Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Hacker
X-Varnish-Cache
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Nginx-Cache-Status
WPE-Backend
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
P3p
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Server-Timing
Allow
X-Ac
X-Rq
X-Node
X-Host
Content-Location
X-CST
Feature-Policy
X-Server-Id
X-Cnection
X-Response-Time
Report-To
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
EagleEye-TraceId
Surrogate-Control
X-Type
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Cache-Lookup
X-Country-Code
Rating
NEL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
Pinterest-Generated-By
X-Mod-Pagespeed
X-Origin-Upstream-Status
X-DataDome
X-Px
Edge-Control
X-Upstream-Env
X-Goog-Hash
Verso
Accept-CH
X-HW
X-Dispatcher
X-Server-Name
X-ORACLE-DMS-RID
MS-Author-Via
X-ESI
X-VARITI-CCR
AR-PoweredBy
AR-CACHE
AR-ATIME
X-GitHub-Request-Id
X-MS-InvokeApp
PB-PID
PB-RID
X-Mobile-Rewrite
Arc-Version
X-DataStream-Cache-Status
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Cached
X-Version
Charset
Content-MD5
X-Powered-By-Plesk
Public-Key-Pins
X-TTL
X-Recruiting
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-PC
X-Vname
X-TtlSet
X-Server-ID
X-Ser
Ar-Sid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Varnish-TTL
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Trace
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Realm
X-FTR-Balancer
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-FTR-Expires
X-Amz-Rid
X-VCache
S
X-Amz-Meta-S3cmd-Attrs
X-SharePointHealthScore
X-Fastly-Request-ID
X-XRDS-Location
X-Debug
TCN
Arr-Disable-Session-Affinity
DynaTrace
X-Hits
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Shield-Request-Id
X-Dw-Request-Base-Id
Pinterest-Version
SPRequestDuration
SPIisLatency
X-Pinterest-Rid
X-Upstream-Proxy
X-Akam-SW-Version
X-Oracle-Dms-Rid
Access-Control-Request-Method
X-FTR-Cache-Host
X-SERVER
X-Powered-CMS
X-Goog-Storage-Class
X-T
Front-End-Https
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Realpath
Tracecode
X-MSEdge-Ref
X-Amzn-Trace-Id
X-Id
X-N
Fastcgi-Cache
X-Dns-Prefetch-Control
X-Varnish-Age
Paypal-Debug-Id
X-Content-Type
X-B3-TraceId
X-Forwarded-For
X-Ttl
X-Upstream
Mrf-Cache-Status
Alternate-Protocol
MRF-Tech
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-RateLimit-Remaining
X-Frontend
X-Logged-In
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
X-Content-Digest
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Display
X-Sol
X-Middleton-Display
X-Litespeed-Cache
Response
X-Middleton-Response
X-Hostname
X-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-B3-Traceid
X-Cache-Key
X-Accel-Expires
X-Srv
X-Pad
X-Kinsta-Cache
MicrosoftSharePointTeamServices
Host
Server-Name
X-Cdn
X-Accel-Buffering
Backend-Timing
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Analytics
X-Content-Options
X-Correlation-Id
X-User-Agent
X-LB-Cache
X-Debug-Info
X-Revision
X-Amzn-RequestId
