Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
X-CDN
Upgrade
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
X-Ua-Compatible
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Age
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Robots-Tag
X-Varnish-Cache
X-Server-Powered-By
X-Nginx-Cache-Status
WPE-Backend
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-CST
X-Host
Content-Location
Feature-Policy
X-Server-Id
X-Cnection
X-Response-Time
X-Type
Report-To
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Origin-Cache
X-Readtime
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Country-Code
X-Cache-Lookup
Rating
NEL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Vhost
X-Ruxit-JS-Agent
X-DynaTrace
Pinterest-Generated-By
X-Mod-Pagespeed
X-Upstream-Env
X-Origin-Upstream-Status
X-Px
X-DataDome
Edge-Control
X-Goog-Hash
Verso
Accept-CH
X-HW
X-Dispatcher
X-Server-Name
X-ORACLE-DMS-RID
X-ESI
MS-Author-Via
X-DataStream-Cache-Status
X-VARITI-CCR
AR-ATIME
AR-PoweredBy
AR-CACHE
PB-RID
X-Mobile-Rewrite
PB-PID
Arc-Version
X-GitHub-Request-Id
X-MS-InvokeApp
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Cached
Charset
X-Version
Content-MD5
X-Dns-Prefetch-Control
X-Powered-By-Plesk
X-Recruiting
Public-Key-Pins
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
X-D2id
X-Abt-Application-Version
X-Navigation-Version
X-TTL
X-TtlSet
X-Vname
X-PC
X-Ser
X-Server-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Ar-Sid
X-Varnish-TTL
X-Trace
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-DC
X-FTR-Cache-Status
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-FTR-Expires
X-VCache
X-Amz-Rid
X-SharePointHealthScore
S
X-Fastly-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Debug
X-XRDS-Location
TCN
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Hits
X-TEC-API-VERSION
X-Dw-Request-Base-Id
DynaTrace
X-Pinterest-Rid
X-Upstream-Proxy
Pinterest-Version
X-Oracle-Dms-Rid
SPIisLatency
SPRequestDuration
X-Akam-SW-Version
Access-Control-Request-Method
X-T
X-FTR-Cache-Host
X-SERVER
X-Goog-Storage-Class
X-Powered-CMS
Front-End-Https
X-Ttl
X-Id
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Fastcgi-Cache
Tracecode
X-Amzn-Trace-Id
X-MSEdge-Ref
Realpath
X-N
X-Varnish-Age
Paypal-Debug-Id
X-B3-TraceId
X-Content-Type
X-Forwarded-For
X-Upstream
Alternate-Protocol
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-RateLimit-Remaining
X-Frontend
X-Logged-In
Display
X-Middleton-Display
X-Sol
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
X-Content-Digest
X-Middleton-Response
Fusion-Content-Id
Response
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
X-Litespeed-Cache
AMP-Access-Control-Allow-Source-Origin
X-Hostname
X-B3-Traceid
X-Cache-Key
X-Pad
X-Accel-Expires
X-Fastcgi-Cache
X-Accel-Buffering
X-Srv
X-Kinsta-Cache
Server-Name
MicrosoftSharePointTeamServices
Host
X-Content-Options
X-Analytics
X-User-Agent
Backend-Timing
X-Correlation-Id
