Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Ua-Compatible
X-AspNetMvc-Version
P3p
Status
Timing-Allow-Origin
X-Template
Content-Encoding
X-Language
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Upgrade
X-Buckets
X-CDN
Xkey
X-Request-ID
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Via
Access-Control-Expose-Headers
Keep-Alive
Access-Control-Max-Age
CF-Ray
X-AH-Environment
X-Pass-Why
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Age
X-Backend
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Envoy-Upstream-Service-Time
X-Pingback
X-Hacker
X-Varnish-Cache
X-Server-Powered-By
X-Nginx-Cache-Status
EagleId
X-Proxy-Cache
Grace
X-UA-Device
Request-Context
Cf-Railgun
WPE-Backend
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
Feature-Policy
X-Server-Id
X-Ac
X-Node
Content-Location
X-Rq
X-Host
EagleEye-TraceId
X-Cnection
X-Backend-Server
Allow
Server-Timing
Report-To
X-Response-Time
X-Cache-Lookup
X-Dns-Prefetch-Control
X-Application-Context
Request-Id
Surrogate-Control
X-Origin-Cache
X-Readtime
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
Pinterest-Generated-By
X-CST
NEL
X-Ruxit-JS-Agent
X-Rack-Cache
X-FTR-Request-ID
X-HW
X-Vhost
X-Clacks-Overhead
X-Country
X-Country-Code
X-DynaTrace
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Instart-Request-ID
X-Goog-Hash
X-Origin-Upstream-Status
X-Dispatcher
X-Url
X-Mod-Pagespeed
X-DataDome
Edge-Control
X-Px
X-VARITI-CCR
X-PC
X-Vname
X-TtlSet
Service-Worker-Allowed
X-MS-InvokeApp
Accept-CH
Verso
X-Server-Name
X-Varnish-TTL
X-DataStream-Cache-Status
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Powered-By-Plesk
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Recruiting
SPRequestGuid
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Vcap-Request-Id
X-D2id
X-GitHub-Request-Id
X-ESI
X-Amz-Server-Side-Encryption
MS-Author-Via
Content-MD5
AR-Request-ID
X-Abt-Application-Version
Public-Key-Pins
X-Version
X-Cached
X-ORACLE-DMS-RID
Ar-Sid
Display
X-Middleton-Display
RTSS
X-Sol
X-Middleton-Response
X-SharePointHealthScore
Response
Arc-Version
PB-RID
Nginx-Cache
PB-PID
X-Mobile-Rewrite
X-DynaTrace-JS-Agent
X-Navigation-Version
X-Upstream-Proxy
Pinterest-Version
X-Pinterest-Rid
DynaTrace
Charset
X-Amz-Rid
X-Oracle-Dms-Rid
Realpath
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
ServerID
X-XRDS-Location
X-Powered-CMS
X-Akam-SW-Version
X-Client-IP
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-Proto
X-Trace
X-Shield-Request-Id
X-FTR-Cache-Status
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend
X-FTR-DC
TCN
X-FTR-Backend-Server