X-Rid
X-Amz-Apigw-Id
Refresh
X-B3-Sampled
X-IPLB-Instance
X-Az
X-Activity-Id
X-AppVersion
Accept-Charset
X-Cache-Hit
X-Cache-2
X-Grace
FilterID
Surrogate-Key
X-B
Powered-By-ChinaCache
X-DIS-Request-ID
X-CF-Powered-By
ServerID
X-Page-Id
X-Whom
Server-Info
X-FastCGI-Cache
TP-Cache
TP-L2-Cache
Host-Header
X-PHP-Backend
X-Request-Received
X-Request-Processing-Time
X-Webkit-CSP
MS-CV
X-Amz-Replication-Status
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-App-Environment
X-Kong-Upstream-Latency
VIX-Pulpo-Node
X-Varnish-Backend
Source
X-Cached-By
VIX-Pulpo-Upstream-Status
X-Kong-Proxy-Latency
X-Origin-Server
Cache-Status
X-Cluster
X-Framework
X-UA-Device-Type
X-Akamai-Edgescape
X-Cache-Action
X-TT
X-Platform-Server
X-Varnish-Grace
X-Tumblr-User
X-Tumblr-Pixel
Access-Control-Allow-Method
X-F-Cache
X-Content-Powered-By
X-GUploader-UploadID
X-Mobile
X-Tumblr-Pixel-0
X-FW-Server
X-FW-Hash
X-Drupal-Cache-Tags
X-FW-Static
X-FW-Type
X-FW-Serve
X-Request-Guid
X-FB-Debug
X-Instance
X-SS-Set-Cookie
X-Zen-Fury
X-RateLimit-Limit
X-Geo-Country
X-Ezoic-Cdn
X-Forwarded-Host
X-Shard
X-Magnolia-Registration
X-Handled-By
Edge-Cache-Tag
From-Origin
X-Node-Name
PageSpeed
X-Cache-TTL
X-ATG-Version
X-Varnish-Hostname
X-Cache-Age
X-Varnish-Server
X-App-Server
Cache-Tags
DC
Cleartype
X-BCube-Filmed-By
X-AOL-HN
X-Cache-Control
Upgrade-Insecure-Requests
Healthy
Payment
X-Region
Filters
X-Response-Served-From
X-RequestSource
X-WebKit-CSP-Report-Only
X-Generated-By
Fastly-Restarts
X-Cache-Rule
X-TX-ID
Server-Node
X-Adobe-Content
X-Adobe-Loc
Cache-Tv-Group
Webserver
X-UUID
X-GeoIP
Country
X-VG-WebCache
CACHE
X-TT-TIMESTAMP
X-Signature
X-Redis-Cache
X-B-Cache
X-Storage
X-RTag
X-Tumblr-Pixel-1
X-Drupal-Cache-Contexts
Actual-Object-TTL
X-Tumblr-Pixel-2
Retry-After
Ms-Operation-Id
X-Jobs
X-FW-Dynamic
X-TA-CDN-Provider
X-Content-Age
X-XRDS-LOCATION
NGB
X-Locale
X-Cacheable-TTL
X-Varnish-Hits
GEO-INFO
Powered
ServedBy
Liferay-Portal
X-Esi
Frame-Options
X-Contextid
X-Oneagent-Js-Injection
HitType
X-Seen-By
X-Rendered-As
X-Cache-TTL-Remaining
X-Varnish-IP
X-WA-Info
X-Wix-Server-Artifact-Id
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Via-JSL
X-BACKEND-TTL
S-Cnection
Viewport
X-Real-IP
X-Guploader-Uploadid
X-ProcessESI
X-RemovedCookies
X-Upgrade-Enabled
Eomportal-Instance
X-Cache-NE
X-Mode
X-Time
Content-Style-Type
Content-Script-Type
Xserver
X-Cache-Server
X-Akamai-Transformed
Datacenter
NtCoent-Length
X-Is-Bot
X-Hl-Ver
X-From
X-ES-SERVER
X-Zipkin-Id
X-Path-Route
X-RN-RSRV
X-Proxied
X-Proto
X-Device-Type
X-Routing-Service
Cache-Hits
Cache-Key
OT-Force-Account-Verify
X-Cache-Operation
X-Varnish-Cache-Hits
Load-Balancing
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
X-Cache-Enabled
Mn-Server-Ip
X-Detected-As
Machine
X-Cache-Config
X-S
Access-Control-Request-Headers
X-AWS-Id
L5d-Success-Class
Mail-Subject
NGX
X-VG-TLSProxy
X-Viewer-Country
X-Origin-Hint
X-Environment-Context
X-VWS-Id
Property-Id
X-FB-TRIP-ID
TWC-Connection-Speed
