Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
CF-Ray
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Hacker
X-Robots-Tag
X-Nginx-Cache-Status
X-Varnish-Cache
X-Server-Powered-By
WPE-Backend
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-CST
X-Host
Content-Location
Feature-Policy
X-Server-Id
X-Cnection
X-Response-Time
X-Type
Report-To
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Origin-Cache
X-Readtime
Request-Id
X-Rack-Cache
X-FTR-Request-ID
X-Country
X-Clacks-Overhead
X-Country-Code
X-Cache-Lookup
Rating
NEL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Instart-Request-ID
X-Vhost
X-Ruxit-JS-Agent
X-Dns-Prefetch-Control
X-DynaTrace
Pinterest-Generated-By
X-Mod-Pagespeed
X-Upstream-Env
X-Origin-Upstream-Status
X-DataDome
X-Px
Edge-Control
X-Goog-Hash
Verso
X-Server-Name
Accept-CH
X-Dispatcher
X-HW
X-ORACLE-DMS-RID
X-ESI
MS-Author-Via
X-DataStream-Cache-Status
X-VARITI-CCR
X-GitHub-Request-Id
X-Mobile-Rewrite
Arc-Version
PB-RID
PB-PID
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-MS-InvokeApp
X-Kinja-Server
X-Exp-Variant
X-Kinja-Revision
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Cached
X-Version
Charset
Content-MD5
X-Powered-By-Plesk
Public-Key-Pins
X-Recruiting
Service-Worker-Allowed
Accept-CH-Lifetime
AR-Request-ID
RTSS
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-TTL
X-PC
X-TtlSet
X-Vname
X-Server-ID
X-SRCache-Fetch-Status
Ar-Sid
X-Ser
X-SRCache-Store-Status
X-Varnish-TTL
X-Trace
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-FTR-Balancer
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-FTR-Expires
X-VCache
X-Amz-Rid
S
X-Fastly-Request-ID
X-SharePointHealthScore
X-Amz-Meta-S3cmd-Attrs
X-Debug
X-XRDS-Location
TCN
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-Dw-Request-Base-Id
X-Hits
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
DynaTrace
X-Upstream-Proxy
Pinterest-Version
X-Oracle-Dms-Rid
X-Pinterest-Rid
SPIisLatency
SPRequestDuration
X-Akam-SW-Version
Access-Control-Request-Method
X-T
X-SERVER
X-FTR-Cache-Host
X-Goog-Storage-Class
X-Powered-CMS
X-Id
Front-End-Https
X-Ttl
X-B3-TraceId
X-Aspnet-Version
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Fastcgi-Cache
X-Amzn-Trace-Id
X-MSEdge-Ref
Realpath
Tracecode
X-N
X-Varnish-Age
Paypal-Debug-Id
X-Content-Type
X-Forwarded-For
X-Upstream
Alternate-Protocol
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-RateLimit-Remaining
X-Middleton-Display
X-Sol
Display
X-Logged-In
X-Frontend
X-PressLabs-Stats
Fusion-Component-Id
X-HS-Content-Id
X-Content-Digest
X-HS-Hub-Id
Response
Fusion-Content-Id
X-Middleton-Response
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
X-Litespeed-Cache
AMP-Access-Control-Allow-Source-Origin
X-Hostname
X-Cache-Key
X-Accel-Expires
X-Pad
X-Fastcgi-Cache
X-Accel-Buffering
X-Kinsta-Cache
X-Srv
Server-Name
Host
MicrosoftSharePointTeamServices
X-B3-Traceid
Backend-Timing
X-Analytics
X-User-Agent
X-Cdn
X-Content-Options
X-Correlation-Id
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Debug-Info
X-LB-Cache
X-Rid
Refresh
X-Amzn-RequestId
X-Revision
X-Amz-Apigw-Id
X-Az
X-AppVersion
Accept-Charset
X-Activity-Id
FilterID
X-IPLB-Instance
X-Cache-Hit
X-B
X-B3-Sampled
X-Cache-2
X-Grace
X-DIS-Request-ID
Surrogate-Key
Powered-By-ChinaCache
X-CF-Powered-By
X-FastCGI-Cache
ServerID
X-Page-Id
X-Whom
Server-Info
TP-Cache
TP-L2-Cache
X-PHP-Backend
X-Webkit-CSP
X-Request-Processing-Time
X-Request-Received
Host-Header
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
MS-CV
X-Cached-By
X-Amz-Replication-Status
VIX-Pulpo-Node
X-TT
X-Kong-Upstream-Latency
VIX-Pulpo-Upstream-Status
X-Kong-Proxy-Latency
X-App-Environment
X-Cache-Action
Cache-Status
X-Varnish-Backend
