Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
ETag
Link
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
CF-Ray
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Pass-Why
X-Cache-Group
X-AH-Environment
P3p
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
WPE-Backend
X-Robots-Tag
X-Nginx-Cache-Status
X-Server-Powered-By
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Device
Allow
Ali-Swift-Global-Savetime
Server-Timing
X-Type
X-CST
X-Ac
X-Node
X-Rq
X-Server-Id
X-Host
Feature-Policy
Content-Location
X-Response-Time
X-Cnection
Report-To
X-Backend-Server
X-Application-Context
Surrogate-Control
X-Iejgwucgyu
EagleEye-TraceId
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Readtime
X-Origin-Cache
X-Rack-Cache
Request-Id
X-Url
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
NEL
X-Instart-Request-ID
X-Upstream-Env
X-Mod-Pagespeed
X-Dns-Prefetch-Control
X-Ruxit-JS-Agent
Pinterest-Generated-By
X-Vhost
X-DynaTrace
X-Px
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Goog-Hash
X-Server-Name
Verso
X-ESI
Accept-CH
X-Dispatcher
X-HW
Charset
X-GitHub-Request-Id
X-VARITI-CCR
X-Mobile-Rewrite
PB-PID
MS-Author-Via
Arc-Version
PB-RID
X-MS-InvokeApp
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cached
AR-CACHE
X-Version
AR-ATIME
AR-PoweredBy
X-DataStream-Cache-Status
X-Powered-By-Plesk
Content-MD5
X-Recruiting
Public-Key-Pins
X-ORACLE-DMS-RID
Service-Worker-Allowed
Accept-CH-Lifetime
X-D2id
X-Vname
X-PC
X-TtlSet
X-Navigation-Version
AR-Request-ID
X-Abt-Application-Version
RTSS
Ar-Sid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ser
X-TTL
X-Trace
X-Varnish-TTL
SPRequestGuid
X-Forwarded-Proto
X-Client-IP
X-Vcap-Request-Id
X-DynaTrace-JS-Agent
X-Oracle-Dms-Rid
X-Amz-Server-Side-Encryption
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend
X-SharePointHealthScore
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Amz-Rid
X-Fastly-Request-ID
X-FTR-Expires
S
X-VCache
Arr-Disable-Session-Affinity
Nginx-Cache
X-Amz-Meta-S3cmd-Attrs
X-Shield-Request-Id
X-Debug
X-Server-ID
TCN
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Proxy
X-Id
X-Dw-Request-Base-Id
X-Hits
X-XRDS-Location
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ttl
SPRequestDuration
SPIisLatency
X-Akam-SW-Version
DynaTrace
Front-End-Https
Access-Control-Request-Method
X-FTR-Cache-Host
X-Goog-Storage-Class
X-T
X-Powered-CMS
Realpath
X-NF-Request-ID
X-SERVER
X-Acc-Meta-Resource-Type
Paypal-Debug-Id
Tracecode
X-MSEdge-Ref
X-Amzn-Trace-Id
X-Varnish-Age
X-B3-TraceId
X-Aspnet-Version
Fastcgi-Cache
X-Forwarded-For
X-N
X-Content-Type
Alternate-Protocol
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
X-Upstream
X-RateLimit-Remaining
X-PressLabs-Stats
X-Accel-Buffering
X-Frontend
Fusion-Template-Id
Fusion-Content-Id
X-HS-Hub-Id
X-Logged-In
Fusion-Source
Fusion-Content-Source
X-HS-Content-Id
Fusion-Component-Id
X-Content-Digest
X-Sol
X-Middleton-Display
Display
X-Srv
Response
X-Middleton-Response
X-Hostname
AMP-Access-Control-Allow-Source-Origin
X-Litespeed-Cache
X-Fastcgi-Cache