We-Hiring
Vix-Hermes-Req-Id
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Privacy
TWC-Locale-Group
X-FC-Vary-Parameters
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Proxy
X-Tb
X-L-Path
X-LJ-Flow-ID
X-Hosted-By
X-TNCMS
X-Debug-Cache
Origin-Cache-Control
Azure-Version
X-Time-Microsecs
Azure-SlotName
X-EIG-Tracking-Id
X-Loop
Azure-InstanceId
X-Labrador-Cache-Channel
X-Newrelic-App-Data
X-Access
Azure-SiteName
X-ServerID
X-Format
X-Akamai-Request-ID
X-Birta-Cache-Post
X-FW-Version
X-Backend-Name
X-Birta-Served
S-Rt
X-Endurance-Cache-Level
Azure-RegionName
X-Section
X-Origin-Response-Time
X-Web-Node
Origin-Edge-Control
X-ProxyCache-Status
Cache-Tag
Selected-FE
X-Proxy-Build
X-ProxyCache-Key
X-CCM
X-OCL
X-IP
X-Rocket-Nginx-Bypass
X-NCache
X-RCS-CacheZone
X-Via-Fastly
X-BYPASS-REASON
X-Xfnlog-Site
Now
DB-Nickname
X-Via-CDN
X-PCL
X-Timing-Wait
X-Tumblr-Pixel-3
X-JoinUs
X-Trace-Id
X-Varnish-Cacheable
X-Grey
Uber-Trace-Id
X-Cache-Category-Id
X-Human
Decoy-Debug-Status
X-Generated
Decoy-Debug-Key
X-Status
X-Vgn-Hpd-Reason
X-Www-Served-By
Decoy-Debug-TTL
X-Site-Version
X-GRACE
X-MP-GENERATED-AT
X-NWS-LOG-UUID
X-Dynatrace-Js-Agent
Served-By
X-VC-Cache
X-Internal-Host
X-Wix-Request-Id
X-R9-Blue-Green-Version
ViewerVersion
X-Rule
X-Cache-Remote
X-EdgeConnect-Cache-Status
X-CDN-Cache
LB
X-UA
X-UnsetCookies
AsisCache
X-Origin-Host
Release
X-Sucuri-ID
Nel
Rt-Fastcgi-Cache
X-Cluster-Node
X-APP-VERSION
X-App-Name
X-B3-Spanid
X-PERF
X-TIME
X-NewRelic-App-Data
X-ApacheServer
X-Datadome
X-Ua
User-Agent
X-Nginx-Cache
X-Source
X-Request-Time
X-Agile
X-Agile-Id
X-Agile-Age
Cache-Name
Pagespeed
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl-Cache
X-OVcl
X-Hit
X-Edge-Location
X-VCT
Warning
X-App-Version
X-Origin-CC
X-Pubstack
X-Origin-TTL
X-Rojux
Request-Time
Request-Country
Request-EU
X-Rewrite-Enabled
Server-Cache-Control
Server-Surrogate-Control
Thinkindot-Control
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
X-A
Thinkindot-CacheControl-Type
UCS
Www
Thinkindot-CacheControl
Xc-Version
Cross-Origin-Window-Policy
Ec-Rule-Version
Fly-Cache
Fly-Request-Id
Cache-Prefix
BehaviorPad-Version
X-Sucuri-Cache
Ajk
Arc-Country
X-Server-Group
Lfy
X-ScT
On-Server
X-A-Wwc
X-S-Cookie
Node
X-Secret
MD5-Digest
Memcached
Meta-Geo-Continent
Rendered-Blocks
X-Aed
X-G
X-Gannett-Site-Version
X-Generated-In
X-Hp-Webp
X-Region-Sid
X-F5-Cache
X-Developer
X-DPWN-IS-SECURE
X-External-Request-Id
X-IN-APIGATEWAY
X-IN-WAF
X-NU-AKA-ACS-Version
X-NX-Host
X-Processor
X-PAYTM-SRV-ID
X-NodeID
X-Mobile-URL
X-Instart-Isnd
X-Logtrace-Id
X-Matched-Rule
X-Destination
X-Debug-Log
X-Cache-ASPX
X-Cache-Expires
X-Cache-Grace
X-Cache-Info
X-BB-ID
X-B-Cookie
X-Platform
X-Application
X-ARC
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Debug-Cookies
X-Date
X-D
X-Request-UUID
X-Connection-Hash
X-Core-Value
X-Accel-Expires-Debug
Origin
X-Varnish-Authentication
X-Thinkindot-L3
X-VG-WebServer
X-Var-Ttl
X-Transaction
X-Twitter-Response-Tags
