Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
X-CDN
Upgrade
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Robots-Tag
X-Varnish-Cache
X-Nginx-Cache-Status
X-Server-Powered-By
WPE-Backend
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-CST
X-Host
Content-Location
Feature-Policy
X-Server-Id
X-Cnection
X-Response-Time
X-Type
Report-To
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Origin-Cache
X-Readtime
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Country-Code
X-Cache-Lookup
Rating
NEL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Vhost
X-Ruxit-JS-Agent
X-DynaTrace
Pinterest-Generated-By
X-Mod-Pagespeed
X-Upstream-Env
X-Origin-Upstream-Status
X-Px
X-DataDome
Edge-Control
X-Goog-Hash
Verso
X-Server-Name
Accept-CH
X-HW
X-Dispatcher
X-ORACLE-DMS-RID
X-ESI
MS-Author-Via
X-DataStream-Cache-Status
X-GitHub-Request-Id
AR-CACHE
AR-ATIME
AR-PoweredBy
PB-PID
X-Mobile-Rewrite
PB-RID
Arc-Version
X-VARITI-CCR
X-MS-InvokeApp
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Cached
X-Version
Charset
Content-MD5
X-Dns-Prefetch-Control
X-Powered-By-Plesk
Public-Key-Pins
X-Recruiting
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-TTL
X-Vname
X-PC
X-TtlSet
X-Server-ID
X-Ser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Ar-Sid
X-Varnish-TTL
X-Trace
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-FTR-Realm
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Backend
X-Country-Code-Real
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-FTR-Expires
X-VCache
X-Amz-Rid
X-SharePointHealthScore
X-Fastly-Request-ID
S
X-Amz-Meta-S3cmd-Attrs
X-XRDS-Location
X-Debug
TCN
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-Dw-Request-Base-Id
X-TEC-API-ROOT
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-VERSION
DynaTrace
SPIisLatency
SPRequestDuration
X-Oracle-Dms-Rid
X-Pinterest-Rid
X-Upstream-Proxy
Pinterest-Version
X-Akam-SW-Version
Access-Control-Request-Method
X-T
X-SERVER
X-FTR-Cache-Host
X-Goog-Storage-Class
X-Powered-CMS
Front-End-Https
X-Ttl
X-Id
X-B3-TraceId
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Fastcgi-Cache
Tracecode
X-Amzn-Trace-Id
X-MSEdge-Ref
Realpath
X-N
X-Varnish-Age
Paypal-Debug-Id
X-Content-Type
X-Forwarded-For
X-Upstream
Alternate-Protocol
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-RateLimit-Remaining
X-Sol
Display
X-Middleton-Display
X-Logged-In
X-Frontend
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
X-Middleton-Response
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Response
X-Content-Digest
X-Litespeed-Cache
AMP-Access-Control-Allow-Source-Origin
X-Hostname
X-Cache-Key
X-Pad
X-Accel-Expires
X-Fastcgi-Cache
X-Accel-Buffering
X-Srv
X-Kinsta-Cache
MicrosoftSharePointTeamServices
Server-Name
Host
X-B3-Traceid
Backend-Timing
X-Analytics
X-User-Agent
X-Content-Options
X-Correlation-Id
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Debug-Info
X-Revision
X-LB-Cache
X-Amzn-RequestId
X-AppVersion
