Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
Access-Control-Max-Age
P3p
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
WPE-Backend
X-Robots-Tag
X-Varnish-Cache
X-Server-Powered-By
X-Nginx-Cache-Status
X-Page-Speed
EagleId
X-UA-Device
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-Host
X-CST
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
Report-To
X-Server-Id
X-Type
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
EagleEye-TraceId
Surrogate-Control
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Readtime
Request-Id
X-Origin-Cache
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Country-Code
X-Clacks-Overhead
NEL
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
X-Mod-Pagespeed
Pinterest-Generated-By
X-Origin-Upstream-Status
X-Px
X-DataDome
X-Upstream-Env
Edge-Control
X-Goog-Hash
Verso
X-Server-Name
Accept-CH
X-ESI
X-HW
X-Dispatcher
X-Server-ID
X-ORACLE-DMS-RID
MS-Author-Via
X-VARITI-CCR
AR-PoweredBy
AR-CACHE
AR-ATIME
X-GitHub-Request-Id
X-DataStream-Cache-Status
X-MS-InvokeApp
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Build
PB-RID
X-Mobile-Rewrite
PB-PID
Arc-Version
X-Cached
X-Version
Charset
Content-MD5
X-Powered-By-Plesk
Public-Key-Pins
X-Recruiting
X-Dns-Prefetch-Control
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
X-TTL
Ar-Sid
RTSS
X-Abt-Application-Version
X-Navigation-Version
X-D2id
X-TtlSet
X-Vname
X-PC
X-Ser
X-Varnish-TTL
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Server-Side-Encryption
X-Trace
X-Vcap-Request-Id
X-Client-IP
X-Forwarded-Proto
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-Goog-Stored-Content-Encoding
X-Country-Code-Real
X-FTR-Cache-Status
X-Goog-Stored-Content-Length
X-FTR-Realm
X-FTR-DC
X-Goog-Generation
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-Goog-Metageneration
X-FTR-Expires
X-Amz-Rid
X-Fastly-Request-ID
X-VCache
S
X-XRDS-Location
X-SharePointHealthScore
X-Amz-Meta-S3cmd-Attrs
TCN
Arr-Disable-Session-Affinity
X-Debug
X-Shield-Request-Id
X-Hits
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Dw-Request-Base-Id
DynaTrace
X-Upstream-Proxy
X-Pinterest-Rid
SPIisLatency
Pinterest-Version
SPRequestDuration
X-Akam-SW-Version
Access-Control-Request-Method
X-Goog-Storage-Class
X-Powered-CMS
X-FTR-Cache-Host
X-B3-TraceId
X-T
X-Oracle-Dms-Rid
Front-End-Https
X-NF-Request-ID
X-SERVER
X-Acc-Meta-Resource-Type
Realpath
X-Ttl
Tracecode
X-Amzn-Trace-Id
X-MSEdge-Ref
X-Aspnet-Version
X-N
Paypal-Debug-Id
X-Varnish-Age
Fastcgi-Cache
X-Id
X-Content-Type
X-Forwarded-For
X-Upstream
Alternate-Protocol
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-RateLimit-Remaining
X-Frontend
X-Logged-In
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
X-Fastcgi-Cache
X-Content-Digest
Display
X-Middleton-Display
X-Sol
AMP-Access-Control-Allow-Source-Origin
Response
X-Middleton-Response
X-Hostname
X-Litespeed-Cache
X-Pad
X-Accel-Expires
X-Srv
X-Kinsta-Cache
MicrosoftSharePointTeamServices
Host
X-Accel-Buffering
Server-Name
X-Cache-Key
X-Analytics
