Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
ETag
Link
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
CF-Ray
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
X-CDN
Upgrade
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Robots-Tag
WPE-Backend
X-Server-Powered-By
X-Nginx-Cache-Status
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-Device
Allow
Ali-Swift-Global-Savetime
Server-Timing
X-CST
X-Ac
X-Type
X-Rq
X-Node
X-Host
Feature-Policy
Content-Location
X-Server-Id
X-Response-Time
X-Cnection
Report-To
X-Backend-Server
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Url
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
NEL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Upstream-Env
X-Dns-Prefetch-Control
X-Ruxit-JS-Agent
Pinterest-Generated-By
X-Mod-Pagespeed
X-Vhost
X-DynaTrace
X-Origin-Upstream-Status
X-Px
X-DataDome
Edge-Control
X-Goog-Hash
Verso
X-Server-Name
X-ESI
Accept-CH
X-Dispatcher
X-HW
X-GitHub-Request-Id
X-ORACLE-DMS-RID
MS-Author-Via
Charset
X-VARITI-CCR
Arc-Version
PB-RID
X-Mobile-Rewrite
PB-PID
X-DataStream-Cache-Status
X-MS-InvokeApp
X-GoogleNews-Bot
AR-PoweredBy
AR-CACHE
X-Cdn-Fetch
X-Kinja
X-Exp-Variant
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
AR-ATIME
X-Kinja-Revision
X-Exp-Id
X-Version
X-Cached
Content-MD5
X-Powered-By-Plesk
X-Recruiting
Public-Key-Pins
Service-Worker-Allowed
Accept-CH-Lifetime
X-D2id
AR-Request-ID
X-Navigation-Version
X-Abt-Application-Version
RTSS
X-Vname
X-TtlSet
X-PC
Ar-Sid
X-TTL
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ser
X-Server-ID
X-Varnish-TTL
X-Trace
X-Forwarded-Proto
SPRequestGuid
X-Client-IP
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-DynaTrace-JS-Agent
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Realm
X-FTR-Cache-Status
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-SharePointHealthScore
X-FTR-Expires
X-Amz-Rid
X-Fastly-Request-ID
Nginx-Cache
X-VCache
S
X-Amz-Meta-S3cmd-Attrs
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-XRDS-Location
TCN
X-Debug
X-Upstream-Proxy
X-Pinterest-Rid
Pinterest-Version
X-Dw-Request-Base-Id
X-Hits
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
SPIisLatency
SPRequestDuration
X-Oracle-Dms-Rid
X-Id
DynaTrace
X-Akam-SW-Version
X-SERVER
Front-End-Https
Access-Control-Request-Method
X-Goog-Storage-Class
X-FTR-Cache-Host
X-T
X-Ttl
X-B3-TraceId
X-Powered-CMS
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Realpath
Paypal-Debug-Id
Tracecode
X-Amzn-Trace-Id
X-MSEdge-Ref
Fastcgi-Cache
X-Varnish-Age
X-N
X-Forwarded-For
X-Content-Type
Alternate-Protocol
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-RateLimit-Remaining
X-Upstream
X-Frontend
X-Middleton-Display
Display
X-Sol
Fusion-Component-Id
Fusion-Content-Source
X-Logged-In
X-PressLabs-Stats
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
X-HS-Hub-Id
X-HS-Content-Id
X-Content-Digest
AMP-Access-Control-Allow-Source-Origin
X-Accel-Buffering
X-Middleton-Response
Response
X-Litespeed-Cache
X-Hostname
X-Srv
X-Kinsta-Cache