X-FTR-Balancer
X-B3-TraceId
X-FTR-Expires
X-Ttl
X-RateLimit-Remaining
X-TTL
X-Goog-Storage-Class
X-Amz-Meta-S3cmd-Attrs
X-Dw-Request-Base-Id
SPIisLatency
X-Debug
SPRequestDuration
X-Ser
X-VCache
Alternate-Protocol
X-Id
X-Cdn
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Fastly-Request-ID
X-FTR-Cache-Host
X-Shard
Paypal-Debug-Id
X-Varnish-Age
X-Upstream
X-Litespeed-Cache
Fastcgi-Cache
X-Server-ID
X-T
S
X-MSEdge-Ref
X-Hits
X-Acc-Meta-Resource-Type
Host
X-Ezoic-Cdn
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
MicrosoftSharePointTeamServices
X-NF-Request-ID
Front-End-Https
X-Content-Digest
X-Logged-In
X-DIS-Request-ID
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Frontend
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-HS-Hub-Id
Server-Name
X-HS-Content-Id
X-N
Pagespeed
X-Amzn-Trace-Id
X-IPLB-Instance
Accept-CH-Lifetime
X-B3-Sampled
X-Kinsta-Cache
X-Srv
X-Pad
X-Content-Type
X-Request-Handler-Origin-Region
X-Forwarded-For
X-Microsite
X-Fastcgi-Cache
Edge-Cache-Tag
X-Grace
FilterID
X-AOL-HN
AMP-Access-Control-Allow-Source-Origin
X-Accel-Expires
TP-Cache
X-Debug-Info
TP-L2-Cache
Surrogate-Key
X-Type
Tracecode
X-Rid
X-Node-Name
X-Request-Received
X-Request-Processing-Time
X-LB-Cache
X-Via-JSL
X-RateLimit-Limit
X-Analytics
Backend-Timing
X-FastCGI-Cache
X-Hostname
X-Page-Id
X-Webkit-Csp
Accept-Charset
X-GUploader-UploadID
X-Whom
Healthy
X-Revision
X-Content-Options
X-Cache-Rule
X-Cache-2
X-Varnish-Backend
X-NWS-LOG-UUID
Host-Header
Accept-Ch-Lifetime
X-Cached-By
X-Cache-Age
X-Content-Powered-By
X-Amz-Replication-Status
X-Content-Security-Policy-Report-Only
X-Cache-Control
X-PHP-Backend
X-Framework
X-User-Agent
X-TT
X-Mobile
X-Correlation-Id
X-Varnish-Hostname
X-Request-Guid
X-App-Environment
X-BCube-Filmed-By
X-Akamai-Edgescape
X-Tumblr-Pixel-0
Powered
X-Varnish-Grace
Source
X-Instance
X-Tumblr-User
X-Tumblr-Pixel
VIX-Pulpo-Upstream-Status
Upgrade-Insecure-Requests
VIX-Pulpo-Node
Cache-Status
X-FB-Debug
X-Cluster
X-B3-Traceid
Fastly-Restarts
X-Amz-Apigw-Id
Server-Info
X-Amzn-RequestId
X-Cache-Hit
Cleartype
X-Cache-TTL
X-Zen-Fury
X-Az
X-AppVersion
X-Activity-Id
X-Jobs
Access-Control-Allow-Method
X-Drupal-Cache-Tags
X-Vcache
X-Platform-Server
X-Cache-Remote
X-Cache-Key
Retry-After
X-Iejgwucgyu
X-Oneagent-Js-Injection
X-ATG-Version
Actual-Object-TTL
X-FW-Static
X-FW-Server
X-FW-Type
X-CF-Powered-By
X-FW-Hash
X-FW-Serve
X-Cache-Action
X-Forwarded-Host
X-Esi
X-Cache-Operation
X-Geo-Country
X-URL
X-Response-Served-From
X-Adobe-Loc
X-WebKit-CSP-Report-Only
Payment
X-Adobe-Content
Cache-Tags
X-ProcessESI
X-Yottaa-Metrics