X-Content-Options
X-User-Agent
Backend-Timing
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Correlation-Id
X-Debug-Info
X-Revision
X-LB-Cache
X-B3-Traceid
X-AppVersion
X-Az
X-Amz-Apigw-Id
X-Activity-Id
X-Amzn-RequestId
X-Cdn
Refresh
FilterID
X-IPLB-Instance
Accept-Charset
X-B3-Sampled
X-Rid
X-Cache-2
X-Cache-Hit
Powered-By-ChinaCache
Surrogate-Key
X-DIS-Request-ID
X-B
X-CF-Powered-By
X-Page-Id
X-Whom
X-Grace
ServerID
Server-Info
TP-L2-Cache
TP-Cache
X-PHP-Backend
Host-Header
MS-CV
X-FastCGI-Cache
X-GUploader-UploadID
X-Request-Received
X-Cached-By
X-Request-Processing-Time
X-Content-Security-Policy-Report-Only
Cache-Status
X-Origin-Server
X-Amz-Replication-Status
Source
VIX-Pulpo-Upstream-Status
X-Kong-Proxy-Latency
VIX-Pulpo-Node
X-TT
X-Varnish-Backend
X-Kong-Upstream-Latency
X-Cluster
X-UA-Device-Type
X-App-Environment
X-Framework
X-Content-Powered-By
Access-Control-Allow-Method
X-Cache-Action
X-Akamai-Edgescape
X-Mobile
X-Webkit-CSP
X-Platform-Server
X-FW-Server
X-FW-Hash
X-F-Cache
X-FW-Serve
X-FW-Static
X-FW-Type
X-Drupal-Cache-Tags
X-Request-Guid
X-Varnish-Grace
X-Tumblr-Pixel
X-Ruxit-Js-Agent
X-Tumblr-User
X-Tumblr-Pixel-0
X-Instance
X-SS-Set-Cookie
X-FB-Debug
X-Zen-Fury
X-RateLimit-Limit
X-Geo-Country
X-Handled-By
X-Ezoic-Cdn
X-Forwarded-Host
X-Cache-TTL
X-Shard
X-Magnolia-Registration
Edge-Cache-Tag
From-Origin
X-Node-Name
X-ATG-Version
X-Cache-Age
X-Varnish-Hostname
X-App-Server
DC
Cache-Tags
X-Varnish-Server
Cleartype
X-BCube-Filmed-By
PageSpeed
X-Cache-Control
X-AOL-HN
Payment
Healthy
Upgrade-Insecure-Requests
Filters
CACHE
X-RequestSource
X-Generated-By
X-WebKit-CSP-Report-Only
X-Response-Served-From
X-Adobe-Loc
X-Adobe-Content
X-Region
X-TX-ID
Server-Node
X-Cache-Rule
X-RTag
X-Redis-Cache
Webserver
Fastly-Restarts
NGB
Ms-Operation-Id
X-VG-WebCache
X-UUID
X-TT-TIMESTAMP
X-Storage
X-FW-Dynamic
X-GeoIP
X-Jobs
X-Signature
X-Drupal-Cache-Contexts
Cache-Tv-Group
Retry-After
Country
X-B-Cache
X-Cacheable-TTL
X-Locale
Actual-Object-TTL
X-Content-Age
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Varnish-Hits
GEO-INFO
X-TA-CDN-Provider
ServedBy
X-XRDS-LOCATION
Powered
Liferay-Portal
X-Contextid
X-Seen-By
Frame-Options
X-Wix-Server-Artifact-Id
HitType
X-Rendered-As
X-Real-IP
X-Cache-TTL-Remaining
X-Oneagent-Js-Injection
X-Via-JSL
X-Varnish-IP
X-WA-Info
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-GRACE
Viewport
S-Cnection
Eomportal-Instance
X-RemovedCookies
X-ProcessESI
X-Cache-NE
X-Upgrade-Enabled
X-BACKEND-TTL
X-Guploader-Uploadid
X-Time
NtCoent-Length
X-Cache-Server
X-Mode
Xserver
Content-Style-Type
Content-Script-Type
Datacenter
X-Esi
X-Cache-Config
X-Akamai-Transformed
X-Device-Type
Mn-Server-Ip
X-Proxied
X-Detected-As
X-RN-RSRV
X-Varnish-Cache-Hits
X-Routing-Service
X-ES-SERVER
X-Proto
X-Cache-Var-Map
X-Cache-Var
X-S
X-Zipkin-Id
Meta-Geo
X-Hl-Ver
Machine
Cache-Hits
Cache-Key
X-Is-Bot
X-From
Load-Balancing
Webcakes-Region
TWC-GeoIP-LatLong
Mail-Subject
TWC-GeoIP-Country
X-Origin-Hint
X-AWS-Id
X-LJ-Flow-ID