Refresh
X-Az
X-Amz-Apigw-Id
X-Activity-Id
Accept-Charset
FilterID
X-Rid
X-IPLB-Instance
X-B3-Sampled
X-Cache-Hit
X-B
X-Grace
X-Cache-2
X-DIS-Request-ID
Surrogate-Key
Powered-By-ChinaCache
X-FastCGI-Cache
X-CF-Powered-By
ServerID
X-Page-Id
X-Whom
Server-Info
TP-Cache
TP-L2-Cache
X-PHP-Backend
MS-CV
Host-Header
X-Webkit-CSP
X-Request-Processing-Time
X-Request-Received
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-Akamai-Edgescape
X-Origin-Server
X-Varnish-Backend
X-Amz-Replication-Status
Source
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cached-By
X-Cluster
X-Kong-Proxy-Latency
X-Cache-Action
X-Framework
X-Kong-Upstream-Latency
Cache-Status
X-App-Environment
X-UA-Device-Type
X-TT
X-GUploader-UploadID
X-Platform-Server
Access-Control-Allow-Method
X-Content-Powered-By
X-Mobile
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Varnish-Grace
X-FW-Hash
X-FW-Static
X-FW-Type
X-Request-Guid
X-Drupal-Cache-Tags
X-FW-Server
X-F-Cache
X-FW-Serve
X-Shard
X-Instance
X-Ezoic-Cdn
X-RateLimit-Limit
X-FB-Debug
X-SS-Set-Cookie
X-Zen-Fury
X-Handled-By
X-Geo-Country
X-Forwarded-Host
X-Magnolia-Registration
Edge-Cache-Tag
PageSpeed
From-Origin
X-Cache-TTL
X-Node-Name
X-ATG-Version
X-Cache-Age
X-Varnish-Hostname
X-App-Server
CACHE
X-Varnish-Server
DC
Cleartype
Cache-Tags
X-BCube-Filmed-By
X-AOL-HN
X-Cache-Control
Payment
Upgrade-Insecure-Requests
Healthy
X-Region
X-RequestSource
X-Response-Served-From
X-Generated-By
X-WebKit-CSP-Report-Only
X-Adobe-Loc
X-Adobe-Content
X-GeoIP
X-TX-ID
X-TT-TIMESTAMP
NGB
X-UUID
Filters
X-Storage
Country
X-Redis-Cache
Webserver
Server-Node
X-VG-WebCache
Cache-Tv-Group
X-RTag
Ms-Operation-Id
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Drupal-Cache-Contexts
Retry-After
Actual-Object-TTL
X-B-Cache
X-FW-Dynamic
X-Jobs
X-Signature
X-Cache-Rule
Fastly-Restarts
X-Locale
X-Content-Age
X-XRDS-LOCATION
X-Cacheable-TTL
GEO-INFO
X-Varnish-Hits
ServedBy
Liferay-Portal
X-Esi
X-Wix-Server-Artifact-Id
X-TA-CDN-Provider
X-Contextid
Powered
X-Seen-By
Frame-Options
X-Oneagent-Js-Injection
HitType
X-Rendered-As
X-Via-JSL
X-Cache-TTL-Remaining
X-Varnish-IP
X-BACKEND-TTL
X-Yottaa-Metrics
X-WA-Info
X-Yottaa-Optimizations
S-Cnection
X-Real-IP
Viewport
X-Guploader-Uploadid
X-ProcessESI
X-RemovedCookies
X-Upgrade-Enabled
X-Cache-Server
Content-Style-Type
X-Cache-NE
Content-Script-Type
Eomportal-Instance
NtCoent-Length
X-Mode
Xserver
Datacenter
X-Cache-Config
X-Akamai-Transformed
X-Cache-Var
X-ES-SERVER
X-Detected-As
X-Device-Type
X-Varnish-Cache-Hits
X-Cache-Var-Map
X-RN-RSRV
Cache-Hits
Load-Balancing
X-Path-Route
X-Hl-Ver
Mn-Server-Ip
X-Routing-Service
X-S
X-Zipkin-Id
X-Proto
Meta-Geo
Machine
X-From
X-Proxied
X-Is-Bot
Cache-Key
X-Origin-Hint
X-Section
Vix-Hermes-Req-Id
X-L-Path
We-Hiring
X-Environment-Context
X-Endurance-Cache-Level
OT-Force-Account-Verify
X-Viewer-Country
X-AWS-Id
X-VWS-Id
TWC-GeoIP-Country
X-LJ-Flow-ID
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-Device-Class