X-Storage
X-RemovedCookies
X-TX-ID
Filters
X-Yottaa-Optimizations
X-TT-TIMESTAMP
Server-Node
X-Handled-By
X-F-Cache
X-Tumblr-Pixel-2
Eomportal-Instance
X-Content-Age
X-UA-Device-Type
X-VG-WebCache
X-Tumblr-Pixel-1
X-Real-IP
X-RequestSource
X-B
Cache-Tv-Group
X-Varnish-Hits
X-Cacheable-TTL
Cache
X-GeoIP
PageSpeed
X-Cache-NE
DC
Refresh
X-Daa-Tunnel
Cache-Tag
X-Accel-Buffering
X-Git-Hash
X-Redis-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
MS-CV
X-Guploader-Uploadid
From-Origin
Webserver
Viewport
Frame-Options
X-Host-Name
X-App-Server
X-UUID
X-Rendered-As
Datacenter
X-PressLabs-Stats
X-Origin-Server
X-TA-CDN-Provider
X-Contextid
X-WA-Info
X-Cache-TTL-Remaining
X-FB-TRIP-ID
X-Cache-Enabled
X-Mode
X-Magnolia-Registration
X-FW-Dynamic
Xserver
Country
X-Varnish-Server
X-Locale
X-Routing-Service
X-Proxied
X-Upstream-CT
X-Upstream-HT
GEO-INFO
X-RN-RSRV
Meta-Geo
X-ES-SERVER
X-Zipkin-Id
X-Cache-Var-Map
X-Cache-Var
X-From
Machine
Load-Balancing
X-Path-Route
X-Ratelimit-Reset
X-XRDS-LOCATION
X-Web-Node
X-Viewer-Country
Cache-Key
ServedBy
NGX
X-APP-VERSION
X-NCache
X-Rule
X-L-Path
X-Pubstack
X-Cache-Backend
X-ProxyCache-Status
X-ProxyCache-Key
X-VG-TLSProxy
X-ServerID
X-R9-Blue-Green-Version
X-Hit
X-Rocket-Nginx-Bypass
X-PCL
X-OCL
X-Cache-Config
X-BYPASS-REASON
Origin-Cache-Control
X-Cache-Host
X-Debug-Cache
X-Labrador-Cache-Channel
X-Human
X-Environment-Context
Mn-Server-Ip
Origin-Edge-Control
X-Signature
Cteonnt-Length
X-B-Cache
X-Hosted-By
X-EIG-Tracking-Id
X-FC-Vary-Parameters
X-Grey
X-CCM
X-Hl-Ver
X-Cache-Category-Id
Uber-Trace-Id
Now
Vix-Hermes-Req-Id
X-Akamai-Request-ID
X-AWS-Id
X-EdgeConnect-Cache-Status
X-LJ-Flow-ID
X-Varnish-Cache-Hits
X-Upgrade-Enabled
X-Varnish-IP
X-Via-Fastly
X-Www-Served-By
X-VWS-Id
X-Tumblr-Pixel-3
X-Trace-Id
X-Proto
X-Origin-Response-Time
X-Region
X-S
X-Site-Version
L5d-Success-Class
X-MP-GENERATED-AT
DB-Nickname
X-Goog-Meta-Goog-Reserved-File-Mtime
Release
X-Vgn-Hpd-Reason
X-Device-Type
X-Access
X-Backend-Name
X-Detected-As
X-Loop
X-Is-Bot
X-TNCMS
Nel
X-Xfnlog-Site
X-Section
X-VCT
X-RCS-CacheZone
Mail-Subject
X-Mobile-URL
X-JoinUs
We-Hiring
DSUID
X-Hp-Webp
Cache-Name
X-Ua
X-NGENIX-Cache
X-B3-Spanid
Powered-By-ChinaCache
X-Generated
Selected-FE
X-Proxy-Build
X-Timing-Wait
X-NewRelic-App-Data
OT-Force-Account-Verify
Rt-Fastcgi-Cache
HitType
Fastcgi-Useragent
X-Seen-By
X-BACKEND-TTL
S-Cnection
X-Webkit-CSP
X-Tb
X-Source
X-Nginx-Cache
X-Drupal-Cache-Contexts
X-Cache-Grace
SRV
Served-By
X-Presslabs-Stats
X-Generated-By
X-UnsetCookies
X-Birta-Cache-Post
X-Birta-Served
X-GRACE
X-Cluster-Node
X-Format
Ms-Operation-Id