TWC-Locale-Group
Webcakes-App-Version
L5d-Success-Class
We-Hiring
TWC-Privacy
X-Tb
TWC-Connection-Speed
Webcakes-App-Name
Vix-Hermes-Req-Id
Property-Id
TWC-Device-Class
X-Cache-Operation
X-L-Path
Access-Control-Request-Headers
X-FC-Vary-Parameters
X-Cache-Enabled
X-Environment-Context
X-VWS-Id
X-Hosted-By
X-VG-TLSProxy
OT-Force-Account-Verify
X-Viewer-Country
X-Endurance-Cache-Level
S-Rt
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Origin-Cache-Control
Azure-SlotName
Origin-Edge-Control
Azure-Version
X-Backend-Name
NGX
X-ServerID
X-Debug-Cache
X-EIG-Tracking-Id
X-FB-TRIP-ID
X-FW-Version
X-Format
X-Proxy
X-Web-Node
X-Labrador-Cache-Channel
X-TNCMS
X-Akamai-Request-ID
X-Origin-Response-Time
X-Loop
X-Birta-Cache-Post
X-Time-Microsecs
X-Birta-Served
X-OCL
X-IP
X-JoinUs
X-Human
X-NCache
Now
Selected-FE
X-Access
X-PCL
X-Proxy-Build
X-CCM
X-BYPASS-REASON
X-Path-Route
X-ProxyCache-Key
Cache-Tag
X-Timing-Wait
X-Trace-Id
X-Via-Fastly
X-Xfnlog-Site
X-Section
X-Varnish-Cacheable
X-ProxyCache-Status
X-Site-Version
X-Status
X-Via-CDN
X-Vgn-Hpd-Reason
DB-Nickname
X-Generated
X-Grey
Decoy-Debug-Key
Decoy-Debug-TTL
X-Cache-Category-Id
X-Rocket-Nginx-Bypass
X-Www-Served-By
Decoy-Debug-Status
X-NWS-LOG-UUID
X-Wix-Request-Id
Uber-Trace-Id
X-Tumblr-Pixel-3
ViewerVersion
X-RCS-CacheZone
X-VC-Cache
X-EdgeConnect-Cache-Status
X-Internal-Host
X-R9-Blue-Green-Version
X-CDN-Cache
X-Newrelic-App-Data
X-MP-GENERATED-AT
X-Dynatrace-Js-Agent
X-Rule
X-Cache-Remote
Served-By
LB
X-NewRelic-App-Data
AsisCache
Release
X-Origin-Host
Pagespeed
X-UA
X-UnsetCookies
X-Sucuri-ID
X-Cluster-Node
Rt-Fastcgi-Cache
X-Ua
Nel
X-App-Name
X-PERF
X-ApacheServer
User-Agent
X-Source
X-Nginx-Cache
X-App-Version
X-Agile-Id
X-Agile-Age
X-TIME
X-Agile
X-Datadome
X-Request-Time
X-APP-VERSION
X-B3-Spanid
X-OVcl
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl-Cache
X-Hit
Cache-Name
X-Origin
X-Edge-Location
X-VCT
Warning
X-Pubstack
Hostname
X-Origin-CC
X-Origin-TTL
X-CACHE-KEY
X-Edge-IP
X-Cdn-Forward
X-BB-ID
X-Ocache
X-Sucuri-Cache
X-Cache-ASPX
X-B-Cookie
X-Application
X-Aed
Ajk
X-Platform
X-Processor
X-Cache-Expires
X-ARC
X-Region-Sid
X-Rojux
X-Rewrite-Enabled
X-D
X-Date
X-S-Cookie
X-Debug-Cache-Expiry
X-Core-Value
X-Connection-Hash
X-CF-Lambda-Fn
X-Accel-Expires-Debug
X-Request-UUID
X-CF-Lambda-Version
Meta-Geo-Continent
X-Cache-Grace
X-A-Wwc
Fly-Request-Id
Request-Time
Fly-Cache
Server-Cache-Control
Ec-Rule-Version
Server-Surrogate-Control
Request-EU
Request-Country
Node
MD5-Digest
On-Server
Origin
X-PAYTM-SRV-ID
Cross-Origin-Window-Policy
Thinkindot-CacheControl
Arc-Country
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
BehaviorPad-Version
X-A
Thinkindot-Control
Thinkindot-CacheControl-Type
UCS
Cache-Prefix
Www
X-Debug-Cache-Fetch
Xc-Version
X-G
X-Gannett-Site-Version
X-Generated-In
X-Varnish-Authentication
X-NU-AKA-ACS-Version
X-NX-Host
X-Up
X-Transaction
X-External-Request-Id
X-Twitter-Response-Tags
X-Debug-Cache-Store
X-IN-WAF
X-Instart-Isnd
X-Trv-Group
X-Thinkindot-L3
X-IN-APIGATEWAY
