Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
X-Robots-Tag
X-Varnish-Cache
X-Server-Powered-By
X-Nginx-Cache-Status
WPE-Backend
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-CST
X-Host
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
X-Server-Id
X-Type
Report-To
X-Backend-Server
X-Application-Context
X-Cloud-Trace-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Country-Code
X-Cache-Lookup
Rating
NEL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
Pinterest-Generated-By
X-Mod-Pagespeed
X-Upstream-Env
X-Origin-Upstream-Status
X-Px
X-DataDome
Edge-Control
X-Goog-Hash
Verso
X-Server-Name
Accept-CH
X-ESI
X-HW
X-Dispatcher
X-ORACLE-DMS-RID
MS-Author-Via
X-DataStream-Cache-Status
X-VARITI-CCR
AR-PoweredBy
X-GitHub-Request-Id
AR-ATIME
AR-CACHE
Arc-Version
X-MS-InvokeApp
PB-RID
PB-PID
X-Mobile-Rewrite
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Cached
Charset
X-Version
X-Server-ID
Content-MD5
X-Dns-Prefetch-Control
X-Powered-By-Plesk
Public-Key-Pins
X-Recruiting
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
X-Navigation-Version
X-D2id
Ar-Sid
X-Abt-Application-Version
X-TTL
X-Vname
X-PC
X-TtlSet
X-Ser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Varnish-TTL
X-Trace
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-FTR-Expires
X-Amz-Rid
X-SharePointHealthScore
X-VCache
S
X-Fastly-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-XRDS-Location
X-Debug
Arr-Disable-Session-Affinity
TCN
X-Shield-Request-Id
X-Dw-Request-Base-Id
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
DynaTrace
SPRequestDuration
SPIisLatency
X-Upstream-Proxy
Pinterest-Version
X-Oracle-Dms-Rid
X-Pinterest-Rid
X-Akam-SW-Version
Access-Control-Request-Method
X-T
X-SERVER
X-Goog-Storage-Class
X-FTR-Cache-Host
X-Powered-CMS
Front-End-Https
X-Ttl
X-B3-TraceId
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Tracecode
Realpath
X-Amzn-Trace-Id
X-MSEdge-Ref
X-Id
X-N
Fastcgi-Cache
Paypal-Debug-Id
X-Varnish-Age
X-Forwarded-For
X-Content-Type
X-Upstream
Alternate-Protocol
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-RateLimit-Remaining
X-Frontend
X-Logged-In
X-PressLabs-Stats
X-HS-Content-Id
X-Sol
X-HS-Hub-Id
Display
X-Middleton-Display
Fusion-Source
X-Content-Digest
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
X-Middleton-Response
X-Litespeed-Cache
Response
AMP-Access-Control-Allow-Source-Origin
X-Hostname
X-Fastcgi-Cache
X-Srv
X-Accel-Expires
X-Pad
X-Cache-Key
X-Accel-Buffering
X-Kinsta-Cache
MicrosoftSharePointTeamServices
Server-Name
Host
X-B3-Traceid
X-Cdn
X-Content-Options
X-Analytics
X-User-Agent
Backend-Timing
X-Correlation-Id
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-LB-Cache
X-Revision
X-Debug-Info
X-Amz-Apigw-Id
X-Amzn-RequestId
X-AppVersion
X-Az
Refresh
X-Activity-Id
Accept-Charset
X-IPLB-Instance
FilterID
X-Rid
X-B3-Sampled
X-Cache-2
X-Cache-Hit
X-B
X-DIS-Request-ID
Powered-By-ChinaCache