Hostname
X-RTag
X-Proxy
X-Cache-Server
X-Microcachable
X-PERF
X-ApacheServer
X-OVcl-Cache
X-OVcl
Fastcgi-X-Cache-Version
X-Time
Decoy-Debug-Key
X-Time-Microsecs
Decoy-Debug-Status
X-Endurance-Cache-Level
Decoy-Debug-TTL
X-Akamai-Transformed
X-Status
Azure-RegionName
Azure-SiteName
X-IP
Azure-InstanceId
Azure-SlotName
Azure-Version
X-ShardId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-ShopId
TWC-Locale-Group
Webcakes-Region
TWC-Device-Class
TWC-Privacy
X-SS-Set-Cookie
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-B3-Parentspanid
X-Via-CDN
TWC-Connection-Speed
X-FW-Version
Webcakes-App-Version
Access-Control-Request-Headers
X-UA
Property-Id
Webcakes-App-Name
IBM-Web2-Location
X-Origin-Hint
X-Geo
Origin
S-Rt
X-Origin
NGB
Proxy-Connection
WZWS-RAY
X-Origin-TTL
Ec-Rule-Version
Fastly-SSL
X-Origin-CC
X-Ruxit-Js-Agent
Thinkindot-CacheControl-Type
VivaBuild
Web-Mar-Node
Cache-Cookie-Set-Lfrom
User-Cache-Control
Thinkindot-Control
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Cache-Cookie-Set-From
Www
Content-Style-Type
Content-Script-Type
IsBot
GEO-REGION-INFO
Apple-News-Services-Request-Url
Arc-Country
Cross-Origin-Window-Policy
Fly-Request-Id
MD5-Digest
Meta-Geo-Continent
Fly-Cache
Cache-Cookie-Set-Idcheck
Cache-Prefix
Server-Int
Rt-Proxy-Cache
Rendered-Blocks
AsisCache
BehaviorPad-Version
Node
Thinkindot-CacheControl
X-Cluster-Name
X-Gen-Mode
X-Thinkindot-L3
X-SRCache-Key
X-Hnp-Log
X-Sn-Servicetimems
X-Instart-Info
X-G
X-Fastly-Cache
X-Destination
X-Date
X-Developer
X-Transaction
X-External-Request-Id
X-DPWN-IS-SECURE
X-Matched-Rule
X-SIPLIST1
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S-Cookie
X-Server-Time
X-ScT
X-Region-Sid
X-Processor
X-NU-AKA-ACS-Version
X-ND-Cache
X-Org
X-PAYTM-SRV-ID
X-Phone
Apple-News-Services-Handled
X-Trv-Group
X-Worker
Xc-Version
X-Application
X-ARC
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Aed
X-Accel-Expires-Debug
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Via-NSCOPI
X-VG-WebServer
X-ServiceProvider
X-CF-Lambda-Version
X-Connection-Hash
X-Twitter-Response-Tags
X-D
X-Core-Value
X-CF-Lambda-Fn
X-Cdn-Origin
X-BBXSRF
X-B-Cookie
X-Block-Status
X-Cache-Bucket
X-Cache-Info
X-A
Viewtype
X-Cdn-Forward
X-Info
X-Request-Time
Backend-Name
X-TIME
X-ElasticPress-Search
X-Varnish-Cacheable
X-Level-Front-Cache
Memcached
X-Irp-Debug
X-IN-WAF
X-Instart-Isnd
On-Server
X-Core-Mission
X-Cache-Id
X-Cache-FS-Status
X-Page-Type
X-App-Version
X-No-Session
X-Cdn-Srv
X-Nginx-Cache-Key
Pramga
V-Age
X-Gannett-Site-Version
X-Generated-On
X-Generation-Time
Server-Host
True-Client-Country-4JS