X-Kinsta-Cache
X-B3-Traceid
X-Cache-Key
X-Pad
Server-Name
X-Accel-Expires
MicrosoftSharePointTeamServices
X-User-Agent
X-Content-Options
Host
Refresh
X-Analytics
X-DIS-Request-ID
Backend-Timing
X-Grace
X-Correlation-Id
X-LB-Cache
X-Revision
X-Rid
X-IPLB-Instance
X-Debug-Info
X-Activity-Id
X-Az
X-AppVersion
Accept-Charset
X-Amz-Apigw-Id
X-B
X-Amzn-RequestId
FilterID
X-CF-Powered-By
X-Cache-Hit
ServerID
X-B3-Sampled
Powered-By-ChinaCache
X-Cdn
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Cache-2
Surrogate-Key
X-Page-Id
X-FastCGI-Cache
X-Whom
X-Ruxit-Js-Agent
Server-Info
X-PHP-Backend
TP-L2-Cache
TP-Cache
X-Varnish-Backend
Host-Header
X-Request-Received
X-Content-Security-Policy-Report-Only
X-Request-Processing-Time
MS-CV
X-Amz-Replication-Status
X-F-Cache
X-TT
X-Akamai-Edgescape
X-Origin-Server
VIX-Pulpo-Node
Source
VIX-Pulpo-Upstream-Status
X-Cluster
X-Framework
X-Tumblr-Pixel-0
X-Tumblr-User
X-UA-Device-Type
X-Tumblr-Pixel
X-Cache-Action
X-App-Environment
X-Webkit-CSP
X-FW-Type
X-FW-Hash
X-Mobile
X-Platform-Server
X-FW-Static
X-Instance
X-FW-Server
X-FW-Serve
Cache-Status
X-RateLimit-Limit
X-Varnish-Grace
X-Content-Powered-By
X-Drupal-Cache-Tags
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cached-By
X-Handled-By
Access-Control-Allow-Method
X-Request-Guid
X-Zen-Fury
X-SS-Set-Cookie
X-Geo-Country
CACHE
X-Magnolia-Registration
X-Ezoic-Cdn
X-FB-Debug
X-Shard
X-Cache-TTL
X-ATG-Version
X-Forwarded-Host
Edge-Cache-Tag
X-Wix-Server-Artifact-Id
From-Origin
X-App-Server
PageSpeed
DC
X-Cache-Age
X-Varnish-Server
Cleartype
X-Node-Name
X-Varnish-Hostname
X-AOL-HN
X-GUploader-UploadID
Cache-Tags
X-XRDS-LOCATION
X-BCube-Filmed-By
X-Cache-Control
Payment
X-Region
X-Generated-By
X-Signature
X-B-Cache
X-RequestSource
X-Response-Served-From
X-WebKit-CSP-Report-Only
Filters
X-Adobe-Content
X-GeoIP
Healthy
X-Adobe-Loc
X-TX-ID
Upgrade-Insecure-Requests
Webserver
X-VG-WebCache
Ms-Operation-Id
NGB
X-FW-Dynamic
GEO-INFO
Country
X-UUID
X-Seen-By
X-TT-TIMESTAMP
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Guploader-Uploadid
X-RTag
X-Tumblr-Pixel-1
Server-Node
X-Jobs
Retry-After
X-Redis-Cache
X-Drupal-Cache-Contexts
X-Varnish-Hits
Actual-Object-TTL
ServedBy
X-Via-JSL
X-Storage
X-Content-Age
X-Cacheable-TTL
Liferay-Portal
X-Locale
X-Cache-Rule
X-Contextid
X-Rendered-As
Fastly-Restarts
HitType
X-Varnish-IP
X-Cache-TTL-Remaining
Powered
Frame-Options
X-BACKEND-TTL
X-Oneagent-Js-Injection
S-Cnection
Viewport
X-WA-Info
X-Wix-Request-Id
ViewerVersion
Content-Script-Type
Content-Style-Type
X-Yottaa-Metrics
X-NewRelic-App-Data
X-Cache-Server
X-Yottaa-Optimizations
X-Real-IP
X-Upgrade-Enabled
NtCoent-Length
Datacenter
X-Cache-Config
X-ProcessESI
X-Mode
X-TA-CDN-Provider
Xserver
X-RemovedCookies
Eomportal-Instance
X-Esi
X-Varnish-Cache-Hits
Nel
X-Endurance-Cache-Level
X-Akamai-Transformed
Machine
X-Path-Route
X-Is-Bot
X-Hl-Ver
X-Proxied
X-RN-RSRV
X-Zipkin-Id
X-Routing-Service
X-ES-SERVER
X-Device-Type
Load-Balancing
Cache-Key
Meta-Geo
X-Cache-Var
X-Detected-As
X-Cache-Var-Map
Cache-Hits
X-Proto
