompressing
X-Pf-Uncompressing
X-Cache-Ttl
X-Request-Url
X-Bug-Bounty
A
Requestid
Accept-Ch
Server-Id
X-Html-Edge-Cache
X-Store
X-Fastly-Cache-Hits
X-Cluster-Name
X-LiteSpeed-Tag
X-NGENIX-Cache
X-Akamai-SSL-Client-Sid
X-PAGE-TYPE
X-SF
RequestId
X-Compress-Hint
X-Dw-Trace-Id
Frontcache
Ohc-Response-Time
Get-Access-Time
Is-Session-Tracking
NnCoection
X-HTML-Edge-Cache
X-EC-Lua
X-ServerName
Ohc-Cache-HIT
X-Cdn-Request-ID
X-Serial