Webcakes-App-Version
Mail-Subject
TWC-Connection-Speed
X-Cache-Enabled
X-FC-Vary-Parameters
Webcakes-Region
X-VG-TLSProxy
X-Tb
X-Hosted-By
L5d-Success-Class
X-Cdn
Property-Id
X-Access
X-Akamai-Request-ID
X-Cache-Operation
Azure-Version
Azure-SlotName
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-TNCMS
Origin-Cache-Control
X-Labrador-Cache-Channel
S-Rt
X-Origin-Response-Time
X-Time
ViewerVersion
X-Via-CDN
X-Wix-Request-Id
X-Loop
Origin-Edge-Control
X-Web-Node
X-FW-Version
NGX
X-Debug-Cache
DB-Nickname
X-Birta-Served
X-Birta-Cache-Post
X-EIG-Tracking-Id
X-ServerID
X-FB-TRIP-ID
X-Format
X-Time-Microsecs
X-Proxy
X-Backend-Name
X-Via-Fastly
Selected-FE
X-Tumblr-Pixel-3
X-IP
X-Human
X-PCL
X-JoinUs
X-Xfnlog-Site
X-NCache
X-OCL
X-Proxy-Build
X-ProxyCache-Key
X-Status
X-CCM
X-Timing-Wait
X-ProxyCache-Status
X-Varnish-Cacheable
X-Trace-Id
X-BYPASS-REASON
Decoy-Debug-TTL
Decoy-Debug-Key
X-GRACE
Cache-Tag
Decoy-Debug-Status
Now
X-Cache-Category-Id
X-Rocket-Nginx-Bypass
Access-Control-Request-Headers
X-Site-Version
X-Www-Served-By
X-Vgn-Hpd-Reason
X-MP-GENERATED-AT
X-Generated
X-Grey
Uber-Trace-Id
Served-By
X-RCS-CacheZone
X-Dynatrace-Js-Agent
X-VC-Cache
X-Newrelic-App-Data
X-R9-Blue-Green-Version
X-EdgeConnect-Cache-Status
X-NWS-LOG-UUID
X-Internal-Host
X-Rule
X-CDN-Cache
X-NewRelic-App-Data
LB
X-Cache-Remote
X-Origin-Host
X-Sucuri-ID
X-UA
AsisCache
X-UnsetCookies
Release
X-Cluster-Node
X-TIME
Nel
Rt-Fastcgi-Cache
User-Agent
X-App-Name
X-APP-VERSION
X-PERF
X-ApacheServer
X-Datadome
X-Ua
X-B3-Spanid
Pagespeed
X-Nginx-Cache
X-Agile-Id
X-Source
X-Agile-Age
X-Agile
X-Request-Time
Cache-Name
Hostname
X-Edge-Location
X-Ocache
X-OVcl
X-OVcl-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Origin
X-Hit
X-Origin-CC
X-Pubstack
X-Sucuri-Cache
X-VCT
X-Origin-TTL
X-App-Version
Warning
X-ElasticPress-Search
X-Edge-IP
Arc-Country
Ajk
Fly-Request-Id
X-Accel-Expires-Debug
X-A-Dgt
X-A-Wwc
MD5-Digest
BehaviorPad-Version
Fly-Cache
X-ARC
Cache-Prefix
X-Application
Cross-Origin-Window-Policy
Ec-Rule-Version
X-Aed
X-A-Dcw
X-A-Dam
Thinkindot-CacheControl-Type
Thinkindot-Control
Request-Country
Thinkindot-CacheControl
Server-Surrogate-Control
Request-Time
Request-EU
Rendered-Blocks
Origin
N-Cache
X-A-Ccd
Server-Cache-Control
Node
On-Server
Www
X-A
Meta-Geo-Continent
X-Developers
X-Request-UUID
X-Region-Sid
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-Processor
X-Platform
X-NodeID
X-Mobile-URL
X-NU-AKA-ACS-Version
X-NX-Host
X-PAYTM-SRV-ID
X-ScT
X-Secret
X-Var-Ttl
X-Up
X-Varnish-Authentication
X-VG-WebServer
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-Server-Group
X-SRCache-Key
X-Thinkindot-L3
X-Transaction
X-Matched-Rule
X-Logtrace-Id
X-Date
X-D
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Core-Value
X-Connection-Hash
X-Cache-ASPX
X-BB-ID
X-Cache-Expires
X-Cache-Grace
X-CF-Lambda-Version
X-Debug-Cookies
X-Debug-Log
X-Hp-Webp
X-Generated-In
X-IN-APIGATEWAY
X-IN-WAF
X-Instart-Isnd