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-LB-Cache
X-Revision
X-Debug-Info
X-Az
X-Rid
Refresh
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Activity-Id
X-AppVersion
Accept-Charset
FilterID
X-IPLB-Instance
X-B
X-Cache-2
X-B3-Sampled
X-Cache-Hit
X-Grace
X-DIS-Request-ID
Powered-By-ChinaCache
Surrogate-Key
X-CF-Powered-By
X-FastCGI-Cache
ServerID
X-Page-Id
X-Whom
Server-Info
TP-Cache
X-PHP-Backend
TP-L2-Cache
MS-CV
X-Request-Received
X-Request-Processing-Time
Host-Header
X-Webkit-CSP
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
Source
X-Akamai-Edgescape
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cached-By
X-Origin-Server
X-Amz-Replication-Status
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cache-Status
X-App-Environment
X-Cluster
X-UA-Device-Type
X-TT
X-Cache-Action
X-Tumblr-Pixel-0
X-Platform-Server
X-Content-Powered-By
X-GUploader-UploadID
X-Tumblr-User
X-Tumblr-Pixel
Access-Control-Allow-Method
X-Mobile
X-Framework
X-Request-Guid
X-FW-Type
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Serve
X-Drupal-Cache-Tags
X-Varnish-Grace
X-F-Cache
X-Shard
X-RateLimit-Limit
X-Instance
X-Ezoic-Cdn
X-Zen-Fury
X-FB-Debug
X-SS-Set-Cookie
X-Handled-By
X-Geo-Country
X-Magnolia-Registration
X-Forwarded-Host
Edge-Cache-Tag
PageSpeed
From-Origin
X-Cache-TTL
X-ATG-Version
X-Node-Name
X-Cache-Age
X-Varnish-Hostname
X-App-Server
CACHE
DC
X-Varnish-Server
Cache-Tags
Cleartype
X-BCube-Filmed-By
X-AOL-HN
X-Cache-Control
Payment
Upgrade-Insecure-Requests
Healthy
X-Region
X-RequestSource
X-Generated-By
Filters
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-Adobe-Content
X-Adobe-Loc
X-GeoIP
X-TX-ID
X-UUID
X-Redis-Cache
X-VG-WebCache
X-TT-TIMESTAMP
X-RTag
Server-Node
Ms-Operation-Id
NGB
Cache-Tv-Group
X-Storage
Country
Webserver
X-B-Cache
X-Cache-Rule
Retry-After
Actual-Object-TTL
X-Drupal-Cache-Contexts
X-FW-Dynamic
X-Jobs
X-Signature
X-Tumblr-Pixel-2
Fastly-Restarts
X-Tumblr-Pixel-1
X-Content-Age
X-XRDS-LOCATION
X-Locale
X-Cacheable-TTL
GEO-INFO
X-Varnish-Hits
ServedBy
Liferay-Portal
X-Wix-Server-Artifact-Id
X-Esi
X-Contextid
X-Seen-By
Powered
X-TA-CDN-Provider
Frame-Options
X-Oneagent-Js-Injection
HitType
X-Rendered-As
X-Via-JSL
X-Cache-TTL-Remaining
X-Varnish-IP
X-BACKEND-TTL
X-WA-Info
X-Yottaa-Optimizations
X-Yottaa-Metrics
S-Cnection
Viewport
X-Real-IP
X-Guploader-Uploadid
X-Upgrade-Enabled
X-RemovedCookies
Eomportal-Instance
X-ProcessESI
Content-Style-Type
Content-Script-Type
NtCoent-Length
X-Cache-NE
X-Cache-Server
X-Mode
Datacenter
Xserver
X-Time
X-Akamai-Transformed
X-Cache-Config
X-Path-Route
X-ES-SERVER
Machine
X-Cache-Var
X-Zipkin-Id
Mn-Server-Ip
X-Routing-Service
X-Device-Type
X-Cache-Var-Map
X-Varnish-Cache-Hits
X-From
Load-Balancing
X-Detected-As
X-RN-RSRV
X-Proto
Meta-Geo
X-S
X-Is-Bot
X-Proxied
Cache-Hits
X-Hl-Ver
Cache-Key
TWC-Locale-Group
X-Environment-Context
X-Section
X-Endurance-Cache-Level
X-AWS-Id
X-Origin-Hint
Webcakes-App-Version
TWC-Device-Class
