Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
ETag
Link
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
CF-Cache-Status
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
CF-Ray
X-Request-ID
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Pass-Why
X-Cache-Group
X-AH-Environment
P3p
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
WPE-Backend
X-Robots-Tag
X-Nginx-Cache-Status
X-Server-Powered-By
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-CacheTime
X-Swift-SaveTime
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Device
Allow
Ali-Swift-Global-Savetime
Server-Timing
X-Type
X-CST
X-Ac
X-Rq
X-Node
X-Server-Id
X-Host
Feature-Policy
Content-Location
X-Response-Time
X-Cnection
Report-To
X-Backend-Server
X-Application-Context
Surrogate-Control
X-Iejgwucgyu
EagleEye-TraceId
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Readtime
X-Origin-Cache
X-Rack-Cache
Request-Id
X-Url
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
NEL
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Instart-Request-ID
X-Upstream-Env
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-Vhost
X-DynaTrace
X-Px
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Goog-Hash
X-Server-Name
Verso
X-ESI
Accept-CH
X-Dispatcher
X-HW
X-GitHub-Request-Id
Charset
X-VARITI-CCR
PB-PID
X-Mobile-Rewrite
PB-RID
Arc-Version
MS-Author-Via
X-MS-InvokeApp
AR-ATIME
X-DataStream-Cache-Status
X-Version
AR-PoweredBy
AR-CACHE
X-Cached
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Cdn-Fetch
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
Content-MD5
X-Powered-By-Plesk
X-Recruiting
X-ORACLE-DMS-RID
Public-Key-Pins
Service-Worker-Allowed
Accept-CH-Lifetime
X-D2id
X-TtlSet
X-Vname
X-PC
X-Navigation-Version
AR-Request-ID
RTSS
Ar-Sid
X-Abt-Application-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ser
X-TTL
X-Trace
X-Forwarded-Proto
SPRequestGuid
X-Client-IP
X-Vcap-Request-Id
X-Varnish-TTL
X-Oracle-Dms-Rid
X-Amz-Server-Side-Encryption
X-DynaTrace-JS-Agent
X-SharePointHealthScore
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-Country-Code-Real
X-Amz-Rid
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-Fastly-Request-ID
X-FTR-Expires
S
X-Amz-Meta-S3cmd-Attrs
X-XRDS-Location
Arr-Disable-Session-Affinity
Nginx-Cache
X-Shield-Request-Id
X-Debug
X-Server-ID
X-Upstream-Proxy
X-Id
X-Pinterest-Rid
Pinterest-Version
TCN
X-Dw-Request-Base-Id
X-VCache
X-Hits
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Ttl
SPRequestDuration
SPIisLatency
DynaTrace
X-B3-TraceId
Front-End-Https
X-Akam-SW-Version
Access-Control-Request-Method
X-Goog-Storage-Class
X-T
X-FTR-Cache-Host
X-Powered-CMS
X-NF-Request-ID
X-SERVER
Realpath
X-Acc-Meta-Resource-Type
Paypal-Debug-Id
Tracecode
X-Varnish-Age
X-Amzn-Trace-Id
X-MSEdge-Ref
X-Aspnet-Version
Fastcgi-Cache
X-Forwarded-For
X-N
X-Content-Type
Alternate-Protocol
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Upstream
X-RateLimit-Remaining
X-PressLabs-Stats
X-Frontend
X-Accel-Buffering
Fusion-Content-Source
Fusion-Source
X-Logged-In
Fusion-Template-Id
Fusion-Component-Id
X-HS-Hub-Id
