Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
Access-Control-Max-Age
P3p
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
WPE-Backend
X-Varnish-Cache
X-Server-Powered-By
X-Nginx-Cache-Status
X-Robots-Tag
X-Page-Speed
EagleId
X-UA-Device
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-WebKit-CSP
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-Host
X-CST
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
Report-To
X-Server-Id
X-Type
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Readtime
Request-Id
X-Origin-Cache
X-Rack-Cache
X-Url
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Cache-Lookup
X-Country-Code
NEL
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
X-Mod-Pagespeed
Pinterest-Generated-By
X-Origin-Upstream-Status
X-Px
X-DataDome
X-Upstream-Env
Edge-Control
X-Goog-Hash
Verso
X-ESI
Accept-CH
X-Server-Name
X-HW
X-ORACLE-DMS-RID
X-Dispatcher
X-Server-ID
MS-Author-Via
X-VARITI-CCR
AR-CACHE
AR-ATIME
AR-PoweredBy
X-DataStream-Cache-Status
X-MS-InvokeApp
X-Mobile-Rewrite
Arc-Version
X-GitHub-Request-Id
PB-RID
PB-PID
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Cached
X-Version
Charset
Content-MD5
X-Powered-By-Plesk
Public-Key-Pins
X-Recruiting
X-Dns-Prefetch-Control
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
Ar-Sid
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-Vname
X-TtlSet
X-PC
X-Ser
X-TTL
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Varnish-TTL
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Trace
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-FTR-Expires
X-VCache
X-Amz-Rid
X-XRDS-Location
S
X-SharePointHealthScore
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-ID
X-Debug
TCN
Arr-Disable-Session-Affinity
X-Shield-Request-Id
DynaTrace
X-Hits
X-Dw-Request-Base-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
SPIisLatency
SPRequestDuration
X-Ttl
X-Akam-SW-Version
Access-Control-Request-Method
X-T
X-FTR-Cache-Host
X-Goog-Storage-Class
X-Powered-CMS
X-B3-TraceId
Pinterest-Version
X-Oracle-Dms-Rid
X-Pinterest-Rid
X-Upstream-Proxy
Front-End-Https
X-SERVER
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Tracecode
X-MSEdge-Ref
Realpath
X-Id
X-Amzn-Trace-Id
X-Aspnet-Version
X-Litespeed-Cache
X-Varnish-Age
X-N
Fastcgi-Cache
X-Content-Type
X-Forwarded-For
Paypal-Debug-Id
X-Upstream
Alternate-Protocol
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-RateLimit-Remaining
X-Logged-In
X-Frontend
X-PressLabs-Stats
X-Sol
Display
X-Middleton-Display
X-HS-Content-Id
X-HS-Hub-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Response
X-Middleton-Response
X-Content-Digest
X-Hostname
AMP-Access-Control-Allow-Source-Origin
X-Fastcgi-Cache
X-Srv
X-Pad
X-Accel-Expires
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Accel-Buffering
Host
Server-Name
X-Cache-Key
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Analytics
Backend-Timing
X-User-Agent
X-Content-Options
X-Correlation-Id
X-B3-Traceid
X-Debug-Info
X-AppVersion
X-Revision