X-Fastcgi-Cache
X-Cache-Key
X-Pad
X-Accel-Expires
Server-Name
MicrosoftSharePointTeamServices
X-B3-Traceid
X-User-Agent
X-Content-Options
Host
Refresh
X-Analytics
Backend-Timing
X-Correlation-Id
X-DIS-Request-ID
X-Revision
X-Rid
X-LB-Cache
X-Debug-Info
X-Az
X-AppVersion
X-IPLB-Instance
X-Activity-Id
FilterID
X-Amz-Apigw-Id
X-Amzn-RequestId
X-B
Accept-Charset
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Cache-Hit
X-B3-Sampled
X-CF-Powered-By
X-Cache-2
Powered-By-ChinaCache
X-FastCGI-Cache
Surrogate-Key
ServerID
X-Grace
X-Page-Id
X-Whom
Server-Info
X-PHP-Backend
TP-L2-Cache
X-Webkit-CSP
TP-Cache
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
X-Request-Received
MS-CV
X-Request-Processing-Time
Host-Header
X-Origin-Server
X-TT
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
Source
VIX-Pulpo-Node
X-Amz-Replication-Status
X-Akamai-Edgescape
X-Tumblr-Pixel-0
X-Tumblr-User
X-UA-Device-Type
X-Tumblr-Pixel
X-F-Cache
X-Cache-Action
X-Cluster
X-Framework
X-Mobile
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Server
X-RateLimit-Limit
X-FW-Type
X-Platform-Server
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-App-Environment
X-Drupal-Cache-Tags
X-Content-Powered-By
X-Instance
Access-Control-Allow-Method
Cache-Status
X-Varnish-Grace
X-Request-Guid
X-Cached-By
X-Handled-By
X-Geo-Country
X-SS-Set-Cookie
X-Zen-Fury
X-Magnolia-Registration
X-FB-Debug
X-Shard
X-Ezoic-Cdn
X-Cache-TTL
Edge-Cache-Tag
X-Forwarded-Host
X-GUploader-UploadID
X-ATG-Version
From-Origin
CACHE
X-App-Server
X-Cache-Age
DC
X-Wix-Server-Artifact-Id
X-Varnish-Server
PageSpeed
X-Node-Name
Cleartype
X-Varnish-Hostname
Cache-Tags
X-AOL-HN
X-BCube-Filmed-By
X-Cache-Control
Payment
X-Region
X-RequestSource
Filters
X-WebKit-CSP-Report-Only
X-Response-Served-From
X-Generated-By
X-Adobe-Content
Healthy
X-TX-ID
X-Signature
X-Adobe-Loc
Upgrade-Insecure-Requests
X-GeoIP
X-B-Cache
X-Tumblr-Pixel-1
Ms-Operation-Id
X-TT-TIMESTAMP
X-RTag
X-VG-WebCache
X-UUID
Country
Cache-Tv-Group
X-FW-Dynamic
NGB
Webserver
X-Tumblr-Pixel-2
X-Storage
GEO-INFO
X-Drupal-Cache-Contexts
X-Seen-By
X-Jobs
Server-Node
X-Redis-Cache
Retry-After
X-XRDS-LOCATION
X-Cacheable-TTL
ServedBy
X-Content-Age
X-Varnish-Hits
Liferay-Portal
Actual-Object-TTL
X-Locale
X-Cache-Rule
X-Via-JSL
X-Contextid
Fastly-Restarts
X-Rendered-As
X-Oneagent-Js-Injection
HitType
Frame-Options
Powered
X-Cache-TTL-Remaining
X-Guploader-Uploadid
X-Varnish-IP
X-Real-IP
X-BACKEND-TTL
S-Cnection
Viewport
Content-Script-Type
X-WA-Info
Content-Style-Type
X-Wix-Request-Id
X-Yottaa-Metrics
X-Yottaa-Optimizations
ViewerVersion
X-Cache-Server
X-GRACE
X-Upgrade-Enabled
X-TA-CDN-Provider
X-Esi
NtCoent-Length
Datacenter
X-Cache-Config
X-ProcessESI
Eomportal-Instance
X-RemovedCookies
X-Mode
X-Time
Xserver
X-NewRelic-App-Data
X-Endurance-Cache-Level
Machine
X-Routing-Service
X-Zipkin-Id
X-RN-RSRV
X-Varnish-Cache-Hits
X-Akamai-Transformed
X-Proxied
Cache-Key
Cache-Hits
X-Cache-Var
X-ES-SERVER
X-Hl-Ver
X-Is-Bot
X-Device-Type
Meta-Geo
X-Cache-NE
X-Path-Route
X-Cache-Var-Map