X-SRCache-Key
X-Hp-Webp
X-NodeID
X-DPWN-IS-SECURE
X-VG-WebServer
X-Logtrace-Id
X-Server-Group
X-Mobile-URL
X-Matched-Rule
X-Var-Ttl
X-Developer
X-Debug-Cookies
X-Protected-By
X-Secret
X-Debug-Log
X-Destination
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Cache-Backend
X-Irp-Debug
True-Client-Country-4JS
X-Key
Server-Int
Proxy-Connection
X-Li-Pop
RNT-Machine
Rendered-Blocks
X-LI-Proto
Pramga
X-Cache-Info
Server-Host
X-LI-UUID
X-Li-Fabric
RNT-Time
Pagetype
X-LAGOON
X-Hnp-Log
X-Cache-Host
X-Cache-Id
X-Distributor
X-Epic-Correlation-Id
X-Eu-Site
X-Cache-Debug
X-Distil-CS
Lfy
X-Crawler
X-Origin-Date
X-Device-Os
X-CGP
X-Dispatcher-Server
X-C
X-Block-Status
X-Nginx-Cache-Key
X-No-Session
X-Page-Type
X-Info
Web-Mar-Node
X-Hash
X-Geo-Header
X-Gen-Mode
Memcached
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Origin-Expires
User-Cache-Control
X-F5-Cache
Fastly-Backend-Name
X-SN
X-Proxy-Upstream
Apple-News-Services-Host
Fastly-SIE
X-Servername
X-Request-URI
X-Sf
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Country-Code
Backend
Cache-Cookie-Set-From
CDCHOST
Cache-Cookie-Set-Lfrom
X-ScT
Apple-News-Services-Request-Url
X-Proxy-Cache-Status
X-SIPLIST1
X-Policy
Fastly-SWR
X-Webstats-RespID
IsBot
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-WPE-Loopback-Upstream-Addr
Kp-EeAlive
X-Rebelmouse-Surrogate-Control
X-Varnish-Url
Magicmarker
X-Rebelmouse-Cache-Control
X-TT-LOGID
X-Reboot
X-PHP-Host
X-ServiceProvider
X-Qloud-Router
X-Swa-Ws
X-Refresh
Heartbleed
HA-Ipaddr
Ha-Gx-Prefs
Cache-Cookie-Set-Idcheck
DSUID
X-Varnish-Ttl
X-ElasticPress-Search
X-FireWall-Port
X-Core-Mission
X-Cache-Miss-From
X-Server-IP
X-Sedo-Request-Id
X-Developers
X-S-Maxage
X-Fetched-On
X-Thanos
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-GeoIP-Country-Code
X-TrackingId
X-MSEdge-Flight
X-Variation
X-User
X-Ah-Environment
X-Level-Front-Cache
X-GeoIP-City
X-Generated-On
X-Wikidot-Backend
X-Fastly-Cache
X-Wikidot-Static-Cache
X-ShopId
X-Shopify-Stage
X-Skip-Cache
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-ShardId
X-Cache-FS-Status
X-MSEdge-Features
X-Backend-State
Fastly-SSL
Is-Eu
SRV
Adler-Geo
X-Cache-Bucket
SD-X-WS
X-Amzn-Remapped-Content-Length
X-Amz-Meta-Cache-Control
X-Bip
X-BBXSRF
X-Alternate-Cache-Key
HTTPS
N-Cache
Platform
Cteonnt-Length
X-Server-Time
Fastly-Soc-X-Request-Id
X-Node-Id
X-Via-SSL
X-Via-Edge
X-Location
Content-Disposition
ServerName
AKAMAI
X-Owner
X-Cms-Context
X-Micro-Cache
FNAC-ModuleRouting
X-Auto-Login
X-Cdn-Srv
Cache
X-GZip
X-Backend-Url
X-Varnish-Beresp-Ttl
X-Planisys-CDN-TTL
X-RateLimit-Reset
X-Planisys-CDN-Cache
X-Backend-Host
X-Planisys-CDN-Rules
Server-ID
X-Real-Ip
MIME-Version
Powered-By
Gh-Request-Id
Section-Io-Cache
X-Org
X-CUA
X-FPC
X-Sn-Servicetimems
X-Load-Cache
Pragrma
V-Age
X-Nc
X-Pjax-Url
Viewtype
VivaBuild
X-Cdn-Origin
X-Apm-App-Name
REQUESTUUID
X-Apm-Svc-Key
X-Apm-Inst-Hash
X-NC
X-Passed-To-PostProcessResponse
X-Passed-To
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From
X-Server-By
X-Original-Request