Fusion-Content-Id
X-HS-Content-Id
X-Content-Digest
Display
X-Sol
X-Middleton-Display
X-Srv
Response
X-Middleton-Response
X-Hostname
X-Litespeed-Cache
X-Fastcgi-Cache
X-Kinsta-Cache
AMP-Access-Control-Allow-Source-Origin
X-Pad
X-Cache-Key
Server-Name
MicrosoftSharePointTeamServices
X-Accel-Expires
X-User-Agent
X-Content-Options
Refresh
Backend-Timing
Host
X-DIS-Request-ID
X-Analytics
X-Grace
X-Correlation-Id
X-B3-Traceid
X-LB-Cache
X-IPLB-Instance
X-Revision
X-Activity-Id
X-Az
X-Rid
X-Debug-Info
X-AppVersion
Accept-Charset
X-B
FilterID
X-CF-Powered-By
X-Amz-Apigw-Id
X-Amzn-RequestId
ServerID
X-DataStream-Origin-MEX-Latency
X-Cache-Hit
X-DataStream-MidMile-RTT
X-B3-Sampled
Powered-By-ChinaCache
X-Cdn
Surrogate-Key
X-Cache-2
X-Page-Id
X-FastCGI-Cache
X-Whom
Server-Info
X-PHP-Backend
TP-L2-Cache
TP-Cache
X-Varnish-Backend
X-Request-Processing-Time
X-Content-Security-Policy-Report-Only
Host-Header
X-Request-Received
MS-CV
X-Akamai-Edgescape
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Source
X-Amz-Replication-Status
X-TT
X-Origin-Server
X-F-Cache
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-UA-Device-Type
X-Cluster
X-Cache-Action
X-Framework
X-FW-Hash
X-App-Environment
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-Instance
X-Mobile
X-Webkit-CSP
Cache-Status
X-Varnish-Grace
X-RateLimit-Limit
X-Content-Powered-By
X-Platform-Server
X-Request-Guid
X-Cached-By
X-Handled-By
X-Drupal-Cache-Tags
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Ruxit-Js-Agent
Access-Control-Allow-Method
X-Zen-Fury
X-Geo-Country
X-Magnolia-Registration
X-Shard
X-Ezoic-Cdn
X-FB-Debug
X-SS-Set-Cookie
X-Cache-TTL
X-Forwarded-Host
X-ATG-Version
Edge-Cache-Tag
CACHE
From-Origin
X-Wix-Server-Artifact-Id
X-App-Server
X-Cache-Age
DC
X-Varnish-Server
Cleartype
X-Node-Name
X-Varnish-Hostname
PageSpeed
X-AOL-HN
Cache-Tags
X-GUploader-UploadID
X-BCube-Filmed-By
X-Cache-Control
Payment
X-Generated-By
X-Region
X-RequestSource
X-Signature
X-Response-Served-From
Filters
X-WebKit-CSP-Report-Only
X-B-Cache
X-Adobe-Loc
X-Adobe-Content
Healthy
X-TX-ID
X-GeoIP
GEO-INFO
X-Tumblr-Pixel-2
X-Seen-By
X-FW-Dynamic
X-VG-WebCache
X-RTag
X-Tumblr-Pixel-1
Upgrade-Insecure-Requests
X-Guploader-Uploadid
Ms-Operation-Id
Country
Server-Node
NGB
X-Redis-Cache
Cache-Tv-Group
X-TT-TIMESTAMP
X-Jobs
Webserver
X-UUID
Retry-After
X-Via-JSL
X-Drupal-Cache-Contexts
Actual-Object-TTL
ServedBy
X-Content-Age
X-Varnish-Hits
Liferay-Portal
X-Locale
X-Cacheable-TTL
X-Storage
X-Cache-Rule
X-Contextid
X-XRDS-LOCATION
X-Rendered-As
HitType
X-Varnish-IP
X-Cache-TTL-Remaining
Frame-Options
Powered
Fastly-Restarts
X-Oneagent-Js-Injection
X-BACKEND-TTL
S-Cnection
Viewport
ViewerVersion
X-WA-Info
X-Wix-Request-Id
Content-Style-Type
Content-Script-Type
X-NewRelic-App-Data
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Server
X-Real-IP
X-Upgrade-Enabled
NtCoent-Length
Datacenter
X-Cache-Config
X-TA-CDN-Provider
X-Mode
Xserver
X-RemovedCookies
X-ProcessESI
Eomportal-Instance
X-Dynatrace-Js-Agent
X-Time
X-Esi
X-Endurance-Cache-Level
X-Varnish-Cache-Hits
X-Detected-As
X-Routing-Service
