Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
CF-Ray
X-Request-ID
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Robots-Tag
X-Server-Powered-By
WPE-Backend
X-Nginx-Cache-Status
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-Device
Allow
Ali-Swift-Global-Savetime
Server-Timing
X-CST
X-Ac
X-Type
X-Node
X-Rq
X-Host
Feature-Policy
Content-Location
X-Server-Id
X-Response-Time
X-Cnection
Report-To
X-Backend-Server
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Readtime
X-Origin-Cache
X-Rack-Cache
Request-Id
X-Url
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
NEL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Instart-Request-ID
X-Upstream-Env
X-Dns-Prefetch-Control
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Pinterest-Generated-By
X-Vhost
X-DynaTrace
X-Px
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Goog-Hash
X-Server-Name
Verso
Accept-CH
X-ESI
X-Dispatcher
X-HW
X-ORACLE-DMS-RID
X-GitHub-Request-Id
X-VARITI-CCR
MS-Author-Via
Charset
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-DataStream-Cache-Status
X-MS-InvokeApp
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja
X-Exp-Id
AR-PoweredBy
AR-ATIME
X-GoogleNews-Bot
AR-CACHE
X-Exp-Variant
X-Cached
X-Version
Content-MD5
X-Powered-By-Plesk
X-Recruiting
Public-Key-Pins
Service-Worker-Allowed
Accept-CH-Lifetime
X-D2id
AR-Request-ID
X-Navigation-Version
X-Abt-Application-Version
X-TtlSet
X-Vname
X-PC
RTSS
Ar-Sid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Server-ID
X-Ser
X-Varnish-TTL
X-Trace
X-TTL
SPRequestGuid
X-Forwarded-Proto
X-Client-IP
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
X-DynaTrace-JS-Agent
X-FTR-Backend-Server
X-SharePointHealthScore
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-DC
X-FTR-Balancer
X-FTR-Cache-Status
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Amz-Rid
X-Fastly-Request-ID
X-FTR-Expires
Nginx-Cache
X-VCache
S
X-Amz-Meta-S3cmd-Attrs
Arr-Disable-Session-Affinity
X-Debug
X-XRDS-Location
X-Shield-Request-Id
TCN
X-Ttl
X-Dw-Request-Base-Id
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
SPRequestDuration
SPIisLatency
Pinterest-Version
X-Id
X-Pinterest-Rid
X-Upstream-Proxy
X-Oracle-Dms-Rid
X-Akam-SW-Version
DynaTrace
Access-Control-Request-Method
X-SERVER
Front-End-Https
X-FTR-Cache-Host
X-Goog-Storage-Class
X-T
X-Powered-CMS
X-B3-TraceId
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Realpath
Tracecode
X-MSEdge-Ref
X-Amzn-Trace-Id
Fastcgi-Cache
X-Varnish-Age
Paypal-Debug-Id
X-N
X-Forwarded-For
X-Content-Type
Alternate-Protocol
MRF-Tech
X-Upstream
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-RateLimit-Remaining
X-PressLabs-Stats
X-Frontend
X-Middleton-Display
X-Logged-In
Display
X-HS-Content-Id
X-HS-Hub-Id
X-Sol
X-Content-Digest
Fusion-Content-Source
Fusion-Template-Id
X-Accel-Buffering
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
AMP-Access-Control-Allow-Source-Origin
X-Middleton-Response
X-Litespeed-Cache
Response
X-Srv
X-Hostname
X-Kinsta-Cache
X-Fastcgi-Cache