Surrogate-Key
X-CF-Powered-By
ServerID
X-Grace
X-Page-Id
X-Whom
X-FastCGI-Cache
Server-Info
TP-Cache
TP-L2-Cache
X-PHP-Backend
X-Request-Received
X-Request-Processing-Time
MS-CV
X-Webkit-CSP
Host-Header
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-Amz-Replication-Status
X-Origin-Server
Source
X-Cached-By
X-Kong-Proxy-Latency
VIX-Pulpo-Node
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
X-TT
X-Kong-Upstream-Latency
X-Framework
X-UA-Device-Type
X-Akamai-Edgescape
Cache-Status
X-Cluster
X-Cache-Action
X-App-Environment
Access-Control-Allow-Method
X-Mobile
X-Content-Powered-By
X-GUploader-UploadID
X-Platform-Server
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Hash
X-F-Cache
X-Tumblr-Pixel-0
X-Varnish-Grace
X-Tumblr-User
X-Request-Guid
X-Tumblr-Pixel
X-FW-Type
X-Drupal-Cache-Tags
X-Instance
X-RateLimit-Limit
X-SS-Set-Cookie
X-FB-Debug
X-Zen-Fury
X-Ezoic-Cdn
X-Shard
X-Handled-By
X-Geo-Country
X-Forwarded-Host
X-Cache-TTL
X-Magnolia-Registration
Edge-Cache-Tag
From-Origin
X-ATG-Version
X-Node-Name
X-Cache-Age
X-App-Server
PageSpeed
X-Varnish-Hostname
X-Varnish-Server
DC
Cache-Tags
Cleartype
X-BCube-Filmed-By
X-AOL-HN
X-Cache-Control
CACHE
Payment
Upgrade-Insecure-Requests
Healthy
X-Generated-By
X-RequestSource
Filters
X-Region
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-Adobe-Loc
X-TX-ID
X-Adobe-Content
X-GeoIP
X-RTag
X-Redis-Cache
Webserver
X-VG-WebCache
X-TT-TIMESTAMP
X-UUID
X-Storage
Server-Node
Cache-Tv-Group
Ms-Operation-Id
Country
NGB
X-Cache-Rule
X-FW-Dynamic
X-Jobs
X-Signature
X-B-Cache
Retry-After
X-Drupal-Cache-Contexts
Actual-Object-TTL
X-Cacheable-TTL
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Content-Age
X-Locale
Fastly-Restarts
X-XRDS-LOCATION
GEO-INFO
X-Varnish-Hits
ServedBy
Liferay-Portal
X-Wix-Server-Artifact-Id
Powered
X-Seen-By
X-Contextid
X-TA-CDN-Provider
Frame-Options
X-Oneagent-Js-Injection
HitType
X-Rendered-As
X-Via-JSL
X-Cache-TTL-Remaining
X-Varnish-IP
X-Real-IP
X-WA-Info
X-Yottaa-Metrics
X-Yottaa-Optimizations
S-Cnection
Viewport
X-BACKEND-TTL
X-Guploader-Uploadid
X-GRACE
X-Upgrade-Enabled
Eomportal-Instance
X-ProcessESI
X-Esi
X-RemovedCookies
X-Cache-NE
Content-Style-Type
Content-Script-Type
X-Cache-Server
NtCoent-Length
X-Mode
X-Time
Xserver
Datacenter
X-Akamai-Transformed
X-Cache-Config
X-RN-RSRV
X-Varnish-Cache-Hits
X-Routing-Service
X-ES-SERVER
X-Detected-As
X-Cache-Var-Map
X-From
X-Proxied
X-Proto
X-S
X-Cache-Var
X-Path-Route
X-Device-Type
Cache-Key
Cache-Hits
X-Is-Bot
Mn-Server-Ip
Meta-Geo
Machine
X-Zipkin-Id
X-Hl-Ver
Load-Balancing
TWC-Device-Class
Webcakes-App-Version
X-LJ-Flow-ID
Webcakes-Region
Property-Id
X-Tb
TWC-Connection-Speed
Webcakes-App-Name
TWC-GeoIP-Country
Mail-Subject
X-Cache-Enabled
TWC-Privacy
Vix-Hermes-Req-Id
X-Endurance-Cache-Level
TWC-GeoIP-LatLong
We-Hiring
TWC-Locale-Group
X-AWS-Id
Access-Control-Request-Headers
L5d-Success-Class
X-Viewer-Country