X-Proxied
X-Cache-Var-Map
X-Proto
X-Path-Route
X-Device-Type
X-Akamai-Transformed
X-Hl-Ver
X-ES-SERVER
Load-Balancing
X-Cache-Var
Machine
Meta-Geo
X-RN-RSRV
X-Is-Bot
Cache-Key
X-Zipkin-Id
Cache-Hits
TWC-Device-Class
X-Proxy
TWC-GeoIP-Country
X-S
X-Backend-Name
X-Environment-Context
Access-Control-Request-Headers
L5d-Success-Class
Mail-Subject
OT-Force-Account-Verify
Property-Id
X-Hosted-By
X-Origin-Hint
X-Cache-NE
X-LJ-Flow-ID
X-L-Path
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Viewer-Country
X-VG-TLSProxy
Webcakes-App-Version
Webcakes-App-Name
TWC-Locale-Group
Webcakes-Region
X-AWS-Id
X-Format
X-FW-Version
X-Access
We-Hiring
X-VWS-Id
X-Status
Vix-Hermes-Req-Id
X-Section
TWC-Privacy
X-Cache-Enabled
X-Labrador-Cache-Channel
X-ServerID
Mn-Server-Ip
X-Tb
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
DB-Nickname
X-EIG-Tracking-Id
X-Loop
X-Via-Fastly
X-FC-Vary-Parameters
X-From
Now
X-TNCMS
Azure-InstanceId
Origin-Cache-Control
Origin-Edge-Control
Decoy-Debug-Status
Decoy-Debug-TTL
X-ProxyCache-Status
X-Akamai-Request-ID
X-Debug-Cache
X-Trace-Id
X-Varnish-Cacheable
Selected-FE
X-Origin-Response-Time
X-BYPASS-REASON
X-Time-Microsecs
X-Timing-Wait
X-NCache
X-Proxy-Build
X-Birta-Cache-Post
X-JoinUs
X-Xfnlog-Site
X-Birta-Served
S-Rt
Decoy-Debug-Key
X-CCM
X-ProxyCache-Key
X-Human
X-Origin-Host
X-PCL
Served-By
Cache-Tag
X-Www-Served-By
X-Web-Node
X-OCL
X-Tumblr-Pixel-3
X-IP
X-Via-CDN
X-Cache-Operation
X-MP-GENERATED-AT
X-GRACE
X-Cache-Category-Id
X-Internal-Host
X-Site-Version
X-Generated
X-Grey
Uber-Trace-Id
NGX
X-CDN-Cache
X-FB-TRIP-ID
AsisCache
X-Rocket-Nginx-Bypass
User-Agent
X-Vgn-Hpd-Reason
LB
X-EdgeConnect-Cache-Status
X-VC-Cache
X-Sucuri-ID
X-R9-Blue-Green-Version
X-Rule
X-UA
X-Varnish-Ttl
X-NWS-LOG-UUID
Rt-Fastcgi-Cache
X-Newrelic-App-Data
X-Cluster-Node
Pagespeed
Hostname
X-RCS-CacheZone
X-App-Name
X-Cache-Remote
X-UnsetCookies
Release
X-PERF
X-B3-Spanid
X-ApacheServer
Nel
X-Agile-Age
X-Agile
X-Agile-Id
X-App-Version
X-Nginx-Cache
X-TIME
Cache-Name
X-Edge-Location
X-Source
X-Datadome
X-Ua
X-Edge-IP
X-Pubstack
X-APP-VERSION
X-Request-Time
X-CACHE-KEY
X-Cdn-Forward
X-Ocache
X-Protected-By
Warning
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Varnish-Beresp-Grace
Fastcgi-Useragent
X-Real-Ip
X-OVcl-Cache
X-Varnish-Beresp-Status
X-OVcl
X-Hit
Request-Time
Request-EU
X-S-Cookie
X-G
X-Gannett-Site-Version
Request-Country
Rendered-Blocks
X-External-Request-Id
X-Connection-Hash
SRV
X-SRCache-Key
X-Thinkindot-L3
X-Request-UUID
X-Twitter-Response-Tags
X-Region-Sid
X-Up
X-CF-Lambda-Version
X-Rewrite-Enabled
X-Transaction
Server-Cache-Control
X-Core-Value
X-Rojux
X-Generated-In
X-ElasticPress-Search
X-ScT
Ajk
X-Developers
Fly-Cache
Ec-Rule-Version
Cross-Origin-Window-Policy
MD5-Digest
Fly-Request-Id
X-Developer
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Store
X-Destination
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-DPWN-IS-SECURE
X-D
BehaviorPad-Version
Arc-Country
On-Server
Origin
X-VCT
Node
Meta-Geo-Continent
X-Date
Cache-Prefix
N-Cache
Server-Surrogate-Control
X-Trv-Group
X-Processor
X-A