X-Cache-Key
X-Pad
X-Accel-Expires
Server-Name
MicrosoftSharePointTeamServices
X-B3-Traceid
X-User-Agent
X-Content-Options
Host
X-Analytics
Refresh
Backend-Timing
X-Correlation-Id
X-DIS-Request-ID
X-Revision
X-Debug-Info
X-LB-Cache
X-Rid
X-Activity-Id
X-Az
X-IPLB-Instance
X-AppVersion
X-Amz-Apigw-Id
X-B
FilterID
Accept-Charset
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Amzn-RequestId
X-Cache-Hit
X-B3-Sampled
ServerID
X-Cache-2
X-CF-Powered-By
Powered-By-ChinaCache
Surrogate-Key
X-FastCGI-Cache
X-Grace
X-Page-Id
X-Whom
Server-Info
X-PHP-Backend
TP-L2-Cache
X-Webkit-CSP
TP-Cache
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
X-Request-Received
MS-CV
X-Varnish-Backend
Host-Header
X-Request-Processing-Time
X-TT
X-Origin-Server
VIX-Pulpo-Upstream-Status
Source
VIX-Pulpo-Node
X-Akamai-Edgescape
X-Amz-Replication-Status
X-Framework
X-UA-Device-Type
X-Cluster
X-Cache-Action
X-Platform-Server
X-RateLimit-Limit
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-App-Environment
X-Tumblr-User
X-F-Cache
X-Mobile
X-FW-Static
X-FW-Serve
X-FW-Hash
X-Drupal-Cache-Tags
X-FW-Type
X-Instance
X-Content-Powered-By
Access-Control-Allow-Method
X-Varnish-Grace
Cache-Status
X-FW-Server
X-Handled-By
X-Request-Guid
X-Cached-By
X-Geo-Country
X-Zen-Fury
X-SS-Set-Cookie
X-Magnolia-Registration
X-FB-Debug
X-Shard
X-Ezoic-Cdn
X-Cache-TTL
X-Forwarded-Host
Edge-Cache-Tag
X-GUploader-UploadID
From-Origin
X-ATG-Version
CACHE
X-App-Server
X-Cache-Age
DC
X-Wix-Server-Artifact-Id
X-Varnish-Server
PageSpeed
X-Node-Name
Cleartype
X-Varnish-Hostname
Cache-Tags
X-AOL-HN
X-BCube-Filmed-By
Payment
X-Region
X-Cache-Control
X-WebKit-CSP-Report-Only
X-Response-Served-From
X-Generated-By
X-RequestSource
Filters
Upgrade-Insecure-Requests
X-GeoIP
X-Adobe-Loc
X-Adobe-Content
X-TX-ID
Healthy
NGB
X-TT-TIMESTAMP
Ms-Operation-Id
X-RTag
X-VG-WebCache
X-UUID
X-Signature
Webserver
Cache-Tv-Group
X-B-Cache
Country
X-Drupal-Cache-Contexts
GEO-INFO
X-Jobs
X-FW-Dynamic
X-Tumblr-Pixel-1
X-Storage
X-Tumblr-Pixel-2
Server-Node
X-Seen-By
X-Redis-Cache
Retry-After
X-XRDS-LOCATION
X-Varnish-Hits
ServedBy
X-Content-Age
X-Cacheable-TTL
Actual-Object-TTL
Liferay-Portal
X-Locale
X-Cache-Rule
X-Via-JSL
X-Contextid
Fastly-Restarts
X-Rendered-As
X-Oneagent-Js-Injection
HitType
Frame-Options
Powered
X-Cache-TTL-Remaining
X-Real-IP
X-Varnish-IP
X-Guploader-Uploadid
X-BACKEND-TTL
S-Cnection
Viewport
Content-Script-Type
Content-Style-Type
X-WA-Info
ViewerVersion
X-Wix-Request-Id
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Server
X-TA-CDN-Provider
X-Upgrade-Enabled
X-GRACE
X-Esi
Datacenter
NtCoent-Length
X-Cache-Config
X-ProcessESI
X-RemovedCookies
Eomportal-Instance
X-Mode
X-NewRelic-App-Data
Xserver
X-Time
X-Varnish-Cache-Hits
X-Endurance-Cache-Level
X-Detected-As
X-Akamai-Transformed
Meta-Geo
X-Cache-Var-Map
X-Proxied
X-Proto
X-Path-Route
X-Cache-NE
X-Routing-Service
X-Device-Type
X-ES-SERVER
X-Hl-Ver
X-Is-Bot
Cache-Hits
X-Cache-Var
X-Zipkin-Id
Machine
Cache-Key
X-RN-RSRV
Load-Balancing
X-LJ-Flow-ID