X-Environment-Context
X-FC-Vary-Parameters
X-VWS-Id
X-VG-TLSProxy
X-Hosted-By
X-L-Path
OT-Force-Account-Verify
X-Origin-Hint
X-Origin-Response-Time
Azure-Version
S-Rt
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-InstanceId
Origin-Edge-Control
Origin-Cache-Control
X-Cache-Operation
X-Access
X-FW-Version
X-Format
X-Web-Node
ViewerVersion
NGX
X-Labrador-Cache-Channel
X-Proxy
X-Loop
X-FB-TRIP-ID
X-EIG-Tracking-Id
X-Debug-Cache
X-Time-Microsecs
X-Akamai-Request-ID
X-Wix-Request-Id
X-ServerID
X-Section
X-Birta-Cache-Post
X-Backend-Name
X-TNCMS
X-Birta-Served
X-CCM
X-OCL
Now
Selected-FE
X-JoinUs
X-BYPASS-REASON
X-Human
X-IP
X-NCache
X-PCL
X-Timing-Wait
X-Proxy-Build
X-Xfnlog-Site
Cache-Tag
X-Status
X-ProxyCache-Status
X-ProxyCache-Key
X-Via-Fastly
Decoy-Debug-TTL
X-Via-CDN
X-Varnish-Cacheable
Decoy-Debug-Key
X-Trace-Id
DB-Nickname
Decoy-Debug-Status
X-Site-Version
X-Grey
X-Www-Served-By
X-Cache-Category-Id
X-Generated
X-Vgn-Hpd-Reason
X-Tumblr-Pixel-3
X-Rocket-Nginx-Bypass
X-Newrelic-App-Data
X-MP-GENERATED-AT
Uber-Trace-Id
Served-By
X-VC-Cache
X-Dynatrace-Js-Agent
X-RCS-CacheZone
X-EdgeConnect-Cache-Status
X-NWS-LOG-UUID
X-Internal-Host
X-R9-Blue-Green-Version
X-CDN-Cache
X-Rule
X-Origin-Host
X-NewRelic-App-Data
LB
X-Cache-Remote
X-Sucuri-ID
X-UA
AsisCache
X-UnsetCookies
Release
X-Cluster-Node
Nel
Rt-Fastcgi-Cache
Pagespeed
X-App-Name
User-Agent
X-ApacheServer
X-PERF
X-TIME
X-Datadome
X-Ua
X-Agile
X-Source
X-Nginx-Cache
X-Agile-Age
X-Agile-Id
X-APP-VERSION
X-App-Version
X-Request-Time
X-B3-Spanid
Cache-Name
Hostname
X-Edge-Location
X-OVcl-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Origin
X-OVcl
X-Hit
X-Ocache
X-Pubstack
X-VCT
Warning
X-Sucuri-Cache
X-Origin-TTL
X-Edge-IP
X-Origin-CC
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
Xc-Version
Thinkindot-Control
UCS
X-Accel-Expires-Debug
Www
X-A
X-Application
X-Cache-ASPX
X-Cache-Expires
X-Cache-Grace
X-BB-ID
X-B-Cookie
X-CF-Lambda-Fn
X-ARC
Thinkindot-CacheControl-Type
X-Aed
Request-EU
Ec-Rule-Version
Fly-Cache
Fly-Request-Id
MD5-Digest
Cross-Origin-Window-Policy
Cache-Prefix
Ajk
Arc-Country
BehaviorPad-Version
Meta-Geo-Continent
Node
Request-Time
Server-Cache-Control
Server-Surrogate-Control
X-CF-Lambda-Version
Request-Country
On-Server
Origin
Rendered-Blocks
Thinkindot-CacheControl
X-D
X-Processor
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-Platform
X-PAYTM-SRV-ID
X-Mobile-URL
X-NodeID
X-NU-AKA-ACS-Version
X-NX-Host
X-Rojux
X-S-Cookie
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Var-Ttl
X-Thinkindot-L3
X-SRCache-Key
X-ScT
X-Secret
X-Server-Group
X-Matched-Rule
X-Logtrace-Id
X-Debug-Cookies
X-Debug-Log
X-Destination
X-Developer
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Core-Value
X-Date
X-Debug-Cache-Expiry
X-DPWN-IS-SECURE
X-External-Request-Id
X-Varnish-Authentication
X-IN-APIGATEWAY
X-IN-WAF
X-Instart-Isnd
X-Hp-Webp
X-Generated-In
X-VG-WebServer