Webcakes-Region
L5d-Success-Class
X-Tb
X-Hosted-By
X-Viewer-Country
OT-Force-Account-Verify
X-Cdn
TWC-Connection-Speed
X-FC-Vary-Parameters
X-Cache-Enabled
X-VWS-Id
TWC-Privacy
X-VG-TLSProxy
Access-Control-Request-Headers
Vix-Hermes-Req-Id
X-L-Path
TWC-GeoIP-Country
Mail-Subject
Property-Id
X-LJ-Flow-ID
TWC-GeoIP-LatLong
We-Hiring
Webcakes-App-Name
X-Access
DB-Nickname
X-Origin-Response-Time
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
X-Cache-Operation
Azure-InstanceId
ViewerVersion
X-EIG-Tracking-Id
X-Format
X-Web-Node
NGX
X-TNCMS
X-Labrador-Cache-Channel
Origin-Cache-Control
X-FW-Version
S-Rt
Origin-Edge-Control
X-Wix-Request-Id
X-Time-Microsecs
X-Via-CDN
X-Birta-Served
X-Birta-Cache-Post
X-Backend-Name
X-Debug-Cache
X-ServerID
X-FB-TRIP-ID
X-Akamai-Request-ID
X-Proxy
X-Loop
Selected-FE
X-ProxyCache-Key
X-Xfnlog-Site
X-Varnish-Cacheable
X-Trace-Id
X-JoinUs
X-IP
X-Via-Fastly
X-Human
X-Timing-Wait
X-Tumblr-Pixel-3
X-Proxy-Build
X-BYPASS-REASON
X-OCL
X-CCM
X-ProxyCache-Status
X-Status
X-NCache
X-PCL
Decoy-Debug-TTL
Now
Cache-Tag
Decoy-Debug-Status
X-GRACE
Decoy-Debug-Key
X-Cache-Category-Id
X-Vgn-Hpd-Reason
X-Grey
X-Generated
X-Rocket-Nginx-Bypass
X-Site-Version
X-MP-GENERATED-AT
X-Www-Served-By
Uber-Trace-Id
X-RCS-CacheZone
Served-By
X-VC-Cache
X-Newrelic-App-Data
X-Dynatrace-Js-Agent
X-R9-Blue-Green-Version
X-NWS-LOG-UUID
X-EdgeConnect-Cache-Status
X-Internal-Host
X-CDN-Cache
X-Rule
X-NewRelic-App-Data
X-Cache-Remote
X-Origin-Host
LB
X-UA
X-Sucuri-ID
AsisCache
Release
X-UnsetCookies
X-Cluster-Node
Nel
User-Agent
X-App-Name
Rt-Fastcgi-Cache
X-PERF
X-APP-VERSION
X-ApacheServer
X-TIME
X-B3-Spanid
X-Datadome
X-Ua
X-Source
Pagespeed
X-Agile-Age
X-Agile-Id
X-Agile
X-Nginx-Cache
X-Request-Time
X-Ocache
X-Edge-Location
Cache-Name
Hostname
X-Hit
X-OVcl-Cache
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl
X-VCT
X-Pubstack
X-Origin-CC
X-Origin-TTL
X-Sucuri-Cache
X-App-Version
Warning
X-Edge-IP
X-ElasticPress-Search
X-A
X-Accel-Expires-Debug
X-Aed
X-Application
X-ARC
X-A-Wwc
X-A-Dgt
X-A-Dam
X-A-Dcw
X-A-Ccd
Origin
Fly-Request-Id
Fly-Cache
MD5-Digest
Meta-Geo-Continent
N-Cache
Ec-Rule-Version
Cross-Origin-Window-Policy
Ajk
Arc-Country
BehaviorPad-Version
Cache-Prefix
Node
On-Server
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
UCS
Server-Surrogate-Control
Server-Cache-Control
Rendered-Blocks
Request-Country
Request-EU
Request-Time
Www
X-Developer
X-Request-UUID
X-Region-Sid
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-Processor
X-Platform
X-NodeID
X-Mobile-URL
X-NU-AKA-ACS-Version
X-NX-Host
X-PAYTM-SRV-ID
X-ScT
X-Secret
X-Var-Ttl
X-Up
X-Varnish-Authentication
X-VG-WebServer
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-Server-Group
X-SRCache-Key
X-Thinkindot-L3
X-Transaction
X-Matched-Rule
X-Logtrace-Id
X-Date
X-D
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Core-Value
X-Connection-Hash
X-Cache-ASPX
X-BB-ID
X-Cache-Expires
X-Cache-Grace
X-CF-Lambda-Version