ServerName
X-Distributor
RNT-Time
RNT-Machine
Request-Country
X-PHP-Host
Request-EU
UCS
Resin-Trace
X-Geo-Header
X-IN-APIGATEWAY
X-Cache-Expires
X-App-Name
X-Swa-Ws
X-Amz-Meta-Cache-Control
X-Server-IP
X-Served-From
X-Request-URI
X-Secret
X-Varnish-Action
X-VC-Cache
X-Wikidot-Static-Cache
HTTPS
X-Wikidot-Backend
X-Webstats-RespID
X-Via-Edge
X-Via-SSL
X-Reqid
CDCHOST
X-Qloud-Router
X-Rebelmouse-Cache-Control
Epwk-Cache
X-Release
Esi-Enabled
X-Rebelmouse-Surrogate-Control
X-Reboot
Fastly-SWR
Fastly-SIE
Country-Code
X-C
X-Nc
X-FireWall-Port
X-Device-Os
X-Dispatcher-Server
X-Cache-Debug
X-CDN-Cache
X-Agile-Id
X-Debug-Log
X-Backend-State
X-Debug-Cookies
X-Developers
X-Cms-Context
X-Li-Pop
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Owner
X-Origin-Expires
X-Planisys-CDN-TTL
X-Protected-By
X-Variation
X-TH-Server
X-Skip-Cache
X-S-Maxage
X-Origin-Date
X-NX-Host
X-HS-Cache-Config
X-Hash
X-Fetched-On
X-Epic-Correlation-Id
X-HS-Combine-CSS
X-Key
Version
X-Location
X-Agile-Age
X-Li-Fabric
X-Distil-CS
X-LI-UUID
Request-Time
Platform
Heartbleed
Gh-Request-Id
REQUESTUUID
Wxu-Next-Region
Who
Wxu-Next-Commit
Wxu-Next-Hostname
SD-X-WS
Fastly-Soc-X-Request-Id
Is-Eu
X-Agile
Backend
AKAMAI
Content-Disposition
Adler-Geo
X-CACHE-GROUP
Group
X-IPS-LoggedIn
X-Eu-Site
X-Thanos
Mime-Version
X-WebServer
X-SN
X-Crawler
X-Real-Ip
Ha-Gx-Prefs
X-LAGOON
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
HA-Ipaddr
X-Refresh
X-GeoIP-City
X-GeoIP-Country-Code
X-CGP
ProcessTime
X-Auto-Login
X-Bip
X-Dc
X-AssetVersion
X-AIR-PT
X-GEO
X-NC
FNAC-ModuleRouting
Server-ID
Memory
X-Var-Ttl
X-Sf
Cache-Hits
Time
X-LI-Proto
X-FPC
Mobile-Detection-Method
X-Load-Cache
Akamai-GRN
X-Wix-Request-Id
X-WPE-Loopback-Upstream-Addr
X-Edge-Location
X-Servername
SS
Amp-Access-Control-Allow-Source-Origin
X-Policy
Cache-Provider
X-We-Are-Hiring
X-Parent-Response-Time
Countrycode
X-Internal-Host
X-CLOUD-TRACE-CONTEXT
X-Clientip
CF-IPCountry
Cdn
NtCoent-Length
X-CDN-Forward
GW-Server
X-DC
X-Micro-Cache
X-Unique-ID
X-NWS-UUID-VERIFY
X-CACHE-KEY
Fastcgi-X-Cache
X-Datadome
X-ZONE
A
X-Gdpr
RequestId
X-Be
X-Tb-Optimization-Total-Bytes-Saved
X-Servedbyhost
X-SD-PageType
X-Varnish-Beresp-Ttl
Ohc-Cache-HIT
Ohc-File-Size
Accept-Ch
X-COUNTRY
X-Response-By
Geoip-City
Geoip-Latitude
GeoIp-Country-Code
X-Cache-URL
X-Zone
X-Ratelimit-Remaining
X-Apm-App-Name
X-Apm-Svc-Key
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-ECACHE
X-Logtrace-Id
Ajk
X-Apm-Inst-Hash
X-Dynatrace-Js-Agent
Liferay-Portal
CF-Cached-On
X-Web-Server
HostName
Cf-Ipcountry
SN
X-VCL-Version
PICS-Label
X-Varnish-Beresp-Status