TWC-GeoIP-Country
X-L-Path
TWC-Device-Class
X-Origin-Hint
Webcakes-App-Name
TWC-Connection-Speed
X-Hosted-By
TWC-GeoIP-LatLong
Vix-Hermes-Req-Id
X-Backend-Name
TWC-Privacy
X-Cache-Enabled
X-Environment-Context
TWC-Locale-Group
X-Section
Property-Id
X-S
Access-Control-Request-Headers
X-Access
Webcakes-Region
Mn-Server-Ip
X-From
Webcakes-App-Version
X-Cdn
X-VWS-Id
We-Hiring
OT-Force-Account-Verify
Mail-Subject
L5d-Success-Class
X-Viewer-Country
X-VG-TLSProxy
X-AWS-Id
S-Rt
Azure-SlotName
Azure-Version
DB-Nickname
Now
X-EIG-Tracking-Id
X-Time-Microsecs
X-Tb
X-Status
X-TNCMS
Decoy-Debug-Key
X-FC-Vary-Parameters
Decoy-Debug-TTL
Decoy-Debug-Status
X-ServerID
X-Proxy
Azure-SiteName
X-Birta-Served
X-Birta-Cache-Post
X-FW-Version
X-Labrador-Cache-Channel
X-Origin-Response-Time
X-Loop
X-Akamai-Request-ID
X-Format
Azure-InstanceId
Azure-RegionName
X-NCache
X-Proxy-Build
X-ProxyCache-Key
Cache-Tag
X-JoinUs
X-BYPASS-REASON
X-CCM
X-IP
X-Timing-Wait
X-Trace-Id
X-Debug-Cache
X-Via-CDN
X-Web-Node
Origin-Edge-Control
Origin-Cache-Control
X-Varnish-Cacheable
X-Via-Fastly
X-Xfnlog-Site
Selected-FE
X-ProxyCache-Status
X-PCL
X-Origin-Host
X-OCL
X-Human
Served-By
X-Tumblr-Pixel-3
NGX
X-Grey
X-Cache-Category-Id
X-Internal-Host
X-MP-GENERATED-AT
X-Www-Served-By
X-FB-TRIP-ID
X-Cache-Operation
X-Generated
X-Site-Version
Uber-Trace-Id
X-Dynatrace-Js-Agent
X-CDN-Cache
X-Rocket-Nginx-Bypass
X-Vgn-Hpd-Reason
X-EdgeConnect-Cache-Status
X-VC-Cache
AsisCache
X-Newrelic-App-Data
X-R9-Blue-Green-Version
LB
User-Agent
X-Rule
X-Sucuri-ID
X-NWS-LOG-UUID
X-UA
X-RCS-CacheZone
X-Cluster-Node
Rt-Fastcgi-Cache
Nel
X-App-Name
Pagespeed
X-Cache-Remote
Release
X-UnsetCookies
X-ApacheServer
X-PERF
Hostname
X-Agile
X-TIME
X-Agile-Age
X-Agile-Id
X-B3-Spanid
X-Ua
X-Datadome
X-Nginx-Cache
X-Source
Cache-Name
X-APP-VERSION
X-App-Version
X-Edge-Location
X-Request-Time
X-Edge-IP
X-CACHE-KEY
X-Pubstack
X-Ocache
Warning
X-Cdn-Forward
X-Protected-By
X-Hit
X-OVcl
X-OVcl-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Origin
X-Sucuri-Cache
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-A-Dgt
X-A-Wwc
X-NodeID
X-Application
Fly-Cache
BehaviorPad-Version
Ec-Rule-Version
Cache-Prefix
Cross-Origin-Window-Policy
X-ARC
X-Aed
X-Accel-Expires-Debug
X-Mobile-URL
X-NU-AKA-ACS-Version
X-B-Cookie
UCS
Request-Country
Request-EU
MD5-Digest
Request-Time
Rendered-Blocks
Origin
Meta-Geo-Continent
N-Cache
Node
On-Server
Server-Cache-Control
Server-Surrogate-Control
Www
X-Developer
X-A
X-A-Ccd
Thinkindot-Control
Thinkindot-CacheControl-Type
Fly-Request-Id
X-BB-ID
Thinkindot-CacheControl
X-A-Dam
X-VG-WebServer
X-External-Request-Id
X-Transaction
X-Thinkindot-L3
X-SRCache-Key
X-Logtrace-Id
X-Date
X-Rewrite-Enabled
X-Core-Value
X-Connection-Hash
X-Trv-Group
X-D
X-Instart-Isnd
X-DPWN-IS-SECURE
X-Rojux
X-Debug-Cache-Store
X-S-Cookie
X-Debug-Cookies
X-Matched-Rule
X-Debug-Log
X-ScT
X-Debug-Cache-Fetch
X-Server-Group
X-Debug-Cache-Expiry
X-Secret
Arc-Country
X-G
X-Request-UUID
X-Hp-Webp
Xc-Version
X-IN-WAF
X-Region-Sid