X-Activity-Id
X-LB-Cache
X-Az
X-Cdn
X-Amzn-RequestId
FilterID
X-Amz-Apigw-Id
Accept-Charset
Refresh
X-Cache-2
X-IPLB-Instance
X-B3-Sampled
X-Rid
Surrogate-Key
X-Cache-Hit
Powered-By-ChinaCache
X-DIS-Request-ID
X-B
X-CF-Powered-By
ServerID
X-Page-Id
X-FastCGI-Cache
X-Grace
X-Whom
Server-Info
TP-L2-Cache
TP-Cache
X-PHP-Backend
X-Request-Received
X-Request-Processing-Time
MS-CV
Host-Header
X-GUploader-UploadID
X-Cached-By
Cache-Status
X-Content-Security-Policy-Report-Only
X-TT
X-Kong-Proxy-Latency
VIX-Pulpo-Upstream-Status
X-Origin-Server
X-Kong-Upstream-Latency
Source
VIX-Pulpo-Node
X-Varnish-Backend
X-Amz-Replication-Status
X-Framework
X-Cache-Action
X-UA-Device-Type
X-Cluster
X-Content-Powered-By
X-Webkit-CSP
Access-Control-Allow-Method
X-App-Environment
X-Akamai-Edgescape
X-Drupal-Cache-Tags
X-Request-Guid
X-Mobile
X-Platform-Server
X-Varnish-Grace
X-Ruxit-Js-Agent
X-F-Cache
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Server
X-FW-Static
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-SS-Set-Cookie
X-FB-Debug
X-Zen-Fury
X-Instance
X-Ezoic-Cdn
X-Shard
X-RateLimit-Limit
X-Geo-Country
X-Forwarded-Host
X-Handled-By
X-Cache-TTL
X-Magnolia-Registration
Edge-Cache-Tag
X-Node-Name
From-Origin
X-ATG-Version
X-Cache-Age
X-Varnish-Hostname
X-App-Server
Cache-Tags
DC
Cleartype
X-Varnish-Server
X-BCube-Filmed-By
PageSpeed
X-AOL-HN
Payment
X-Cache-Control
Healthy
Upgrade-Insecure-Requests
X-RequestSource
X-Response-Served-From
Filters
CACHE
Server-Node
X-Adobe-Loc
X-Adobe-Content
X-WebKit-CSP-Report-Only
X-TX-ID
X-Generated-By
X-Region
Fastly-Restarts
X-Storage
Country
Cache-Tv-Group
X-GeoIP
NGB
X-VG-WebCache
X-TT-TIMESTAMP
X-RTag
X-UUID
Ms-Operation-Id
Retry-After
Actual-Object-TTL
X-Jobs
X-Drupal-Cache-Contexts
X-Cache-Rule
Webserver
X-Redis-Cache
X-Content-Age
X-FW-Dynamic
X-Locale
X-Signature
X-Cacheable-TTL
X-B-Cache
X-Varnish-Hits
GEO-INFO
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-TA-CDN-Provider
ServedBy
X-XRDS-LOCATION
Liferay-Portal
Powered
X-Contextid
Frame-Options
X-Seen-By
X-Wix-Server-Artifact-Id
HitType
X-Rendered-As
X-Real-IP
X-Cache-TTL-Remaining
X-Via-JSL
X-Oneagent-Js-Injection
X-Varnish-IP
X-WA-Info
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-GRACE
X-BACKEND-TTL
Viewport
S-Cnection
X-RemovedCookies
Eomportal-Instance
X-ProcessESI
X-Upgrade-Enabled
X-Cache-NE
NtCoent-Length
X-Time
X-Guploader-Uploadid
X-Cache-Server
Content-Style-Type
Content-Script-Type
Xserver
X-Esi
X-Mode
Datacenter
X-Akamai-Transformed
X-Cache-Config
Cache-Key
X-Varnish-Cache-Hits
Load-Balancing
Mn-Server-Ip
X-Cache-Var
X-ES-SERVER
X-Is-Bot
X-Hl-Ver
X-From
X-S
X-Path-Route
X-Proto
Meta-Geo
X-Cache-Var-Map
Machine
X-Detected-As
X-Device-Type
X-RN-RSRV
X-FC-Vary-Parameters
X-LJ-Flow-ID
X-VWS-Id
X-VG-TLSProxy
X-Routing-Service
X-Proxied
X-Origin-Hint
Webcakes-Region
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
OT-Force-Account-Verify
Mail-Subject
L5d-Success-Class
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