X-Stale
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Svr
X-Actual-URL
X-CDN-Forward
HostName
X-ND-Cache
X-Aicache-OS
Fastcgi-Useragent
X-Parent-Response-Time
Rt-Proxy-Cache
X-Exp-Se
X-Geo
X-Served-From
X-Dc
Host-ID
X-CSRF-TOKEN
X-HS-Cache-Config
X-Croise-Owner
X-VServer
X-Unique-ID
X-DC
X-Gdpr
X-Ua-Device
X-Edge-Server
Cdn-Host
Cdn-Request-Time
X-ID
X-B3-Parentspanid
Time
X-Wa
Memory
X-Servedbyhost
X-Microcachable
X-Git-Hash
ProcessTime
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
PICS-Label
X-Oss-Storage-Class
X-Oss-Object-Type
Resin-Trace
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
SID
X-Oss-Server-Time
X-Tb-Optimization-Total-Bytes-Saved
CF-IPCountry
Mime-Version
X-V
X-Req
X-From-Cache
AR-SID
X-Cache-HT
X-Newrelic-Synthetics
X-Optimization
X-Release
Odigeo-Trace-Id
Cdn
X-Host-Name
Cf-Ipcountry
X-WebServer
X-TH-Server
X-HTML-Minification-Powered-By
X-Lb-Id
X-Varnish-Beresp-TTL
X-Fstrz
CF-Cached-On
X-Phone
X-Daa-Tunnel
X-Atg-Version
X-Response-By
XServer
Proxy-Firewall
X-LB-ID
X-Instart-Info
X-APP
X-Upstream-HT
X-Upstream-CT
Public-Key-Pins-Report-Only
Processtime
GMS-Ver
X-WR-MODIFICATION
Backend-Name
X-Ratelimit-Remaining
X-B3-SpanId
X-Check-Cacheable
X-Worker
X-Vcl-Version
WZWS-RAY
X-Fastly-Backend-Reqs
X-Backend-TTL
X-Ratelimit-Limit
X-Zone
Fastcgi-X-Cache-Version
X-CACHE-AGE
X-GEO
X-CLOUD-TRACE-CONTEXT
219prxHost
189phosttRef
225prxHost
409pxxline
355prline
352pxline
286prxHost
188prxHost
Xxline
178proxuri
X-Server-W
X-Nananana
X-NGINX-Cache
X-Vcache
Pics-Label
X-Amz-Meta-Surrogate-Control
X-IPS-LoggedIn
X-SRV
Version
X-Ratelimit-Reset
GW-Server
X-Clientip
Countrycode
X-We-Are-Hiring
X-WA
X-URL
X-HS-Status
X-UE-Client-Country
Mobile-Detection-Method
Lb
X-UPSTREAM-Address
X-ServedByHost
X-VCL-Version
X-CSRF-Token
Serverid
SN
Esi-Enabled
X-Hyper-Cache
SS
X-Fastly-Country-Code
WP-Super-Cache
Ohc-File-Size
DataCenter
X-Contensis-Viewer-Groups
X-SERVER-NAME
GeoIp-Country-Code
X-AssetVersion
GeoIP-Country-Code
Geoip-Latitude
GeoIP-Latitude
GeoIP-City
X-Akamai-Request-ID2
X-GZIP
X-Dynatrace
FSS-Proxy
URI
X-HS-Combine-CSS
FSS-Cache
X-PF-Uncompressing
X-Be
X-Request-Start
X-Via-Ucdn
X-BE
Accept-Language
X-Render-Time
Geoip-City
X-Vtex-Remote-Cache
X-NWS-UUID-VERIFY
X-GDPR
X-LiteSpeed-Cache-Control
X-RequestId
X-Vtex-Processado-Em
X-CS
X-Unique-Id
X-Reqid
X-Fpc
Ohc-Cache-HIT
X-Gen-Id
CDN
X-PJAX-URL
X-ZONE
X-FORWARDED-FOR
FastCGI-Cache
X-HostName
Amp-Access-Control-Allow-Source-Origin
Dynatrace
Locale
X-Html-Edge-Cache
X-Fastly-Cache-Hits
X-UCC
RequestUuid
X-Via-NSCOPI
X-Pf-Uncompressing
X-Urbn-Context-Path
Cneonction
X-Urbn-Site-Id
X-Cdn-Cache
X-Cache-Ttl
IBM-Web2-Location
X-Dw-Trace-Id
Who
Dnion-Transfer-Encoding
X-ABtesting
X-LiteSpeed-Tag
X-Hello
X-Flog
X-Request-Url
Accept-Ch
X-Varnish-Action
Server-Id
A
X-Store
X-Akamai-SSL-Client-Sid
Get-Access-Time
Is-Session-Tracking
X-Port
Frontcache
X-Generation-Time
X-Cdn-Request-ID
X-HTML-Edge-Cache
NnCoection
X-ServerName
X-EC-Lua
Ohc-Response-Time
X-Serial
X-Cache-URL