X-AWS-Id
X-Backend-Name
X-Access
Webcakes-Region
Webcakes-App-Version
X-Cache-NE
X-Cache-Enabled
X-Hosted-By
X-L-Path
X-S
X-FW-Version
X-Format
Webcakes-App-Name
We-Hiring
L5d-Success-Class
TWC-Connection-Speed
Mail-Subject
Property-Id
OT-Force-Account-Verify
TWC-Device-Class
TWC-GeoIP-Country
TWC-Privacy
Vix-Hermes-Req-Id
TWC-Locale-Group
TWC-GeoIP-LatLong
Access-Control-Request-Headers
X-LJ-Flow-ID
X-Environment-Context
X-VWS-Id
X-Section
X-VG-TLSProxy
X-Status
X-Proxy
X-Viewer-Country
X-Origin-Hint
X-Time-Microsecs
X-Loop
X-Tb
X-Akamai-Request-ID
X-ServerID
X-TNCMS
Azure-Version
Azure-RegionName
Azure-SiteName
X-Via-Fastly
Azure-SlotName
Azure-InstanceId
X-Birta-Cache-Post
X-Origin-Response-Time
X-FC-Vary-Parameters
Mn-Server-Ip
X-From
X-Labrador-Cache-Channel
Now
X-Time
X-EIG-Tracking-Id
DB-Nickname
X-Birta-Served
S-Rt
Decoy-Debug-Key
Selected-FE
Decoy-Debug-Status
X-Xfnlog-Site
Decoy-Debug-TTL
X-Web-Node
X-Timing-Wait
X-Proxy-Build
X-IP
X-JoinUs
X-NCache
Origin-Edge-Control
X-Debug-Cache
X-ProxyCache-Status
X-BYPASS-REASON
X-ProxyCache-Key
X-CCM
X-Trace-Id
X-Varnish-Cacheable
Cache-Tag
Origin-Cache-Control
X-Internal-Host
X-Human
X-Grey
Served-By
X-MP-GENERATED-AT
X-Origin-Host
X-Via-CDN
X-Tumblr-Pixel-3
X-Www-Served-By
X-PCL
X-Cache-Category-Id
X-OCL
X-Generated
X-FB-TRIP-ID
X-GRACE
NGX
Uber-Trace-Id
X-Cache-Operation
X-Site-Version
X-CDN-Cache
X-Rocket-Nginx-Bypass
AsisCache
User-Agent
X-Vgn-Hpd-Reason
X-EdgeConnect-Cache-Status
LB
X-UA
X-Dynatrace-Js-Agent
X-VC-Cache
X-NWS-LOG-UUID
X-R9-Blue-Green-Version
X-Rule
X-Sucuri-ID
X-Cluster-Node
X-Newrelic-App-Data
Rt-Fastcgi-Cache
Hostname
X-Cache-Remote
X-RCS-CacheZone
X-App-Name
Release
X-UnsetCookies
X-ApacheServer
X-B3-Spanid
X-PERF
X-TIME
X-Agile-Age
X-Agile-Id
X-Agile
X-Nginx-Cache
X-Source
Pagespeed
Cache-Name
X-Varnish-Ttl
X-APP-VERSION
X-Ua
X-Datadome
X-Edge-Location
X-App-Version
X-Edge-IP
X-Pubstack
X-Request-Time
X-CACHE-KEY
X-Protected-By
X-Ocache
Warning
X-Real-Ip
X-Varnish-Beresp-Status
X-Hit
X-OVcl
Fastcgi-Useragent
X-Varnish-Beresp-Grace
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cdn-Forward
X-OVcl-Cache
X-Rojux
X-S-Cookie
Fly-Request-Id
X-Developers
X-BB-ID
X-Rewrite-Enabled
X-Gannett-Site-Version
Fly-Cache
X-G
X-Developer
Cache-Prefix
BehaviorPad-Version
Arc-Country
Ajk
X-DPWN-IS-SECURE
X-Cache-ASPX
X-SRCache-Key
X-External-Request-Id
Cross-Origin-Window-Policy
X-B-Cookie
Ec-Rule-Version
Origin
UCS
X-Server-Group
X-CF-Lambda-Version
X-CF-Lambda-Fn
Thinkindot-Control
Thinkindot-CacheControl-Type
Server-Cache-Control
Server-Surrogate-Control
X-Connection-Hash
Thinkindot-CacheControl
X-ScT
Www
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-Cache-Grace
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-Core-Value
X-D
X-Debug-Cookies
On-Server
X-ARC
X-Debug-Cache-Store
Node
N-Cache
X-Destination
Meta-Geo-Continent
X-Debug-Log
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Secret
Request-EU
Request-Time
X-Cache-Expires
Request-Country
Rendered-Blocks
X-Date
X-Application
X-Thinkindot-L3