X-Gannett-Site-Version
X-G
X-Destination
X-Developer
X-DPWN-IS-SECURE
X-External-Request-Id
X-B-Cookie
X-CF-Lambda-Fn
X-Protected-By
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Cache-Backend
X-Varnish-Ttl
X-Distributor
X-Eu-Site
X-Epic-Correlation-Id
X-Device-Os
X-Gen-Mode
X-Dispatcher-Server
X-Distil-CS
X-Hnp-Log
X-Key
X-LAGOON
X-Irp-Debug
X-Info
X-Hash
X-Crawler
X-Geo-Header
X-CGP
X-Ah-Environment
X-Amzn-Remapped-Connection
Web-Mar-Node
User-Cache-Control
True-Client-Country-4JS
UCS
X-Amzn-Remapped-Date
X-Block-Status
X-Cache-Miss-From
X-Li-Fabric
X-Cache-Id
X-Cache-Host
X-C
X-Cache-Debug
X-Cms-Context
X-Li-Pop
X-SIPLIST1
X-SN
X-Swa-Ws
X-Sf
X-ServiceProvider
X-Request-URI
X-Sedo-Request-Id
X-Servername
X-TT-LOGID
X-Varnish-Url
X-Cache-Info
X-F5-Cache
X-Webstats-RespID
Memcached
Lfy
X-Via-Edge
X-Via-SSL
X-Refresh
X-Reboot
X-Nginx-Cache-Key
X-No-Session
X-Origin-Expires
X-WPE-Loopback-Upstream-Addr
X-Location
X-LI-Proto
X-LI-UUID
X-Page-Type
X-Real-Ip
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Proxy-Upstream
X-Proxy-Cache-Status
X-PHP-Host
X-Policy
SRV
X-Origin-Date
Fastly-Backend-Name
AKAMAI
Heartbleed
Pagetype
RNT-Machine
Apple-News-Services-Parsed-Url
HA-Ipaddr
Magicmarker
Kp-EeAlive
Apple-News-Services-Host
Fastly-SWR
Fastly-Soc-X-Request-Id
Backend
Fastly-SIE
IsBot
Country-Code
RNT-Time
CDCHOST
Cache-Cookie-Set-Idcheck
Content-Disposition
Server-Int
Server-Host
Apple-News-Services-Request-Url
Proxy-Connection
Apple-News-Services-Handled
Cache-Cookie-Set-Lfrom
Ha-Gx-Prefs
Cache-Cookie-Set-From
Pramga
X-Cdn-Forward
X-FireWall-Port
HTTPS
X-Core-Mission
Platform
X-Level-Front-Cache
X-Variation
X-Micro-Cache
X-Generated-On
X-Gateway-Cache-Key
Adler-Geo
X-Cache-Bucket
X-Wikidot-Backend
X-Fetched-On
X-Wikidot-Static-Cache
X-Fastly-Cache
X-Gateway-Cache-Status
X-GeoIP-City
X-GeoIP-Country-Code
X-User
X-Shopify-Stage
X-Gateway-Skip-Cache
Is-Eu
X-BBXSRF
X-Sorting-Hat-ShopId
X-RateLimit-Limit-Second
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Amz-Meta-Cache-Control
X-Alternate-Cache-Key
X-RateLimit-Remaining-Second
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-Server-IP
X-S-Maxage
SD-X-WS
X-Skip-Cache
X-MSEdge-Features
X-Planisys-CDN-Cache
X-Bip
X-Amzn-Remapped-Content-Length
DSUID
X-TrackingId
X-Node-Id
X-Thanos
X-Backend-Url
Fastly-SSL
X-Cache-FS-Status
X-Backend-Host
X-Backend-State
X-MSEdge-Flight
X-GZip
X-Owner
X-Server-Time
X-RateLimit-Reset
X-Auto-Login
FNAC-ModuleRouting
X-Cdn-Srv
Cteonnt-Length
X-CACHE-KEY
Section-Io-Cache
X-CUA
X-Varnish-Beresp-Ttl
ServerName
Server-ID
Powered-By
X-CDN-Forward
MIME-Version
Gh-Request-Id
Pragrma
X-Org
X-NC
X-Returned-From
Fastcgi-Useragent
X-Apm-Svc-Key
X-Apm-Inst-Hash
X-Returned-From-BeforeDispatch
X-Sn-Servicetimems
X-Passed-To
X-Svr
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Aicache-OS
X-Actual-URL
X-Stale
X-Original-Request
X-Apm-App-Name
REQUESTUUID
X-Cdn-Origin
X-Returned-From-DLL
Viewtype
X-Server-By