X-Cache-Operation
Webcakes-App-Version
X-Zipkin-Id
We-Hiring
TWC-Privacy
Vix-Hermes-Req-Id
X-AWS-Id
Access-Control-Request-Headers
X-Debug-Cache
X-Birta-Served
X-EIG-Tracking-Id
X-Environment-Context
X-Hosted-By
X-Birta-Cache-Post
X-Backend-Name
Origin-Edge-Control
X-FB-TRIP-ID
S-Rt
X-Access
X-L-Path
X-Labrador-Cache-Channel
X-TNCMS
X-Time-Microsecs
NGX
X-Viewer-Country
X-Web-Node
X-Tb
X-ServerID
X-Loop
X-Cache-Enabled
X-Origin-Response-Time
X-Section
Origin-Cache-Control
X-Akamai-Request-ID
X-Endurance-Cache-Level
X-Proxy-Build
X-Trace-Id
X-Varnish-Cacheable
X-JoinUs
X-IP
X-PCL
Now
X-ProxyCache-Key
X-OCL
X-ProxyCache-Status
Selected-FE
X-CCM
X-Timing-Wait
X-Format
X-Xfnlog-Site
X-Human
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-FW-Version
Cache-Hits
Cache-Tag
X-BYPASS-REASON
X-Via-CDN
X-Generated
X-Grey
X-Vgn-Hpd-Reason
X-Www-Served-By
X-Site-Version
X-Status
X-Rocket-Nginx-Bypass
Decoy-Debug-TTL
Decoy-Debug-Status
DB-Nickname
X-Via-Fastly
Decoy-Debug-Key
X-NCache
X-Cache-Category-Id
ViewerVersion
X-Wix-Request-Id
X-Proxy
X-MP-GENERATED-AT
X-NWS-LOG-UUID
X-VC-Cache
X-RCS-CacheZone
Uber-Trace-Id
X-Internal-Host
X-CDN-Cache
X-R9-Blue-Green-Version
Served-By
X-Tumblr-Pixel-3
X-EdgeConnect-Cache-Status
X-Newrelic-App-Data
X-Dynatrace-Js-Agent
X-NewRelic-App-Data
X-Cache-Remote
X-Rule
LB
Pagespeed
AsisCache
Release
X-Origin-Host
X-UnsetCookies
X-UA
X-Sucuri-ID
Rt-Fastcgi-Cache
X-Cluster-Node
X-App-Name
X-Ua
Nel
User-Agent
X-Nginx-Cache
X-PERF
X-ApacheServer
X-Source
X-Agile-Age
X-TIME
X-App-Version
X-Agile
X-Agile-Id
X-Request-Time
X-Datadome
X-B3-Spanid
Cache-Name
Hostname
X-APP-VERSION
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Origin
X-Edge-Location
X-OVcl-Cache
X-VCT
X-OVcl
X-CACHE-KEY
X-Hit
X-Pubstack
Warning
X-Origin-CC
X-Edge-IP
X-Origin-TTL
X-Cdn-Forward
Www
UCS
X-A-Wwc
Origin
Thinkindot-Control
X-A-Dgt
X-Aed
Rendered-Blocks
Request-Country
Request-EU
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Ajk
X-A-Dam
Cache-Prefix
X-A-Ccd
Server-Surrogate-Control
BehaviorPad-Version
X-A-Dcw
Arc-Country
Request-Time
X-A
Server-Cache-Control
MD5-Digest
Meta-Geo-Continent
Node
Fly-Request-Id
Fly-Cache
Cross-Origin-Window-Policy
X-Accel-Expires-Debug
Ec-Rule-Version
On-Server
X-Cache-Expires
X-Platform
X-VG-WebServer
X-Processor
X-Region-Sid
X-Request-UUID
X-PAYTM-SRV-ID
X-NX-Host
X-Matched-Rule
X-Logtrace-Id
X-Mobile-URL
X-NodeID
X-NU-AKA-ACS-Version
X-Rewrite-Enabled
X-Rojux
X-Twitter-Response-Tags
X-Trv-Group
X-Varnish-Authentication
X-Up
X-Var-Ttl
X-Transaction
X-Thinkindot-L3
X-ScT
X-S-Cookie
X-Secret
X-Server-Group
X-SRCache-Key
X-IN-WAF
X-IN-APIGATEWAY
X-Connection-Hash
X-CF-Lambda-Version
X-Core-Value
X-D
X-Date
X-CF-Lambda-Fn
X-Cache-Grace
X-B-Cookie
X-ARC
X-BB-ID
Xc-Version
X-Cache-ASPX
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-G
X-External-Request-Id
X-Gannett-Site-Version
X-Generated-In
X-Hp-Webp
X-DPWN-IS-SECURE
X-Developer
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Destination