MD5-Digest
X-ElasticPress-Search
X-Platform
X-IN-APIGATEWAY
X-IN-WAF
X-Instart-Isnd
X-PAYTM-SRV-ID
X-Nginx-Cache-Key
X-Logtrace-Id
X-Hp-Webp
X-Matched-Rule
X-Request-UUID
X-NodeID
X-VG-WebServer
X-Generated-In
X-Origin-CC
X-NX-Host
X-Region-Sid
X-Processor
X-Varnish-Authentication
X-NU-AKA-ACS-Version
X-Origin-TTL
X-VCT
Xc-Version
X-Mobile-URL
X-Twitter-Response-Tags
X-Var-Ttl
SRV
X-Trv-Group
X-Transaction
X-Up
Section-Io-Cache
X-Sucuri-Cache
X-Cache-Backend
Proxy-Connection
X-No-Session
X-Cache-FS-Status
X-CUA
Pramga
X-Node-Id
X-Li-Pop
X-Sf
X-LAGOON
X-C
X-Li-Fabric
X-Rebelmouse-Surrogate-Control
X-Varnish-Url
X-Refresh
X-Crawler
X-ServiceProvider
X-Cache-Debug
RNT-Time
X-Irp-Debug
X-Cache-Info
X-RateLimit-Remaining-Second
X-CGP
X-Cache-Id
X-Cache-Miss-From
X-Location
X-LI-UUID
X-RateLimit-Limit-Second
X-Webstats-RespID
X-Qloud-Router
X-Policy
True-Client-Country-4JS
X-Sedo-Request-Id
X-Reboot
X-Proxy-Cache-Status
X-LI-Proto
Server-Host
Server-Int
X-Cache-Host
X-Proxy-Upstream
X-Cms-Context
X-Rebelmouse-Cache-Control
RNT-Machine
X-Origin-Date
Memcached
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Backend
X-Request-URI
CDCHOST
Country-Code
Content-Disposition
X-Epic-Correlation-Id
X-Eu-Site
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Hash
X-Geo-Header
X-TT-LOGID
X-Swa-Ws
X-F5-Cache
X-PHP-Host
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
X-Page-Type
Cache-Cookie-Set-Lfrom
X-Dispatcher-Server
Heartbleed
HA-Ipaddr
Ha-Gx-Prefs
X-Info
IsBot
X-Origin-Expires
Magicmarker
Lfy
Kp-EeAlive
X-Distil-CS
X-Device-Os
X-SIPLIST1
Fastly-SWR
Fastly-SIE
Fastly-Soc-X-Request-Id
X-Distributor
X-SN
X-Skip-Cache
Fastly-Backend-Name
X-GZip
X-BBXSRF
X-Gateway-Cache-Key
X-Fetched-On
X-Level-Front-Cache
X-Bip
X-Gen-Mode
X-Block-Status
X-Generated-On
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Planisys-CDN-Rules
X-S-Maxage
X-Core-Mission
X-Hnp-Log
X-Cdn-Srv
X-Key
X-MSEdge-Features
X-Planisys-CDN-TTL
X-Fastly-Cache
X-GeoIP-Country-Code
X-MSEdge-Flight
X-Planisys-CDN-Cache
X-GeoIP-City
X-Thanos
X-ShopId
HTTPS
X-Shopify-Stage
Fastly-SSL
Is-Eu
X-Servername
Powered-By
Platform
X-ShardId
X-Sorting-Hat-PodId
X-Wikidot-Static-Cache
X-Variation
X-Backend-Url
X-User
X-Dc
X-Sorting-Hat-ShopId
X-Wikidot-Backend
X-Ah-Environment
Adler-Geo
SD-X-WS
Pagetype
X-Amz-Meta-Cache-Control
X-Amzn-Remapped-Connection
X-Alternate-Cache-Key
User-Cache-Control
Web-Mar-Node
X-Server-IP
X-Amzn-Remapped-Content-Length
X-Backend-State
X-Backend-Host
X-Auto-Login
X-Amzn-Remapped-Date
X-FireWall-Port
X-Nc
X-WPE-Loopback-Upstream-Addr
X-Via-SSL
Pragrma
X-Server-Time
X-Cache-Bucket
X-Via-Edge
X-Owner
X-Varnish-Beresp-Ttl
X-Micro-Cache
X-TrackingId
X-Returned-From
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Original-Request
X-Passed-To
X-Passed-To-BeforeDispatch
X-Stale
Server-ID
X-Actual-URL
X-RateLimit-Reset
X-Server-By
X-Returned-From-PostProcessResponse
X-Passed-To-DLL
X-Svr
X-Passed-To-PostProcessResponse
X-Unique-ID
X-VServer
X-HS-Cache-Config
Host-ID
X-Croise-Owner
X-Microcachable
Cteonnt-Length