X-Parent-Response-Time
VivaBuild
X-Nc
V-Age
X-Returned-From-PostProcessResponse
X-FPC
AR-SID
X-Load-Cache
X-HS-Cache-Config
X-Pjax-Url
X-ND-Cache
Rt-Proxy-Cache
X-Exp-Se
X-Croise-Owner
Host-ID
X-VServer
X-Dc
X-Geo
X-Ua-Device
X-Edge-Server
X-CSRF-TOKEN
HostName
X-Unique-ID
X-Served-From
Cdn-Host
Cdn-Request-Time
X-Gdpr
Cache
X-Microcachable
PICS-Label
X-DC
X-B3-Parentspanid
SID
X-Servedbyhost
X-Oss-Object-Type
X-Oss-Request-Id
Memory
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Wa
Time
X-Oss-Storage-Class
ProcessTime
X-Git-Hash
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
Mime-Version
Resin-Trace
X-V
X-Newrelic-Synthetics
CF-IPCountry
X-From-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Req
X-Optimization
X-Cache-HT
Odigeo-Trace-Id
Cf-Ipcountry
X-Lb-Id
X-HTML-Minification-Powered-By
X-Varnish-Beresp-TTL
Cdn
X-TH-Server
X-Release
X-WebServer
X-Fstrz
X-Atg-Version
X-Host-Name
Proxy-Firewall
X-Phone
X-Response-By
XServer
X-ID
Public-Key-Pins-Report-Only
CF-Cached-On
GMS-Ver
X-APP
Processtime
X-LB-ID
X-Instart-Info
X-WR-MODIFICATION
X-Daa-Tunnel
X-Ratelimit-Remaining
X-Fastly-Backend-Reqs
X-Upstream-HT
X-Vcl-Version
X-Ratelimit-Limit
X-Upstream-CT
WZWS-RAY
Backend-Name
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
X-GEO
Fastcgi-X-Cache-Version
X-Worker
X-Zone
X-Check-Cacheable
X-SRV
286prxHost
X-Nananana
189phosttRef
219prxHost
225prxHost
355prline
Xxline
X-Server-W
X-Amz-Meta-Surrogate-Control
178proxuri
X-Vcache
188prxHost
X-NGINX-Cache
409pxxline
352pxline
X-B3-SpanId
X-URL
X-Clientip
X-WA
Countrycode
X-HS-Status
Mobile-Detection-Method
X-IPS-LoggedIn
X-We-Are-Hiring
X-UE-Client-Country
X-Ratelimit-Reset
GW-Server
Version
Lb
Pics-Label
X-Hyper-Cache
X-Fastly-Country-Code
SS
SN
X-Backend-TTL
X-CSRF-Token
X-ServedByHost
Ohc-File-Size
DataCenter
Esi-Enabled
Geoip-Latitude
GeoIp-Country-Code
X-VCL-Version
X-SERVER-NAME
X-FORWARDED-FOR
X-GZIP
X-Dynatrace
GeoIP-City
GeoIP-Country-Code
X-Contensis-Viewer-Groups
X-Request-Start
GeoIP-Latitude
X-UPSTREAM-Address
Geoip-City
X-BE
X-HS-Combine-CSS
FSS-Cache
URI
X-AssetVersion
X-Render-Time
FSS-Proxy
X-PF-Uncompressing
Serverid
X-Akamai-Request-ID2
X-Via-Ucdn
X-Cache-Ttl
X-CS
X-LiteSpeed-Cache-Control
Accept-Language
X-Be
X-GDPR
CDN
X-PJAX-URL
WP-Super-Cache
X-Unique-Id
X-Vtex-Remote-Cache
X-NWS-UUID-VERIFY
Ohc-Cache-HIT
X-ZONE
X-RequestId
X-Fpc
X-Vtex-Processado-Em
X-Cdn-Cache
X-Gen-Id
X-HostName
Dynatrace
Amp-Access-Control-Allow-Source-Origin
X-ABtesting
Locale
X-Pf-Uncompressing
X-Via-NSCOPI
X-Flog
X-Urbn-Site-Id
X-Reqid
Cneonction
X-Hello
X-Urbn-Context-Path
RequestUuid
X-Fastly-Cache-Hits
X-UCC
X-Html-Edge-Cache
X-Request-Url
X-LiteSpeed-Tag
Who
A
Server-Id
X-Store
X-Varnish-Action
Accept-Ch
X-Akamai-SSL-Client-Sid
X-HTML-Edge-Cache
X-Cdn-Request-ID
IBM-Web2-Location
Dnion-Transfer-Encoding
X-Port
Is-Session-Tracking
X-Serial
X-ServerName
NnCoection
X-EC-Lua
Frontcache
Get-Access-Time
Ohc-Response-Time
X-Cache-URL