X-G
X-Gannett-Site-Version
X-Connection-Hash
X-A-Dam
X-Up
X-Cdn-Forward
X-Protected-By
X-Varnish-Beresp-Grace
X-Cache-Backend
X-ElasticPress-Search
X-Varnish-Ttl
X-Varnish-Beresp-Status
Server-Host
Server-Int
SRV
True-Client-Country-4JS
X-Eu-Site
X-SN
Lfy
RNT-Time
X-Geo-Header
Pagetype
Memcached
X-Request-URI
X-Info
X-Irp-Debug
X-ServiceProvider
X-Hnp-Log
X-Gen-Mode
Proxy-Connection
Pramga
X-Hash
RNT-Machine
Web-Mar-Node
X-Cache-Miss-From
X-Cache-Id
X-Sf
X-Amzn-Remapped-Date
X-CGP
X-Cache-Host
X-Servername
X-C
X-Block-Status
X-Rebelmouse-Surrogate-Control
X-Cache-Debug
X-Amzn-Remapped-Connection
X-Crawler
X-Distil-CS
X-Distributor
X-Key
X-Epic-Correlation-Id
X-SIPLIST1
X-Dispatcher-Server
X-Sedo-Request-Id
X-CACHE-KEY
X-Developers
X-Device-Os
User-Cache-Control
X-Varnish-Url
CDCHOST
X-TT-LOGID
X-Page-Type
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Origin-Expires
X-Origin-Date
X-Swa-Ws
Fastly-Backend-Name
X-No-Session
X-F5-Cache
Country-Code
Backend
X-WPE-Loopback-Upstream-Addr
X-Qloud-Router
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Webstats-RespID
X-Proxy-Cache-Status
X-Policy
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-PHP-Host
Fastly-SIE
X-Nginx-Cache-Key
X-LI-UUID
IsBot
HA-Ipaddr
X-Li-Fabric
Ha-Gx-Prefs
Heartbleed
X-LI-Proto
X-Li-Pop
Kp-EeAlive
X-Ah-Environment
X-Cache-Info
X-LAGOON
N-Cache
X-Refresh
Fastly-SWR
X-Reboot
Magicmarker
X-FireWall-Port
X-Generated-On
X-Cache-FS-Status
X-GeoIP-City
X-GeoIP-Country-Code
X-Level-Front-Cache
X-Core-Mission
X-Node-Id
X-Location
X-Fetched-On
X-Micro-Cache
X-Via-Edge
X-MSEdge-Features
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Server-IP
X-Cms-Context
X-MSEdge-Flight
X-Variation
X-S-Maxage
X-Gateway-Skip-Cache
X-Via-SSL
X-Bip
SD-X-WS
DSUID
Is-Eu
HTTPS
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Wikidot-Static-Cache
X-Skip-Cache
X-Thanos
X-Cache-Bucket
Adler-Geo
X-Fastly-Cache
X-User
AKAMAI
Content-Disposition
X-TrackingId
Fastly-SSL
Fastly-Soc-X-Request-Id
X-ShopId
Platform
X-Backend-State
X-Amz-Meta-Cache-Control
X-ShardId
X-Amzn-Remapped-Content-Length
X-BBXSRF
X-Alternate-Cache-Key
X-Wikidot-Backend
X-GZip
Cteonnt-Length
FNAC-ModuleRouting
X-Server-Time
X-Backend-Host
X-Planisys-CDN-TTL
X-Backend-Url
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Owner
ServerName
X-Auto-Login
X-Cdn-Srv
X-RateLimit-Reset
X-Real-Ip
X-Varnish-Beresp-Ttl
Powered-By
Section-Io-Cache
X-CUA
Server-ID
X-Org
Gh-Request-Id
Pragrma
MIME-Version
Cache
X-NC
X-Server-By
X-Passed-To-PostProcessResponse
X-Cdn-Origin
X-Parent-Response-Time
X-Aicache-OS
VivaBuild
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Returned-From-DLL
X-Sn-Servicetimems
X-Original-Request
X-Passed-To
X-Returned-From-PostProcessResponse
X-Nc
Viewtype
REQUESTUUID
X-Apm-App-Name
X-Returned-From-BeforeDispatch
X-Returned-From
X-FPC
X-Apm-Inst-Hash
Fastcgi-Useragent
X-Actual-URL
X-CDN-Forward