X-Up
X-Trv-Group
X-Edge-IP
X-Webstats-RespID
Hostname
X-SRCache-Key
X-Ocache
X-Cache-Backend
X-ElasticPress-Search
X-Varnish-Ttl
X-Protected-By
SRV
User-Cache-Control
DSUID
X-C
X-Geo-Header
X-Varnish-Url
RNT-Time
RNT-Machine
X-Gen-Mode
X-Block-Status
X-Hnp-Log
X-Cache-Debug
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Cache-Bucket
X-Reboot
X-Hash
X-Cache-Host
Pagetype
Proxy-Connection
X-Cache-Id
X-Refresh
X-Developers
X-Device-Os
X-Dispatcher-Server
X-Sedo-Request-Id
X-Amzn-Remapped-Connection
X-Ah-Environment
X-Crawler
X-Amzn-Remapped-Date
X-Distil-CS
X-Distributor
True-Client-Country-4JS
X-Cache-Miss-From
X-CGP
Server-Int
Web-Mar-Node
Magicmarker
X-Request-URI
X-Epic-Correlation-Id
X-Eu-Site
Server-Host
N-Cache
X-Sf
X-Info
X-SIPLIST1
X-RateLimit-Limit-Second
X-Proxy-Upstream
Country-Code
X-Servername
X-LI-UUID
X-Origin-Date
X-Proxy-Cache-Status
CDCHOST
X-Nginx-Cache-Key
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Origin-Expires
Apple-News-Services-Handled
Apple-News-Services-Request-Url
X-No-Session
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Backend
Fastly-Backend-Name
X-ServiceProvider
X-PHP-Host
X-RateLimit-Remaining-Second
HA-Ipaddr
Ha-Gx-Prefs
X-TT-LOGID
X-LAGOON
X-Real-Ip
Kp-EeAlive
IsBot
X-Irp-Debug
X-Key
Fastly-SIE
X-Policy
X-LI-Proto
X-Li-Fabric
X-Li-Pop
Fastly-SWR
X-Page-Type
X-SN
Cteonnt-Length
X-Varnish-Beresp-Grace
X-WPE-Loopback-Upstream-Addr
X-FireWall-Port
X-Varnish-Beresp-Status
FNAC-ModuleRouting
X-Core-Mission
X-Via-SSL
X-Qloud-Router
X-Cms-Context
ServerName
X-MSEdge-Features
X-GeoIP-City
X-Generated-On
X-Gateway-Skip-Cache
X-GeoIP-Country-Code
X-Level-Front-Cache
X-Cache-FS-Status
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Gateway-Cache-Status
X-Fastly-Cache
X-Location
X-Fetched-On
X-Cdn-Srv
X-Gateway-Cache-Key
X-MSEdge-Flight
X-Micro-Cache
X-Amzn-Remapped-Content-Length
HTTPS
X-Swa-Ws
X-Thanos
Fastly-Soc-X-Request-Id
AKAMAI
X-Amz-Meta-Cache-Control
Fastly-SSL
X-User
X-ShopId
X-ShardId
X-TrackingId
X-Variation
Pramga
SD-X-WS
X-Via-Edge
X-S-Maxage
Content-Disposition
Platform
Adler-Geo
X-Alternate-Cache-Key
X-Server-IP
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Backend-State
Heartbleed
Is-Eu
X-Bip
X-BBXSRF
X-Skip-Cache
X-Cdn-Forward
X-Shopify-Stage
X-GZip
X-RateLimit-Reset
X-Backend-Host
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Backend-Url
X-Planisys-CDN-Cache
X-Auto-Login
X-Owner
X-Node-Id
Cache
X-Server-Time
MIME-Version
Server-ID
X-NC
Gh-Request-Id
X-CDN-Forward
X-Varnish-Beresp-Ttl
Powered-By
X-Sn-Servicetimems
X-CUA
X-Apm-Inst-Hash
X-Apm-App-Name
X-Org
X-Apm-Svc-Key
X-FPC
X-Cdn-Origin
V-Age
X-CACHE-KEY
Section-Io-Cache
AR-SID
HostName
Pragrma
Rt-Proxy-Cache
X-Exp-Se
VivaBuild
X-Geo
Viewtype
X-ND-Cache
REQUESTUUID
X-Load-Cache
X-Svr
X-Passed-To-PostProcessResponse
X-Actual-URL
X-Original-Request
X-Stale
X-Served-From
X-Passed-To-DLL
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Aicache-OS
X-Server-By
X-Pjax-Url