X-Detected-As
X-Proto
Load-Balancing
Vix-Hermes-Req-Id
TWC-Privacy
TWC-Locale-Group
We-Hiring
Webcakes-App-Name
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Mail-Subject
L5d-Success-Class
OT-Force-Account-Verify
Property-Id
TWC-Device-Class
TWC-Connection-Speed
X-Access
X-AWS-Id
X-Viewer-Country
X-VG-TLSProxy
X-Section
X-VWS-Id
X-Cdn
X-From
Mn-Server-Ip
X-Proxy
X-Origin-Hint
X-Environment-Context
X-Cache-Enabled
X-Format
X-Hosted-By
X-LJ-Flow-ID
X-L-Path
Access-Control-Request-Headers
X-FW-Version
X-S
Azure-SlotName
Azure-Version
X-Tb
Azure-SiteName
Azure-RegionName
X-Status
Azure-InstanceId
Decoy-Debug-TTL
Decoy-Debug-Status
X-Via-Fastly
X-TNCMS
X-Time-Microsecs
S-Rt
Decoy-Debug-Key
DB-Nickname
X-FC-Vary-Parameters
X-ServerID
X-Loop
X-Labrador-Cache-Channel
X-Birta-Cache-Post
X-Backend-Name
X-Birta-Served
X-Origin-Response-Time
X-EIG-Tracking-Id
X-Akamai-Request-ID
X-CCM
X-BYPASS-REASON
X-Timing-Wait
X-JoinUs
Selected-FE
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy-Build
X-Trace-Id
Cache-Tag
X-IP
Now
X-Debug-Cache
Origin-Edge-Control
X-Web-Node
X-Via-CDN
X-Tumblr-Pixel-3
X-Xfnlog-Site
Origin-Cache-Control
X-Varnish-Cacheable
X-MP-GENERATED-AT
X-NCache
X-Cache-Category-Id
X-FB-TRIP-ID
X-Grey
NGX
X-Origin-Host
X-PCL
X-Www-Served-By
X-OCL
X-Human
X-Site-Version
X-Cache-Operation
Uber-Trace-Id
X-Generated
Served-By
X-Vgn-Hpd-Reason
X-Dynatrace-Js-Agent
X-Rocket-Nginx-Bypass
X-CDN-Cache
X-Internal-Host
X-EdgeConnect-Cache-Status
X-VC-Cache
AsisCache
X-Newrelic-App-Data
X-R9-Blue-Green-Version
LB
User-Agent
X-NWS-LOG-UUID
X-Sucuri-ID
X-Rule
X-UA
X-Cluster-Node
X-RCS-CacheZone
Rt-Fastcgi-Cache
X-Cache-Remote
X-App-Name
Pagespeed
Nel
X-UnsetCookies
Release
X-ApacheServer
X-PERF
Hostname
X-Agile
X-Agile-Age
X-TIME
X-B3-Spanid
X-Agile-Id
X-Ua
X-Datadome
X-Source
X-Nginx-Cache
Cache-Name
X-APP-VERSION
X-App-Version
X-Request-Time
X-CACHE-KEY
X-Pubstack
X-Edge-Location
X-Ocache
X-Edge-IP
X-Protected-By
Warning
X-Cdn-Forward
X-OVcl-Cache
X-Sucuri-Cache
X-Varnish-Beresp-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl
X-Origin
X-Varnish-Beresp-Grace
X-Hit
X-Processor
X-A-Wwc
X-Platform
X-A-Dgt
X-Origin-CC
X-B-Cookie
X-ARC
X-Accel-Expires-Debug
X-PAYTM-SRV-ID
X-Aed
X-A-Dam
X-Application
X-Origin-TTL
Request-Time
N-Cache
Meta-Geo-Continent
Node
On-Server
Origin
MD5-Digest
Fly-Request-Id
Cache-Prefix
BehaviorPad-Version
Cross-Origin-Window-Policy
Ec-Rule-Version
Fly-Cache
Rendered-Blocks
Request-Country
UCS
Thinkindot-Control
Www
X-A
X-Region-Sid
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Request-EU
X-BB-ID
Server-Cache-Control
Server-Surrogate-Control
X-A-Ccd
X-IN-WAF
X-SRCache-Key
X-D
X-Thinkindot-L3
X-Request-UUID
X-Date
X-Core-Value
X-Varnish-Authentication
X-CF-Lambda-Version
X-Connection-Hash
X-Secret
X-Server-Group
X-Transaction
X-Trv-Group
X-Developer
X-Debug-Cache-Store
X-Destination
X-Debug-Cookies
X-Debug-Log
X-Up
Arc-Country
X-Debug-Cache-Expiry
X-Twitter-Response-Tags
X-Var-Ttl
X-Debug-Cache-Fetch
X-VCT
X-ScT
Xc-Version