X-Application
X-Ocache
X-Protected-By
X-Sucuri-Cache
X-ElasticPress-Search
X-Cache-Backend
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Policy
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Qloud-Router
Web-Mar-Node
X-Origin-Expires
True-Client-Country-4JS
X-Origin-Date
X-Page-Type
X-PHP-Host
X-RateLimit-Remaining-Second
RNT-Machine
RNT-Time
X-Refresh
X-Request-URI
X-Sedo-Request-Id
Server-Host
Server-Int
X-Rebelmouse-Cache-Control
X-Block-Status
X-Rebelmouse-Surrogate-Control
SRV
X-Reboot
X-RateLimit-Limit-Second
X-C
X-Epic-Correlation-Id
X-Eu-Site
X-Key
X-LAGOON
X-Distil-CS
X-Distributor
X-Irp-Debug
X-Instart-Isnd
X-Hash
X-Geo-Header
X-Gen-Mode
X-Hnp-Log
X-Info
X-Dispatcher-Server
X-Device-Os
X-Cache-Id
X-Cache-Miss-From
X-Cache-Host
X-No-Session
X-Cache-Debug
X-CGP
X-Crawler
X-Li-Fabric
X-Developers
X-Li-Pop
X-LI-Proto
X-LI-UUID
Proxy-Connection
User-Cache-Control
X-TT-LOGID
X-SIPLIST1
IsBot
Kp-EeAlive
Cache-Cookie-Set-Lfrom
Country-Code
Heartbleed
Cache-Cookie-Set-Idcheck
Fastly-Backend-Name
Fastly-SIE
Cache-Cookie-Set-From
X-SN
HA-Ipaddr
Ha-Gx-Prefs
X-WPE-Loopback-Upstream-Addr
Apple-News-Services-Handled
X-Varnish-Url
X-Sf
Apple-News-Services-Host
Apple-News-Services-Request-Url
Pagetype
X-Servername
X-Swa-Ws
Apple-News-Services-Parsed-Url
Fastly-SWR
CDCHOST
X-ServiceProvider
X-Varnish-Ttl
X-FireWall-Port
DSUID
Fastly-SSL
Platform
X-Backend-State
Backend
Fastly-Soc-X-Request-Id
X-Sorting-Hat-ShopId
X-MSEdge-Flight
X-Cms-Context
X-Core-Mission
X-MSEdge-Features
X-Thanos
X-TrackingId
X-Ah-Environment
X-Sorting-Hat-PodId
X-Level-Front-Cache
X-Amzn-Remapped-Date
Content-Disposition
X-Nginx-Cache-Key
X-Bip
AKAMAI
X-Cache-Info
N-Cache
X-Gateway-Cache-Status
X-ShardId
X-Gateway-Cache-Key
Is-Eu
Magicmarker
SD-X-WS
X-Gateway-Skip-Cache
X-Generated-On
X-GeoIP-City
Pramga
X-Server-IP
X-User
X-S-Maxage
HTTPS
X-ShopId
Adler-Geo
X-Fetched-On
X-Location
X-Alternate-Cache-Key
X-Amzn-Remapped-Connection
Lfy
X-Amzn-Remapped-Content-Length
X-Webstats-RespID
Memcached
X-F5-Cache
X-GeoIP-Country-Code
X-Variation
X-Via-SSL
X-Via-Edge
X-Shopify-Stage
ServerName
FNAC-ModuleRouting
X-BBXSRF
X-Skip-Cache
Cteonnt-Length
X-Amz-Meta-Cache-Control
X-Auto-Login
X-Planisys-CDN-Cache
X-Fastly-Cache
X-Server-Time
X-Cache-Bucket
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Backend-Host
X-Owner
X-Cache-FS-Status
X-Wikidot-Static-Cache
X-Backend-Url
X-Micro-Cache
X-Node-Id
X-Wikidot-Backend
Cache
X-GZip
Server-ID
X-RateLimit-Reset
X-Cdn-Srv
X-Varnish-Beresp-Ttl
X-Real-Ip
Powered-By
Gh-Request-Id
X-Org
X-CUA
Section-Io-Cache
X-Nc
X-Pjax-Url
X-Sn-Servicetimems
X-Load-Cache
Pragrma
X-Cdn-Origin
V-Age
X-Apm-Inst-Hash
REQUESTUUID
MIME-Version
X-Apm-App-Name
VivaBuild
X-Apm-Svc-Key
Viewtype
X-NC
X-Aicache-OS
X-Returned-From-DLL
X-Parent-Response-Time
X-Original-Request
X-FPC
X-Returned-From
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Actual-URL
X-Returned-From-PostProcessResponse
X-Passed-To-PostProcessResponse