X-Pjax-Url
X-Stale
X-Svr
X-Apm-Svc-Key
V-Age
X-Load-Cache
X-ND-Cache
X-VServer
Rt-Proxy-Cache
Host-ID
X-Geo
X-Exp-Se
X-Croise-Owner
X-HS-Cache-Config
X-Dc
X-Served-From
X-Ua-Device
X-Edge-Server
X-CSRF-TOKEN
X-Gdpr
X-Unique-ID
HostName
Cdn-Request-Time
Cdn-Host
X-Microcachable
X-DC
X-B3-Parentspanid
SID
X-Wa
X-Oss-Hash-Crc64ecma
PICS-Label
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Servedbyhost
Time
Memory
X-Oss-Request-Id
ProcessTime
Mime-Version
Wxu-Next-Region
Resin-Trace
X-Git-Hash
Wxu-Next-Hostname
Wxu-Next-Commit
X-V
X-From-Cache
X-Tb-Optimization-Total-Bytes-Saved
CF-IPCountry
X-Req
X-ID
X-Cache-HT
AR-SID
X-Newrelic-Synthetics
X-Optimization
Odigeo-Trace-Id
Cf-Ipcountry
Cdn
X-Lb-Id
X-Release
X-HTML-Minification-Powered-By
X-Varnish-Beresp-TTL
X-WebServer
X-Fstrz
X-TH-Server
X-Atg-Version
X-Host-Name
X-Response-By
Proxy-Firewall
X-Phone
XServer
Public-Key-Pins-Report-Only
CF-Cached-On
X-APP
GMS-Ver
Processtime
X-LB-ID
X-WR-MODIFICATION
X-Instart-Info
X-Ratelimit-Remaining
X-Daa-Tunnel
X-Upstream-HT
X-Ratelimit-Limit
X-Fastly-Backend-Reqs
Backend-Name
WZWS-RAY
X-Vcl-Version
X-Upstream-CT
Fastcgi-X-Cache-Version
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
X-GEO
X-Check-Cacheable
X-B3-SpanId
X-Worker
X-Zone
219prxHost
409pxxline
X-Vcache
189phosttRef
178proxuri
X-Nananana
188prxHost
Xxline
225prxHost
355prline
X-Server-W
X-Backend-TTL
352pxline
X-NGINX-Cache
286prxHost
X-Amz-Meta-Surrogate-Control
X-URL
X-Ratelimit-Reset
X-IPS-LoggedIn
X-UE-Client-Country
X-WA
X-HS-Status
Mobile-Detection-Method
Countrycode
GW-Server
X-We-Are-Hiring
X-Clientip
Pics-Label
Lb
Version
SS
X-Fastly-Country-Code
X-Hyper-Cache
X-CSRF-Token
X-ServedByHost
SN
Ohc-File-Size
DataCenter
Esi-Enabled
GeoIp-Country-Code
Geoip-Latitude
X-SERVER-NAME
X-UPSTREAM-Address
X-VCL-Version
X-Dynatrace
WP-Super-Cache
X-GZIP
X-SRV
FSS-Proxy
X-BE
X-Request-Start
URI
Geoip-City
X-PF-Uncompressing
X-AssetVersion
X-Contensis-Viewer-Groups
GeoIP-Latitude
GeoIP-Country-Code
GeoIP-City
X-HS-Combine-CSS
FSS-Cache
X-Render-Time
Serverid
X-Akamai-Request-ID2
X-Be
Accept-Language
X-LiteSpeed-Cache-Control
X-GDPR
X-CS
X-Via-Ucdn
X-Unique-Id
CDN
X-ZONE
X-Fpc
X-Vtex-Processado-Em
X-RequestId
X-NWS-UUID-VERIFY
X-PJAX-URL
X-Vtex-Remote-Cache
Ohc-Cache-HIT
X-Gen-Id
FastCGI-Cache
Amp-Access-Control-Allow-Source-Origin
Dynatrace
X-HostName
X-FORWARDED-FOR
X-Pf-Uncompressing
X-Html-Edge-Cache
Locale
X-UCC
Cneonction
X-Reqid
X-Urbn-Site-Id
RequestUuid
X-Via-NSCOPI
X-Fastly-Cache-Hits
X-Urbn-Context-Path
X-Cdn-Cache
X-Cache-Ttl
Accept-Ch
Server-Id
X-LiteSpeed-Tag
A
X-ABtesting
X-Varnish-Action
Who
X-Request-Url
X-Store
X-Flog
X-Hello
X-Akamai-SSL-Client-Sid
Dnion-Transfer-Encoding
X-Generation-Time
X-Dw-Trace-Id
IBM-Web2-Location
X-Cdn-Request-ID
X-Port
Get-Access-Time
Is-Session-Tracking
Frontcache
X-HTML-Edge-Cache
X-Serial
Ohc-Response-Time
X-ServerName
NnCoection
X-Cache-URL
X-EC-Lua