X-Aed
X-A-Ccd
X-Instart-Isnd
Www
X-Origin-TTL
X-Hp-Webp
X-Logtrace-Id
X-Platform
X-Cache-Expires
X-Varnish-Authentication
X-Accel-Expires-Debug
X-A-Wwc
X-IN-APIGATEWAY
X-A-Dgt
X-A-Dcw
X-PAYTM-SRV-ID
X-A-Dam
X-CF-Lambda-Fn
X-Server-Group
X-Cache-ASPX
Thinkindot-CacheControl-Type
Thinkindot-Control
X-B-Cookie
X-VG-WebServer
X-Var-Ttl
Xc-Version
X-ARC
Thinkindot-CacheControl
X-Application
X-Secret
X-Nginx-Cache-Key
X-Matched-Rule
X-NX-Host
X-Origin-CC
X-Cache-Grace
X-Mobile-URL
X-NU-AKA-ACS-Version
UCS
X-BB-ID
X-NodeID
X-IN-WAF
X-Sucuri-Cache
X-Cache-Backend
Section-Io-Cache
IsBot
X-Cache-Info
Lfy
Magicmarker
X-CGP
Kp-EeAlive
X-Sedo-Request-Id
Server-Host
Server-Int
Heartbleed
True-Client-Country-4JS
X-C
X-Cache-Miss-From
RNT-Time
Proxy-Connection
X-ServiceProvider
Pramga
X-Sf
X-Crawler
X-Cache-FS-Status
X-Cache-Debug
Memcached
RNT-Machine
X-Cache-Id
X-Cache-Host
X-Cms-Context
X-CUA
Cache-Cookie-Set-From
X-Reboot
X-LI-Proto
X-Hash
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Li-Pop
X-Li-Fabric
X-Swa-Ws
X-LAGOON
X-Request-URI
HA-Ipaddr
X-Geo-Header
X-Qloud-Router
X-Proxy-Upstream
X-Origin-Date
X-Origin-Expires
X-Node-Id
X-No-Session
X-Varnish-Url
X-Page-Type
X-PHP-Host
X-Proxy-Cache-Status
X-LI-UUID
X-Policy
X-Location
X-F5-Cache
X-Refresh
X-Epic-Correlation-Id
X-Distributor
Country-Code
CDCHOST
Cache-Cookie-Set-Lfrom
Apple-News-Services-Request-Url
Cache-Cookie-Set-Idcheck
X-Distil-CS
Fastly-Backend-Name
X-SIPLIST1
Ha-Gx-Prefs
X-SN
X-Device-Os
X-Dispatcher-Server
Fastly-Soc-X-Request-Id
Apple-News-Services-Parsed-Url
Backend
Apple-News-Services-Handled
X-Eu-Site
X-Irp-Debug
X-Webstats-RespID
AKAMAI
Apple-News-Services-Host
X-GZip
X-MSEdge-Features
X-Gateway-Cache-Key
X-Block-Status
X-Info
X-Gateway-Cache-Status
X-BBXSRF
X-Key
X-Fetched-On
X-Gateway-Skip-Cache
X-Backend-State
X-MSEdge-Flight
X-Bip
X-Gen-Mode
X-Rebelmouse-Cache-Control
X-S-Maxage
X-Rebelmouse-Surrogate-Control
X-Cdn-Srv
X-GeoIP-Country-Code
X-Hnp-Log
X-Core-Mission
X-GeoIP-City
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Level-Front-Cache
X-Generated-On
X-Planisys-CDN-Cache
X-Thanos
Fastly-SWR
Fastly-SIE
X-Dc
X-Wikidot-Backend
X-Ah-Environment
User-Cache-Control
X-Sorting-Hat-ShopId
SD-X-WS
Content-Disposition
Pagetype
Powered-By
X-ShopId
X-TT-LOGID
X-ShardId
X-Wikidot-Static-Cache
X-Sorting-Hat-PodId
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Auto-Login
Web-Mar-Node
X-Amz-Meta-Cache-Control
X-Shopify-Stage
HTTPS
X-Alternate-Cache-Key
Fastly-SSL
X-Skip-Cache
X-WPE-Loopback-Upstream-Addr
X-FireWall-Port
X-Nc
X-Backend-Host
X-Servername
X-Via-Edge
X-Via-SSL
X-Owner
X-Micro-Cache
X-Variation
X-Fastly-Cache
X-TrackingId
X-User
Adler-Geo
X-Varnish-Beresp-Ttl
X-Cache-Bucket
Pragrma
X-Amzn-Remapped-Content-Length
Platform
X-Server-IP
X-Server-Time
Is-Eu
X-Backend-Url
X-Original-Request
X-Returned-From-BeforeDispatch
X-Actual-URL
Server-ID
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Server-By
X-Passed-To
X-Stale
X-Returned-From
X-Svr
X-RateLimit-Reset
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Unique-ID
X-VServer
X-HS-Cache-Config