X-Destination
X-Processor
X-Platform
X-NX-Host
X-Origin-CC
X-Origin-TTL
X-PAYTM-SRV-ID
X-VCT
X-Varnish-Authentication
X-Up
X-Developers
X-Twitter-Response-Tags
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Gannett-Site-Version
X-Cache-Grace
X-Generated-In
X-Var-Ttl
X-Cache-ASPX
X-Cache-Expires
X-IN-APIGATEWAY
X-A-Dcw
X-ElasticPress-Search
Ajk
X-Varnish-Ttl
SRV
X-Cache-Backend
X-Eu-Site
Server-Int
X-Request-URI
X-F5-Cache
X-Webstats-RespID
Server-Host
X-Epic-Correlation-Id
X-Varnish-Url
True-Client-Country-4JS
X-Geo-Header
Pramga
Proxy-Connection
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Cache-Id
X-Reboot
RNT-Time
RNT-Machine
X-Hash
X-Refresh
X-TT-LOGID
X-Distil-CS
X-SIPLIST1
X-CGP
X-Sf
X-Cms-Context
X-Ah-Environment
X-C
X-Cache-Host
X-Cache-Info
X-Cache-Miss-From
X-Cache-Debug
X-ServiceProvider
X-Servername
X-Dispatcher-Server
X-Swa-Ws
X-Qloud-Router
X-Distributor
X-Device-Os
Section-Io-Cache
X-SN
X-Crawler
X-Sedo-Request-Id
Fastcgi-Useragent
X-Rebelmouse-Surrogate-Control
HA-Ipaddr
X-Origin-Date
Ha-Gx-Prefs
Cache-Cookie-Set-Lfrom
Heartbleed
Cache-Cookie-Set-Idcheck
Backend
Content-Disposition
Cache-Cookie-Set-From
X-Info
X-Page-Type
Fastly-Soc-X-Request-Id
Fastly-SIE
Fastly-Backend-Name
Apple-News-Services-Handled
CDCHOST
Fastly-SWR
X-Nginx-Cache-Key
X-No-Session
X-Node-Id
X-Origin-Expires
X-Policy
X-Li-Fabric
X-Li-Pop
X-LI-Proto
Memcached
Apple-News-Services-Host
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Irp-Debug
X-LAGOON
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
IsBot
X-Location
AKAMAI
Kp-EeAlive
Country-Code
X-LI-UUID
Magicmarker
Lfy
X-PHP-Host
X-GZip
X-ShopId
X-Cdn-Srv
X-Core-Mission
X-ShardId
X-MSEdge-Features
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Generated-On
X-GeoIP-City
X-Level-Front-Cache
X-GeoIP-Country-Code
X-Fetched-On
X-Fastly-Cache
X-Planisys-CDN-Cache
X-Server-IP
X-Planisys-CDN-Rules
X-MSEdge-Flight
X-S-Maxage
X-Planisys-CDN-TTL
X-CUA
X-BBXSRF
X-Key
X-User
X-Variation
X-Hnp-Log
X-Via-Edge
X-Via-SSL
Fastly-SSL
HTTPS
User-Cache-Control
X-Thanos
X-Gen-Mode
X-Block-Status
SD-X-WS
Web-Mar-Node
X-Wikidot-Static-Cache
Pagetype
X-Wikidot-Backend
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
Platform
Powered-By
X-Alternate-Cache-Key
Is-Eu
X-Bip
X-Skip-Cache
X-Backend-State
X-Sorting-Hat-PodId
X-Amzn-Remapped-Content-Length
X-Backend-Host
X-Sorting-Hat-ShopId
X-Backend-Url
X-Cache-FS-Status
Adler-Geo
X-Shopify-Stage
X-Auto-Login
X-Varnish-Beresp-Ttl
X-Amz-Meta-Cache-Control
X-WPE-Loopback-Upstream-Addr
X-FireWall-Port
Pragrma
X-Server-Time
X-RateLimit-Reset
X-Micro-Cache
X-Cache-Bucket
X-TrackingId
X-Owner
X-Nc
X-Real-Ip
X-Passed-To
X-Passed-To-PostProcessResponse
X-Original-Request
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
Server-ID
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Svr
X-Actual-URL
X-Server-By
X-Dc
X-Returned-From-BeforeDispatch
X-Stale
X-Returned-From
ServerName
Host-ID
FNAC-ModuleRouting
X-Org
X-Unique-ID
DSUID
Cteonnt-Length
X-HS-Cache-Config
X-Croise-Owner