X-Debug-Cookies
X-Debug-Log
X-Hp-Webp
X-Generated-In
X-IN-APIGATEWAY
X-IN-WAF
X-Instart-Isnd
X-Gannett-Site-Version
X-G
X-Destination
X-Developers
X-DPWN-IS-SECURE
X-External-Request-Id
X-B-Cookie
X-CF-Lambda-Fn
X-Protected-By
X-Varnish-Beresp-Status
X-Cache-Backend
X-Varnish-Beresp-Grace
X-Varnish-Ttl
X-Eu-Site
X-Gen-Mode
X-Epic-Correlation-Id
X-Distil-CS
X-Dispatcher-Server
X-Geo-Header
X-Distributor
X-Hnp-Log
X-Key
X-LAGOON
X-Irp-Debug
X-Info
X-Li-Fabric
X-Device-Os
X-Hash
X-Cms-Context
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Ah-Environment
Web-Mar-Node
True-Client-Country-4JS
User-Cache-Control
X-Block-Status
X-C
X-CGP
X-Li-Pop
X-Cache-Miss-From
X-Cache-Id
X-Cache-Debug
X-Cache-Host
X-Crawler
X-LI-Proto
X-SIPLIST1
X-SN
X-Swa-Ws
X-Sf
X-ServiceProvider
X-Request-URI
X-Sedo-Request-Id
X-Servername
X-TT-LOGID
X-Varnish-Url
X-Cache-Info
X-F5-Cache
X-Webstats-RespID
Memcached
Lfy
X-Via-Edge
X-Via-SSL
X-Refresh
X-Reboot
X-Origin-Date
X-Page-Type
X-Real-Ip
X-No-Session
X-Nginx-Cache-Key
X-LI-UUID
X-Location
X-PHP-Host
X-Policy
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-RateLimit-Limit-Second
X-Qloud-Router
X-Proxy-Cache-Status
X-Proxy-Upstream
SRV
X-Origin-Expires
RNT-Machine
Backend
RNT-Time
Apple-News-Services-Request-Url
Magicmarker
Fastly-SWR
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Country-Code
CDCHOST
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Kp-EeAlive
IsBot
HA-Ipaddr
Heartbleed
Ha-Gx-Prefs
Cache-Cookie-Set-From
Fastly-Soc-X-Request-Id
Content-Disposition
Pramga
Pagetype
Fastly-Backend-Name
Fastly-SIE
Server-Host
Server-Int
X-Cdn-Forward
X-FireWall-Port
X-ShardId
X-Shopify-Stage
Platform
X-Micro-Cache
X-ShopId
X-Fetched-On
X-S-Maxage
X-Gateway-Cache-Status
X-Node-Id
HTTPS
Is-Eu
X-MSEdge-Flight
X-Level-Front-Cache
X-WPE-Loopback-Upstream-Addr
X-MSEdge-Features
X-GeoIP-Country-Code
X-GeoIP-City
X-Gateway-Cache-Key
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Skip-Cache
X-Gateway-Skip-Cache
X-Generated-On
Fastly-SSL
X-Planisys-CDN-TTL
X-Core-Mission
X-User
X-Wikidot-Static-Cache
X-Backend-Url
X-Thanos
X-Wikidot-Backend
DSUID
X-Amzn-Remapped-Content-Length
X-Amz-Meta-Cache-Control
X-Bip
X-Alternate-Cache-Key
X-Cache-Bucket
Adler-Geo
Proxy-Connection
X-Backend-State
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Backend-Host
X-Cache-FS-Status
X-Fastly-Cache
X-Variation
SD-X-WS
X-GZip
Cteonnt-Length
FNAC-ModuleRouting
X-Cdn-Srv
X-Owner
X-RateLimit-Reset
X-Auto-Login
X-Server-Time
X-Server-IP
X-BBXSRF
X-TrackingId
X-CACHE-KEY
X-CUA
ServerName
X-Varnish-Beresp-Ttl
Server-ID
Section-Io-Cache
Powered-By
X-CDN-Forward
Gh-Request-Id
MIME-Version
Pragrma
X-Org
X-NC
X-Stale
V-Age
X-Sn-Servicetimems
X-Apm-Svc-Key
X-Apm-Inst-Hash
X-Cdn-Origin
X-Apm-App-Name
X-FPC
X-Server-By
X-Load-Cache
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Nc
X-Passed-To-PostProcessResponse
X-Svr
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Original-Request