Host-ID
X-Croise-Owner
X-Microcachable
Cteonnt-Length
ServerName
FNAC-ModuleRouting
Viewtype
VivaBuild
Mime-Version
X-Pjax-Url
X-Org
REQUESTUUID
DSUID
Cdn-Host
X-Edge-Server
Cdn-Request-Time
X-Load-Cache
X-CDN-Forward
X-Parent-Response-Time
Gh-Request-Id
X-Aicache-OS
X-NC
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-V
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-CSRF-TOKEN
SID
X-Cdn-Origin
Time
V-Age
X-From-Cache
X-Sn-Servicetimems
X-FPC
ProcessTime
X-Ua-Device
Memory
X-Req
X-Apm-Inst-Hash
X-Apm-Svc-Key
Rt-Proxy-Cache
X-Apm-App-Name
X-ND-Cache
X-Exp-Se
X-Gdpr
X-Geo
MIME-Version
X-Servedbyhost
X-Served-From
Odigeo-Trace-Id
X-Tb-Optimization-Total-Bytes-Saved
PICS-Label
X-URL
X-HTML-Minification-Powered-By
Cache
X-Wa
Cf-Ipcountry
X-Fstrz
X-Lb-Id
Public-Key-Pins-Report-Only
X-B3-Parentspanid
X-GEO
AR-SID
X-Optimization
X-Cache-HT
Cdn
X-Git-Hash
X-Newrelic-Synthetics
Wxu-Next-Hostname
Wxu-Next-Region
CF-IPCountry
X-Response-By
Resin-Trace
Wxu-Next-Commit
Fastcgi-X-Cache-Version
X-DC
X-Varnish-Beresp-TTL
X-Webkit-Csp
GMS-Ver
HostName
X-Vcache
X-Atg-Version
Proxy-Firewall
X-WR-MODIFICATION
X-Release
XServer
X-Vcl-Version
X-TH-Server
X-WebServer
WZWS-RAY
X-Amz-Meta-Surrogate-Control
X-Fastly-Backend-Reqs
Processtime
X-APP
X-Ratelimit-Remaining
X-We-Are-Hiring
Mobile-Detection-Method
X-Clientip
X-Phone
X-Ratelimit-Limit
X-UE-Client-Country
X-Daa-Tunnel
GW-Server
X-LB-ID
Countrycode
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
SS
Amp-Access-Control-Allow-Source-Origin
X-Hyper-Cache
X-Instart-Info
X-WA
CF-Cached-On
X-Host-Name
Ohc-File-Size
X-Zone
X-NGINX-Cache
Backend-Name
X-HS-Status
X-Nananana
X-Fastly-Country-Code
X-Check-Cacheable
X-Upstream-CT
FSS-Cache
Pics-Label
X-Upstream-HT
X-PF-Uncompressing
FSS-Proxy
X-HS-Combine-CSS
X-Ratelimit-Reset
Lb
GeoIp-Country-Code
X-CSRF-Token
352pxline
355prline
Geoip-Latitude
409pxxline
X-ServedByHost
286prxHost
X-Server-W
188prxHost
219prxHost
225prxHost
X-Backend-TTL
178proxuri
X-Worker
Xxline
189phosttRef
X-Be
DataCenter
X-Fpc
X-SERVER-NAME
URI
Ohc-Cache-HIT
X-VHOST
SN
Geoip-City
X-IPS-LoggedIn
X-Dynatrace
X-GZIP
X-UPSTREAM-Address
X-BE
Version
X-LiteSpeed-Cache-Control
X-Render-Time
X-Gen-Id
WP-Super-Cache
X-UCC
X-Request-Start
Esi-Enabled
X-B3-SpanId
Who
X-CS
X-Varnish-Action
X-NGENIX-Cache
X-ID
X-Unique-Id
X-AssetVersion
X-PJAX-URL
X-VCL-Version
X-Contensis-Viewer-Groups
CDN
X-Html-Edge-Cache
X-Cache-URL
X-FORWARDED-FOR
X-HostName
Dynatrace
X-LiteSpeed-Tag
X-Fastly-Cache-Hits
X-ServerName
Cneonction
GeoIP-Country-Code
GeoIP-City
X-GDPR
RequestUuid
X-Pf-Uncompressing
X-Via-Ucdn
X-SRV
GeoIP-Latitude
X-Cache-Ttl
X-Cdn-Cache
Serverid
X-Store
X-NWS-UUID-VERIFY
X-Akamai-Request-ID2
X-Vtex-Processado-Em
X-Via-NSCOPI
X-Vtex-Remote-Cache
RequestId
X-Servedby
Accept-Ch
Server-Id
X-RequestId
A
X-Request-Url
Accept-Language
X-Akamai-SSL-Client-Sid
X-Pc-Key
X-Pc-Appver
X-Pc-Hit
X-Reqid
X-EC-Lua
Ohc-Response-Time
X-Port
Get-Access-Time
X-Dw-Trace-Id
IBM-Web2-Location
X-Generation-Time
Is-Session-Tracking
X-Serial
NnCoection
X-Cdn-Request-ID
X-HTML-Edge-Cache
Frontcache
X-ZONE