X-Hyper-Cache
X-Varnish-Beresp-Grace
X-SERVER-NAME
X-APP
Proxy-Firewall
X-Fstrz
X-UPSTREAM-Address
X-Vcl-Version
X-LiteSpeed-Cache-Control
X-FORWARDED-FOR
X-Varnish-Beresp-TTL
XServer
AR-SID
X-Pf-Uncompressing
X-Fastly-Country-Code
Odigeo-Trace-Id
MIME-Version
CDN
X-Request-Start
Section-Io-Cache
X-Lb-Id
X-Aicache-OS
X-NodeID
X-HS-Status
WebServer
X-Amzn-Remapped-Connection
Is-Session-Tracking
X-Server-Group
X-Amzn-Remapped-Date
GeoIP-City
X-Dispatch
X-Newrelic-Synthetics
GeoIP-Latitude
GeoIP-Country-Code
X-MServer
Get-Access-Time
X-Ratelimit-Limit
X-Pjax-Url
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-ServedByHost
X-Method
LB
X-Cache-Ttl
X-SRV
X-VServer
PFcat
Requestid
X-Fastly-Backend-Reqs
X-Newrelic-App-Data
X-Check-Cacheable
X-Nananana
Host-ID
X-CS
X-PF-Uncompressing
X-Up
X-RequestId
X-Erf-Bev-Bev-Is-Generated
X-B3-SpanId
X-Erf-Bev-Bev
X-WA
X-Correlation-ID
X-Backend-TTL
X-Dynatrace
Pragrma
X-Amzn-Remapped-Content-Length
CACHE
X-Server-W
X-CSRF-TOKEN
X-Powered-By-Defense
X-Azure-Ref-OriginShield
X-Compress-Hint
X-Backend-Host
X-MSEdge-Features
X-Contensis-Viewer-Groups
X-LiteSpeed-Tag
X-CUA
X-Cache-ASPX
Server-Surrogate-Control
X-Backend-Url
X-MSEdge-Flight
Server-Cache-Control
Sid
X-Azure-Ref
X-Oss-Server-Time
X-Oss-Storage-Class
X-Wa
X-HTML-Minification-Powered-By
Lb
X-Varnish-Authentication
X-Oss-Request-Id
Powered-By
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-WR-MODIFICATION
Correlation-Id
X-EC-Lua
X-Debug-Cache-Fetch
X-F5-Cache
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-PJAX-URL
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-User
X-LB-ID
TTL
X-Gateway-Cache-Key
Dynatrace
X-Akamai-Request-ID2
X-Request-Url
W
X-Edge
X-Dw-Trace-Id
Cneonction
X-Generated-In
X-Bc
X-Svr
X-BC
URI
Accept-Language
X-Got-Non-Ke-Cookie
X-Clara-WADP
X-NGINX-Cache
X-WADP-Cache
X-ServerName
X-Html-Edge-Cache
X-Fpc
L
User-Agent
X-Sedo-Request-Id
352pxline
355prline
286prxHost
225prxHost
Xxline
219prxHost
409pxxline
X-Urbn-Site-Id
X-RateLimit-Reset
X-Cache-Miss-From
Pagetype
188prxHost
X-Urbn-Context-Path
Locale
189phosttRef
178proxuri
X-Li-Proto
X-Swift-Error
X-Fastly-Cache-Hits
X-Requestid
X-HTML-Edge-Cache
X-Mid
X-Exp-Se
X-BE
X-Unique-Id
X-ABtesting
X-MID
X-Flog
X-Hello
Magicmarker
WP-Super-Cache
X-Varnish-Url
X-Via-Ucdn
X-CSRF-Token
X-Cache-Tag
N-Cache
Warning
Ttl
X-Akamai-SSL-Client-Sid
X-TT-LOGID
X-Edge-IP
RequestUuid
X-MCACHE
X-Cache-Detail
X-Sucuri-Cache
X-Sucuri-ID
V-Cache
X-Gen-Id
X-GDPR
FSS-Proxy
Server-Id
Dnion-Transfer-Encoding
X-App
X-Alicdn-Da-Ups-Status
FSS-Cache
Lfy
Https
X-Platform
Ohc-Response-Time