X-Returned-From
X-Parent-Response-Time
VivaBuild
X-Actual-URL
Viewtype
REQUESTUUID
AR-SID
Fastcgi-Useragent
X-Aicache-OS
X-Croise-Owner
X-VServer
X-HS-Cache-Config
Rt-Proxy-Cache
X-Dc
X-Pjax-Url
X-Exp-Se
X-ND-Cache
Host-ID
X-Geo
X-Ua-Device
X-Gdpr
X-Edge-Server
X-Served-From
Cdn-Host
HostName
X-CSRF-TOKEN
X-Unique-ID
Cdn-Request-Time
Cache
X-Microcachable
PICS-Label
X-DC
X-B3-Parentspanid
X-Servedbyhost
Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
SID
X-Oss-Server-Time
X-Oss-Request-Id
Memory
X-Wa
X-Oss-Storage-Class
ProcessTime
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
Mime-Version
Resin-Trace
X-Git-Hash
X-Newrelic-Synthetics
X-V
X-From-Cache
X-Tb-Optimization-Total-Bytes-Saved
CF-IPCountry
X-Req
X-Cache-HT
X-Optimization
Odigeo-Trace-Id
Cf-Ipcountry
X-HTML-Minification-Powered-By
X-Release
X-Lb-Id
X-Varnish-Beresp-TTL
X-WebServer
X-Fstrz
Cdn
X-TH-Server
X-Host-Name
X-Atg-Version
XServer
X-Phone
Proxy-Firewall
X-Response-By
CF-Cached-On
Public-Key-Pins-Report-Only
X-ID
X-WR-MODIFICATION
X-APP
Processtime
X-LB-ID
X-Instart-Info
GMS-Ver
X-SERVER-NAME
X-Daa-Tunnel
X-Ratelimit-Remaining
WZWS-RAY
Backend-Name
X-Ratelimit-Limit
X-Vcl-Version
X-Upstream-CT
X-Fastly-Backend-Reqs
X-Upstream-HT
X-CLOUD-TRACE-CONTEXT
X-GEO
X-CACHE-AGE
Fastcgi-X-Cache-Version
X-Worker
X-Zone
X-Check-Cacheable
355prline
225prxHost
352pxline
286prxHost
219prxHost
X-SRV
X-Vcache
X-NGINX-Cache
X-Nananana
409pxxline
178proxuri
188prxHost
189phosttRef
Xxline
X-Server-W
X-Amz-Meta-Surrogate-Control
X-B3-SpanId
X-IPS-LoggedIn
Countrycode
GW-Server
Mobile-Detection-Method
X-We-Are-Hiring
X-Clientip
X-Ratelimit-Reset
X-WA
X-HS-Status
X-UE-Client-Country
X-URL
Version
Lb
SN
Pics-Label
SS
X-Hyper-Cache
X-CSRF-Token
X-ServedByHost
X-Fastly-Country-Code
X-Backend-TTL
Ohc-File-Size
DataCenter
X-VCL-Version
Esi-Enabled
Geoip-Latitude
X-FORWARDED-FOR
GeoIp-Country-Code
X-GZIP
WP-Super-Cache
X-Dynatrace
GeoIP-Latitude
X-Render-Time
GeoIP-Country-Code
FSS-Proxy
Geoip-City
X-UPSTREAM-Address
X-PF-Uncompressing
X-HS-Combine-CSS
X-AssetVersion
X-Contensis-Viewer-Groups
X-BE
X-Request-Start
GeoIP-City
URI
FSS-Cache
Serverid
X-Akamai-Request-ID2
X-CS
X-GDPR
X-LiteSpeed-Cache-Control
X-Via-Ucdn
X-Cache-Ttl
X-PJAX-URL
Accept-Language
X-Be
CDN
X-Unique-Id
X-Vtex-Remote-Cache
X-ZONE
X-Gen-Id
X-NWS-UUID-VERIFY
X-Vtex-Processado-Em
X-Cdn-Cache
Ohc-Cache-HIT
X-RequestId
X-Fpc
Amp-Access-Control-Allow-Source-Origin
X-HostName
Dynatrace
X-Html-Edge-Cache
X-Urbn-Context-Path
X-UCC
RequestUuid
Locale
X-Pf-Uncompressing
X-Urbn-Site-Id
X-Via-NSCOPI
X-Reqid
X-ABtesting
X-Fastly-Cache-Hits
X-Hello
X-Flog
Cneonction
X-LiteSpeed-Tag
Accept-Ch
X-Request-Url
Server-Id
Who
X-Store
X-Varnish-Action
A
X-Akamai-SSL-Client-Sid
X-Cdn-Request-ID
X-Port
NnCoection
X-Cache-URL
IBM-Web2-Location
Dnion-Transfer-Encoding
Get-Access-Time
Is-Session-Tracking
X-Serial
X-HTML-Edge-Cache
X-ServerName
Ohc-Response-Time
X-EC-Lua
Frontcache