X-VServer
X-Load-Cache
X-Microcachable
X-Aicache-OS
REQUESTUUID
Cdn-Host
X-Pjax-Url
X-CDN-Forward
Cdn-Request-Time
X-Edge-Server
Gh-Request-Id
VivaBuild
Viewtype
X-NC
X-Parent-Response-Time
V-Age
X-FPC
X-CSRF-TOKEN
X-Apm-App-Name
X-Apm-Inst-Hash
X-Cdn-Origin
X-Apm-Svc-Key
X-Sn-Servicetimems
X-Oss-Request-Id
X-Oss-Storage-Class
X-Ua-Device
MIME-Version
Mime-Version
SID
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-V
X-ND-Cache
X-Gdpr
X-Exp-Se
Rt-Proxy-Cache
X-Geo
Memory
Time
ProcessTime
PICS-Label
X-Served-From
X-Req
X-From-Cache
X-Servedbyhost
X-Wa
X-URL
Odigeo-Trace-Id
Cache
X-Tb-Optimization-Total-Bytes-Saved
X-B3-Parentspanid
HostName
X-HTML-Minification-Powered-By
X-Optimization
Cf-Ipcountry
AR-SID
X-Cache-HT
X-DC
CF-IPCountry
Wxu-Next-Region
X-Newrelic-Synthetics
Wxu-Next-Hostname
Wxu-Next-Commit
X-Fstrz
Resin-Trace
X-Git-Hash
Cdn
Public-Key-Pins-Report-Only
X-Response-By
X-Lb-Id
X-GEO
GMS-Ver
Fastcgi-X-Cache-Version
X-Atg-Version
X-Varnish-Beresp-TTL
XServer
Proxy-Firewall
X-Release
X-WR-MODIFICATION
X-Fastly-Backend-Reqs
X-WebServer
X-TH-Server
X-LB-ID
Processtime
WZWS-RAY
X-Ratelimit-Remaining
X-Vcl-Version
X-Phone
X-APP
X-Amz-Meta-Surrogate-Control
X-Ratelimit-Limit
X-Daa-Tunnel
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
Countrycode
X-We-Are-Hiring
X-UE-Client-Country
Mobile-Detection-Method
CF-Cached-On
GW-Server
X-Clientip
X-Instart-Info
X-Host-Name
X-Check-Cacheable
X-Hyper-Cache
Backend-Name
SS
X-Vcache
X-HS-Status
X-NGINX-Cache
Ohc-File-Size
X-Upstream-HT
X-Zone
X-Upstream-CT
X-Ratelimit-Reset
X-Fastly-Country-Code
X-ID
X-Nananana
X-WA
X-Worker
Pics-Label
Lb
FSS-Cache
SN
X-CSRF-Token
FSS-Proxy
X-ServedByHost
188prxHost
X-Backend-TTL
409pxxline
219prxHost
286prxHost
352pxline
355prline
X-HS-Combine-CSS
189phosttRef
225prxHost
X-Server-W
Xxline
X-PF-Uncompressing
178proxuri
DataCenter
X-B3-SpanId
X-SERVER-NAME
X-VHOST
GeoIp-Country-Code
Geoip-Latitude
X-IPS-LoggedIn
X-Dynatrace
X-GZIP
X-UPSTREAM-Address
Version
Ohc-Cache-HIT
X-BE
URI
X-Fpc
Geoip-City
X-Request-Start
X-Render-Time
X-Be
Esi-Enabled
X-VCL-Version
X-CS
WP-Super-Cache
X-LiteSpeed-Cache-Control
X-UCC
X-Gen-Id
X-Unique-Id
GeoIP-Latitude
X-Contensis-Viewer-Groups
GeoIP-Country-Code
Who
GeoIP-City
X-GDPR
CDN
X-Varnish-Action
X-AssetVersion
X-PJAX-URL
X-FORWARDED-FOR
Dynatrace
Amp-Access-Control-Allow-Source-Origin
X-HostName
X-Cache-URL
X-NGENIX-Cache
RequestUuid
X-Pf-Uncompressing
Cneonction
X-SRV
X-Html-Edge-Cache
X-Via-Ucdn
X-Fastly-Cache-Hits
Serverid
X-Cache-Ttl
X-Akamai-Request-ID2
X-ZONE
X-Cdn-Cache
X-Via-NSCOPI
X-LiteSpeed-Tag
X-Store
Accept-Language
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-RequestId
Accept-Ch
A
Server-Id
X-NWS-UUID-VERIFY
X-Request-Url
X-Akamai-SSL-Client-Sid
Locale
X-Cdn-Request-ID
NnCoection
X-ABtesting
X-Flog
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Reqid
X-Hello
X-Serial
Frontcache
X-HTML-Edge-Cache
X-Dw-Trace-Id
RequestId
X-Port
X-EC-Lua
X-ServerName
Is-Session-Tracking
Get-Access-Time
Ohc-Response-Time