X-CDN-Forward
FNAC-ModuleRouting
X-Edge-Server
Cdn-Host
Cdn-Request-Time
X-Pjax-Url
REQUESTUUID
X-Parent-Response-Time
Viewtype
VivaBuild
DSUID
Mime-Version
ServerName
X-Org
X-Load-Cache
Gh-Request-Id
X-Aicache-OS
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-FPC
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-V
X-NC
SID
Time
X-CSRF-TOKEN
X-Ua-Device
X-Gdpr
V-Age
X-Apm-App-Name
X-Sn-Servicetimems
Memory
X-From-Cache
X-Apm-Inst-Hash
X-Apm-Svc-Key
X-Cdn-Origin
X-Req
X-Geo
X-Exp-Se
ProcessTime
Rt-Proxy-Cache
X-ND-Cache
PICS-Label
MIME-Version
X-Servedbyhost
X-Served-From
Odigeo-Trace-Id
X-URL
X-Wa
X-HTML-Minification-Powered-By
X-Tb-Optimization-Total-Bytes-Saved
Cf-Ipcountry
Public-Key-Pins-Report-Only
X-B3-Parentspanid
X-Fstrz
X-Lb-Id
X-GEO
Cdn
AR-SID
X-Git-Hash
X-Optimization
X-Cache-HT
X-Newrelic-Synthetics
X-Response-By
CF-IPCountry
Resin-Trace
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
Fastcgi-X-Cache-Version
HostName
Cache
GMS-Ver
X-Varnish-Beresp-TTL
X-DC
X-Webkit-Csp
X-Atg-Version
X-WR-MODIFICATION
XServer
Proxy-Firewall
X-Release
Processtime
X-Amz-Meta-Surrogate-Control
X-Fastly-Backend-Reqs
X-Daa-Tunnel
X-TH-Server
X-Vcl-Version
WZWS-RAY
X-WebServer
X-APP
X-Ratelimit-Remaining
X-UE-Client-Country
Countrycode
X-We-Are-Hiring
Mobile-Detection-Method
X-Phone
X-Clientip
GW-Server
X-LB-ID
X-Ratelimit-Limit
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
X-Nananana
SS
X-Instart-Info
CF-Cached-On
X-WA
X-Hyper-Cache
X-Zone
X-Host-Name
Ohc-File-Size
X-Fastly-Country-Code
X-Vcache
X-NGINX-Cache
X-HS-Status
Backend-Name
X-Check-Cacheable
Pics-Label
FSS-Cache
FSS-Proxy
X-Upstream-HT
X-Ratelimit-Reset
X-PF-Uncompressing
X-Upstream-CT
X-Worker
X-ServedByHost
X-CSRF-Token
X-HS-Combine-CSS
Lb
352pxline
286prxHost
219prxHost
355prline
409pxxline
X-Server-W
Xxline
189phosttRef
225prxHost
188prxHost
X-Backend-TTL
Geoip-Latitude
GeoIp-Country-Code
178proxuri
Amp-Access-Control-Allow-Source-Origin
DataCenter
X-Be
X-IPS-LoggedIn
Geoip-City
X-SERVER-NAME
X-Fpc
X-VHOST
SN
URI
Ohc-Cache-HIT
X-Dynatrace
X-GZIP
X-Render-Time
X-Gen-Id
X-Request-Start
Version
Esi-Enabled
X-UPSTREAM-Address
X-UCC
X-BE
X-LiteSpeed-Cache-Control
WP-Super-Cache
X-B3-SpanId
X-CS
X-Varnish-Action
Who
X-Unique-Id
X-ID
X-NGENIX-Cache
X-Html-Edge-Cache
CDN
X-PJAX-URL
X-AssetVersion
X-Contensis-Viewer-Groups
X-VCL-Version
X-Cache-URL
Dynatrace
X-HostName
X-FORWARDED-FOR
X-SRV
X-Via-Ucdn
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
X-GDPR
X-LiteSpeed-Tag
X-Fastly-Cache-Hits
RequestUuid
Cneonction
X-Pf-Uncompressing
X-Cdn-Cache
Serverid
X-Cache-Ttl
X-RequestId
X-Akamai-Request-ID2
X-NWS-UUID-VERIFY
RequestId
X-Store
Server-Id
A
X-Via-NSCOPI
Accept-Ch
X-ServerName
X-Vtex-Processado-Em
X-Servedby
Accept-Language
X-Request-Url
X-Vtex-Remote-Cache
X-Pc-Appver
X-Akamai-SSL-Client-Sid
X-Pc-Key
X-Pc-Hit
X-Reqid
X-EC-Lua
Ohc-Response-Time
X-Port
Get-Access-Time
X-Dw-Trace-Id
IBM-Web2-Location
X-Generation-Time
Is-Session-Tracking
X-Serial
NnCoection
X-Cdn-Request-ID
X-HTML-Edge-Cache
Frontcache
X-ZONE