X-Logtrace-Id
X-Instart-Isnd
X-Rewrite-Enabled
X-IN-APIGATEWAY
X-Matched-Rule
X-Mobile-URL
X-NX-Host
X-NU-AKA-ACS-Version
X-NodeID
X-Nginx-Cache-Key
X-Hp-Webp
X-Rojux
X-G
X-S-Cookie
X-External-Request-Id
X-DPWN-IS-SECURE
X-Developers
X-CF-Lambda-Fn
X-Cache-Grace
X-Generated-In
X-VG-WebServer
X-Gannett-Site-Version
X-Cache-Expires
X-Cache-ASPX
X-A-Dcw
Ajk
X-ElasticPress-Search
X-Varnish-Ttl
X-Cache-Backend
X-Varnish-Url
X-Webstats-RespID
Server-Int
Section-Io-Cache
True-Client-Country-4JS
X-F5-Cache
Server-Host
X-Epic-Correlation-Id
X-Eu-Site
RNT-Time
Proxy-Connection
X-Rebelmouse-Surrogate-Control
Pramga
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Cache-Info
X-Refresh
Fastcgi-Useragent
RNT-Machine
X-Hash
X-Request-URI
X-Geo-Header
X-Distil-CS
X-C
X-CGP
X-SIPLIST1
X-Skip-Cache
X-Ah-Environment
X-Cache-Debug
X-Cache-Id
X-Cache-Host
X-Cache-Miss-From
X-Cache-FS-Status
X-Cms-Context
X-Sf
X-Dispatcher-Server
X-Swa-Ws
X-RateLimit-Limit-Second
X-Distributor
X-Device-Os
X-Sedo-Request-Id
X-SN
X-ServiceProvider
X-Crawler
X-Servername
X-TT-LOGID
X-Reboot
HA-Ipaddr
Ha-Gx-Prefs
X-Info
X-Page-Type
Heartbleed
CDCHOST
X-Origin-Expires
Cache-Cookie-Set-Lfrom
X-Policy
X-No-Session
X-Node-Id
Fastly-Backend-Name
X-PHP-Host
Country-Code
X-Origin-Date
Fastly-SIE
Fastly-Soc-X-Request-Id
Apple-News-Services-Host
Fastly-SWR
Content-Disposition
Cache-Cookie-Set-Idcheck
X-Proxy-Cache-Status
X-Li-Pop
X-LI-Proto
X-LI-UUID
Apple-News-Services-Request-Url
X-Li-Fabric
Apple-News-Services-Parsed-Url
X-Qloud-Router
X-Irp-Debug
X-LAGOON
X-Proxy-Upstream
Cache-Cookie-Set-From
Memcached
Backend
X-Location
IsBot
Lfy
Magicmarker
AKAMAI
Apple-News-Services-Handled
Kp-EeAlive
SRV
X-GZip
X-ShardId
X-ShopId
X-Core-Mission
X-MSEdge-Features
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Generated-On
X-GeoIP-City
X-Level-Front-Cache
X-GeoIP-Country-Code
X-Fetched-On
X-Fastly-Cache
X-Planisys-CDN-Cache
X-Server-IP
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-S-Maxage
X-MSEdge-Flight
X-CUA
X-BBXSRF
X-Wikidot-Static-Cache
SD-X-WS
Pagetype
User-Cache-Control
X-Shopify-Stage
X-Wikidot-Backend
Adler-Geo
X-User
HTTPS
Fastly-SSL
Web-Mar-Node
X-Amzn-Remapped-Connection
X-Key
X-Via-Edge
X-Via-SSL
Is-Eu
X-Hnp-Log
X-Gen-Mode
Powered-By
Platform
X-Amzn-Remapped-Date
X-Block-Status
X-Thanos
X-Variation
X-Bip
X-Sorting-Hat-ShopId
X-Backend-Url
X-Backend-State
X-Sorting-Hat-PodId
X-Backend-Host
X-Alternate-Cache-Key
X-Amz-Meta-Cache-Control
X-Amzn-Remapped-Content-Length
X-Varnish-Beresp-Ttl
X-FireWall-Port
X-WPE-Loopback-Upstream-Addr
Pragrma
X-Cache-Bucket
X-Auto-Login
X-Owner
X-TrackingId
X-Server-Time
X-Cdn-Srv
X-RateLimit-Reset
X-Nc
X-Real-Ip
X-Passed-To
X-Micro-Cache
Server-ID
X-Server-By
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Dc
X-Passed-To-PostProcessResponse
X-Svr
X-Original-Request
X-Passed-To-BeforeDispatch
X-Returned-From-BeforeDispatch
X-Returned-From
X-Stale
X-Passed-To-DLL
X-Actual-URL
X-Unique-ID
ServerName
Host-ID
X-Org
X-Croise-Owner
DSUID
Cteonnt-Length
FNAC-ModuleRouting