X-Dc
X-Returned-From-BeforeDispatch
X-Stale
X-Server-By
Rt-Proxy-Cache
X-CDN-Forward
Fastcgi-Useragent
X-ND-Cache
X-Exp-Se
X-Svr
X-Served-From
X-CSRF-TOKEN
X-Croise-Owner
X-HS-Cache-Config
Host-ID
X-Geo
X-VServer
X-Gdpr
X-Ua-Device
HostName
X-Edge-Server
Cdn-Request-Time
X-Unique-ID
Cdn-Host
X-B3-Parentspanid
X-Wa
X-Microcachable
X-Servedbyhost
ProcessTime
X-DC
Wxu-Next-Region
Resin-Trace
SID
Wxu-Next-Hostname
Time
X-Oss-Server-Time
X-Git-Hash
X-Oss-Request-Id
Memory
PICS-Label
X-Oss-Object-Type
Mime-Version
X-Oss-Hash-Crc64ecma
Wxu-Next-Commit
X-Oss-Storage-Class
X-Tb-Optimization-Total-Bytes-Saved
X-Newrelic-Synthetics
X-V
X-From-Cache
CF-IPCountry
X-Req
X-Cache-HT
X-Optimization
Cf-Ipcountry
X-ID
AR-SID
Odigeo-Trace-Id
Cdn
X-Release
X-URL
X-HTML-Minification-Powered-By
X-TH-Server
X-WebServer
X-Host-Name
X-Lb-Id
X-Varnish-Beresp-TTL
CF-Cached-On
X-Fstrz
X-Phone
X-Daa-Tunnel
X-Atg-Version
Proxy-Firewall
X-Response-By
X-LB-ID
XServer
X-Instart-Info
X-Upstream-HT
Public-Key-Pins-Report-Only
X-Upstream-CT
Backend-Name
Processtime
X-WR-MODIFICATION
GMS-Ver
X-APP
X-Ratelimit-Remaining
X-Check-Cacheable
X-Ratelimit-Limit
X-Fastly-Backend-Reqs
X-Worker
WZWS-RAY
X-Vcl-Version
Fastcgi-X-Cache-Version
X-GEO
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
219prxHost
409pxxline
X-Server-W
286prxHost
355prline
225prxHost
352pxline
178proxuri
Xxline
X-B3-SpanId
189phosttRef
188prxHost
X-Zone
X-Nananana
X-IPS-LoggedIn
X-Amz-Meta-Surrogate-Control
X-NGINX-Cache
Pics-Label
X-Vcache
X-Backend-TTL
Version
X-Ratelimit-Reset
Mobile-Detection-Method
X-We-Are-Hiring
X-UE-Client-Country
X-Clientip
X-WA
Countrycode
GW-Server
X-HS-Status
Lb
SN
X-UPSTREAM-Address
X-Hyper-Cache
WP-Super-Cache
X-Fastly-Country-Code
SS
X-ServedByHost
X-CSRF-Token
Ohc-File-Size
DataCenter
GeoIp-Country-Code
Geoip-Latitude
X-SERVER-NAME
Esi-Enabled
X-VCL-Version
GeoIP-City
GeoIP-Latitude
X-Akamai-Request-ID2
X-AssetVersion
X-Contensis-Viewer-Groups
GeoIP-Country-Code
X-SRV
Accept-Language
X-Dynatrace
X-GZIP
URI
X-Request-Start
FSS-Cache
FSS-Proxy
X-Be
X-GDPR
X-HS-Combine-CSS
X-PF-Uncompressing
X-BE
X-Via-Ucdn
X-Render-Time
Geoip-City
Serverid
X-CS
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-NWS-UUID-VERIFY
X-RequestId
X-LiteSpeed-Cache-Control
X-Unique-Id
CDN
X-PJAX-URL
X-Fpc
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Reqid
X-Gen-Id
Locale
X-ZONE
X-Via-NSCOPI
Ohc-Cache-HIT
FastCGI-Cache
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
X-HostName
Dynatrace
X-Fastly-Cache-Hits
X-ABtesting
RequestUuid
X-Flog
X-Html-Edge-Cache
X-UCC
X-Pf-Uncompressing
Cneonction
X-Hello
X-Cdn-Cache
X-Cache-Ttl
X-LiteSpeed-Tag
A
X-Store
X-Varnish-Action
Who
Server-Id
X-Request-Url
Accept-Ch
X-Generation-Time
IBM-Web2-Location
Dnion-Transfer-Encoding
X-Akamai-SSL-Client-Sid
X-Dw-Trace-Id
X-Cache-URL
X-Cdn-Request-ID
Frontcache
Get-Access-Time
X-HTML-Edge-Cache
X-Serial
X-ServerName
Ohc-Response-Time
X-EC-Lua
NnCoection
Is-Session-Tracking
X-Port