X-Returned-From-PostProcessResponse
X-Gdpr
X-Passed-To
X-Passed-To-BeforeDispatch
X-Returned-From
X-Parent-Response-Time
X-B3-Parentspanid
X-Nc
X-CSRF-TOKEN
X-HS-Cache-Config
X-Dc
X-DC
Host-ID
X-VServer
X-Croise-Owner
Fastcgi-Useragent
PICS-Label
Time
X-Edge-Server
Cdn-Host
Cdn-Request-Time
Memory
X-Unique-ID
X-Servedbyhost
X-Git-Hash
X-Wa
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Microcachable
CF-IPCountry
X-Oss-Object-Type
Resin-Trace
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
SID
X-Oss-Hash-Crc64ecma
ProcessTime
X-Tb-Optimization-Total-Bytes-Saved
X-V
Mime-Version
X-Optimization
X-Newrelic-Synthetics
X-ID
X-Cache-HT
X-Req
X-From-Cache
X-Release
X-Host-Name
X-Lb-Id
X-TH-Server
X-WebServer
Odigeo-Trace-Id
Cf-Ipcountry
X-Varnish-Beresp-TTL
X-HTML-Minification-Powered-By
Cdn
X-Phone
X-Daa-Tunnel
X-Atg-Version
Proxy-Firewall
XServer
X-Fstrz
X-APP
X-Instart-Info
X-Upstream-CT
X-Upstream-HT
CF-Cached-On
X-LB-ID
X-Fastly-Backend-Reqs
X-Response-By
Processtime
X-WR-MODIFICATION
X-SERVER-NAME
Backend-Name
X-Ratelimit-Remaining
Public-Key-Pins-Report-Only
X-Ratelimit-Limit
X-Worker
GMS-Ver
X-Vcl-Version
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
188prxHost
189phosttRef
WZWS-RAY
178proxuri
219prxHost
X-Server-W
409pxxline
X-Nananana
286prxHost
X-Check-Cacheable
355prline
225prxHost
X-B3-SpanId
352pxline
Xxline
X-Zone
X-IPS-LoggedIn
X-Backend-TTL
X-GEO
X-NGINX-Cache
X-Vcache
Fastcgi-X-Cache-Version
Version
X-Ratelimit-Reset
X-URL
X-WA
X-HS-Status
X-Amz-Meta-Surrogate-Control
Lb
X-We-Are-Hiring
X-Clientip
X-ServedByHost
Mobile-Detection-Method
SN
Countrycode
Pics-Label
X-UE-Client-Country
GW-Server
Esi-Enabled
X-UPSTREAM-Address
X-VCL-Version
X-CSRF-Token
X-Hyper-Cache
DataCenter
GeoIp-Country-Code
GeoIP-Latitude
Geoip-Latitude
GeoIP-City
X-Contensis-Viewer-Groups
X-Fastly-Country-Code
GeoIP-Country-Code
SS
X-Akamai-Request-ID2
X-AssetVersion
Ohc-File-Size
X-SRV
X-Dynatrace
Accept-Language
X-Request-Start
X-Render-Time
Geoip-City
X-BE
X-Via-Ucdn
WP-Super-Cache
Serverid
X-GZIP
X-CS
X-Vtex-Processado-Em
X-LiteSpeed-Cache-Control
X-PJAX-URL
X-ZONE
FSS-Cache
X-HS-Combine-CSS
X-Vtex-Remote-Cache
FSS-Proxy
X-Be
X-RequestId
X-NWS-UUID-VERIFY
X-PF-Uncompressing
X-GDPR
X-Cache-Ttl
URI
X-Unique-Id
X-Reqid
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Gen-Id
X-Cdn-Cache
X-Via-NSCOPI
CDN
FastCGI-Cache
Dynatrace
X-HostName
Amp-Access-Control-Allow-Source-Origin
X-FORWARDED-FOR
X-Flog
Cneonction
X-ABtesting
Ohc-Cache-HIT
X-Fastly-Cache-Hits
X-Fpc
RequestUuid
X-Hello
X-Pf-Uncompressing
X-Request-Handler-Origin-Region
X-Microsite
X-LiteSpeed-Tag
X-Request-Url
Server-Id
X-UCC
A
Accept-Ch
X-Html-Edge-Cache
X-Generation-Time
X-Store
IBM-Web2-Location
Dnion-Transfer-Encoding
X-Akamai-SSL-Client-Sid
X-Dw-Trace-Id
Requestid
X-Test
Who
Is-Session-Tracking
Ohc-Response-Time
Get-Access-Time
X-Port
X-Varnish-Action
X-Serial
Frontcache
X-ServerName
NnCoection
X-Cdn-Request-ID
X-HTML-Edge-Cache
X-EC-Lua