X-VServer
X-HS-Cache-Config
X-Load-Cache
X-Edge-Server
VivaBuild
X-Pjax-Url
X-Aicache-OS
X-Microcachable
Cdn-Host
Cdn-Request-Time
X-CDN-Forward
Viewtype
REQUESTUUID
X-Parent-Response-Time
X-FPC
X-NC
Gh-Request-Id
X-CSRF-TOKEN
X-Apm-App-Name
X-Cdn-Origin
X-Apm-Inst-Hash
X-Sn-Servicetimems
X-Apm-Svc-Key
V-Age
X-Oss-Server-Time
Mime-Version
X-Ua-Device
X-Oss-Storage-Class
SID
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
MIME-Version
X-V
Memory
Rt-Proxy-Cache
X-Geo
Time
X-ND-Cache
X-Gdpr
X-Exp-Se
ProcessTime
X-Req
X-Wa
X-From-Cache
PICS-Label
X-Servedbyhost
X-Served-From
X-URL
Odigeo-Trace-Id
Cache
X-Tb-Optimization-Total-Bytes-Saved
HostName
X-HTML-Minification-Powered-By
X-B3-Parentspanid
X-Cache-HT
X-Optimization
AR-SID
X-DC
X-Newrelic-Synthetics
X-Fstrz
Wxu-Next-Commit
CF-IPCountry
Wxu-Next-Region
Wxu-Next-Hostname
Resin-Trace
Public-Key-Pins-Report-Only
Cdn
X-Git-Hash
Cf-Ipcountry
X-Lb-Id
X-Response-By
X-GEO
GMS-Ver
X-Varnish-Beresp-TTL
Fastcgi-X-Cache-Version
X-Atg-Version
Proxy-Firewall
XServer
X-Release
X-WR-MODIFICATION
Processtime
X-Fastly-Backend-Reqs
X-WebServer
X-TH-Server
WZWS-RAY
X-LB-ID
X-Ratelimit-Remaining
X-Amz-Meta-Surrogate-Control
X-Ratelimit-Limit
X-APP
X-Phone
X-Vcl-Version
X-Daa-Tunnel
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
X-We-Are-Hiring
X-Instart-Info
Countrycode
X-Clientip
Mobile-Detection-Method
CF-Cached-On
X-UE-Client-Country
GW-Server
X-Host-Name
X-Check-Cacheable
Backend-Name
X-NGINX-Cache
X-Vcache
X-HS-Status
X-Hyper-Cache
SS
Ohc-File-Size
X-Nananana
X-Upstream-HT
X-Worker
X-ID
X-WA
X-Upstream-CT
Pics-Label
X-Ratelimit-Reset
X-Fastly-Country-Code
X-Zone
Lb
X-PF-Uncompressing
X-ServedByHost
409pxxline
178proxuri
X-Server-W
FSS-Proxy
X-CSRF-Token
Xxline
X-HS-Combine-CSS
FSS-Cache
SN
355prline
286prxHost
188prxHost
189phosttRef
X-Backend-TTL
219prxHost
225prxHost
352pxline
DataCenter
X-B3-SpanId
X-VHOST
GeoIp-Country-Code
Geoip-Latitude
X-IPS-LoggedIn
X-SERVER-NAME
X-GZIP
X-Dynatrace
X-SRV
Esi-Enabled
X-Render-Time
Geoip-City
X-UPSTREAM-Address
URI
X-BE
X-Fpc
Version
Ohc-Cache-HIT
X-Be
X-Request-Start
Serverid
X-CS
WP-Super-Cache
X-Gen-Id
X-LiteSpeed-Cache-Control
X-VCL-Version
X-UCC
X-Unique-Id
X-Varnish-Action
Who
GeoIP-Country-Code
GeoIP-City
X-GDPR
GeoIP-Latitude
X-PJAX-URL
CDN
X-AssetVersion
X-Contensis-Viewer-Groups
Dynatrace
X-HostName
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
X-Via-Ucdn
X-Cache-URL
X-NGENIX-Cache
X-Pf-Uncompressing
Cneonction
X-Fastly-Cache-Hits
RequestUuid
X-Html-Edge-Cache
X-ZONE
X-Akamai-Request-ID2
X-Cache-Ttl
X-Cdn-Cache
X-Vtex-Remote-Cache
X-LiteSpeed-Tag
X-Vtex-Processado-Em
X-RequestId
A
Accept-Language
Server-Id
X-Store
Accept-Ch
X-Via-NSCOPI
X-NWS-UUID-VERIFY
X-Request-Url
X-Akamai-SSL-Client-Sid
X-Reqid
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Flog
X-ABtesting
Locale
X-Hello
X-ServerName
Get-Access-Time
X-Cdn-Request-ID
X-Port
X-HTML-Edge-Cache
RequestId
Is-Session-Tracking
Ohc-Response-Time
Frontcache
X-Serial
X-Dw-Trace-Id
NnCoection
X-EC-Lua