X-Akamai-Edgescape
X-Cluster
X-Framework
X-Origin-Server
Source
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-GUploader-UploadID
X-Content-Powered-By
Access-Control-Allow-Method
X-Mobile
X-Tumblr-User
X-Platform-Server
X-FW-Static
X-FW-Type
X-Request-Guid
X-FW-Serve
X-FW-Server
X-F-Cache
X-FW-Hash
X-Ezoic-Cdn
X-UA-Device-Type
X-Instance
X-Varnish-Grace
X-RateLimit-Limit
X-Shard
X-Drupal-Cache-Tags
X-FB-Debug
X-SS-Set-Cookie
X-Geo-Country
X-Handled-By
X-Zen-Fury
X-Forwarded-Host
X-Magnolia-Registration
Edge-Cache-Tag
PageSpeed
From-Origin
X-Cache-TTL
X-Node-Name
X-ATG-Version
X-Cache-Age
X-Varnish-Hostname
X-App-Server
CACHE
DC
X-Varnish-Server
Cleartype
Cache-Tags
X-BCube-Filmed-By
X-AOL-HN
X-Cache-Control
Payment
X-Region
X-WebKit-CSP-Report-Only
Filters
X-Response-Served-From
X-RequestSource
Upgrade-Insecure-Requests
X-Adobe-Loc
X-TX-ID
X-Generated-By
X-Adobe-Content
Healthy
X-VG-WebCache
X-GeoIP
Cache-Tv-Group
Webserver
NGB
X-Redis-Cache
X-TT-TIMESTAMP
X-UUID
Server-Node
X-Storage
X-Tumblr-Pixel-1
Ms-Operation-Id
Country
Actual-Object-TTL
Fastly-Restarts
X-RTag
X-Signature
X-Jobs
X-Tumblr-Pixel-2
X-B-Cache
X-FW-Dynamic
Retry-After
X-Cache-Rule
X-Content-Age
X-Cacheable-TTL
X-Locale
X-Drupal-Cache-Contexts
X-XRDS-LOCATION
X-Varnish-Hits
GEO-INFO
ServedBy
Liferay-Portal
X-Wix-Server-Artifact-Id
X-Esi
X-Seen-By
X-TA-CDN-Provider
X-Contextid
Powered
Frame-Options
X-Oneagent-Js-Injection
X-Rendered-As
HitType
X-Via-JSL
X-Cache-TTL-Remaining
X-Varnish-IP
X-BACKEND-TTL
X-Yottaa-Optimizations
X-WA-Info
X-Yottaa-Metrics
S-Cnection
Viewport
X-Real-IP
X-Guploader-Uploadid
X-RemovedCookies
X-Cache-Server
X-ProcessESI
X-Upgrade-Enabled
Eomportal-Instance
Content-Script-Type
Content-Style-Type
X-Cache-NE
X-Mode
NtCoent-Length
Datacenter
X-Cache-Config
X-Akamai-Transformed
X-Proxied
X-Zipkin-Id
X-Detected-As
X-Routing-Service
X-Is-Bot
X-Proto
Cache-Key
Cache-Hits
X-Path-Route
X-S
X-RN-RSRV
Machine
Meta-Geo
X-ES-SERVER
X-Cache-Var
X-Hl-Ver
Load-Balancing
X-From
X-Cache-Var-Map
Mn-Server-Ip
Property-Id
L5d-Success-Class
X-Endurance-Cache-Level
Webcakes-Region
TWC-GeoIP-Country
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Locale-Group
Vix-Hermes-Req-Id
TWC-Device-Class
Access-Control-Request-Headers
Webcakes-App-Version
Webcakes-App-Name
X-Device-Type
X-Access
X-Varnish-Cache-Hits
TWC-Connection-Speed
X-Environment-Context
X-Cache-Enabled
X-VG-TLSProxy
X-Viewer-Country
X-Hosted-By
X-Tb
X-L-Path
X-Section
X-Origin-Hint
X-FC-Vary-Parameters
X-Web-Node
Azure-InstanceId
X-Via-CDN
X-Wix-Request-Id
Azure-RegionName
X-TNCMS
X-FB-TRIP-ID
X-Cache-Operation
Azure-SlotName
Mail-Subject
X-Loop
X-Labrador-Cache-Channel
OT-Force-Account-Verify
Origin-Edge-Control
NGX
ViewerVersion
X-Time-Microsecs
Azure-Version
DB-Nickname
S-Rt
Azure-SiteName
We-Hiring
X-FW-Version
X-Birta-Served
X-Birta-Cache-Post
Origin-Cache-Control
X-ServerID
X-EIG-Tracking-Id
Xserver
X-Format
X-Backend-Name
X-Proxy
X-Akamai-Request-ID
X-Origin-Response-Time
X-Time
X-CCM
X-JoinUs
X-Timing-Wait
X-Xfnlog-Site
X-Debug-Cache
X-Trace-Id
X-PCL
X-Varnish-Cacheable
X-ProxyCache-Key
Selected-FE
X-Status
X-IP
X-Human
X-Via-Fastly
X-BYPASS-REASON
X-ProxyCache-Status
X-Tumblr-Pixel-3
X-NCache
X-OCL
X-Proxy-Build
Decoy-Debug-Status
X-GRACE
Cache-Tag
Decoy-Debug-Key
Decoy-Debug-TTL
Now
X-Grey
X-Generated
X-Cache-Category-Id
X-LJ-Flow-ID
X-Site-Version
X-Rocket-Nginx-Bypass
X-Www-Served-By
X-VWS-Id
X-AWS-Id
X-MP-GENERATED-AT
X-Vgn-Hpd-Reason
Uber-Trace-Id
X-VC-Cache
Served-By
X-RCS-CacheZone
X-Newrelic-App-Data
X-Dynatrace-Js-Agent
X-NWS-LOG-UUID
X-UA
X-Internal-Host
X-R9-Blue-Green-Version
X-EdgeConnect-Cache-Status
X-CDN-Cache
X-Rule
X-Cache-Remote
X-Origin-Host
X-NewRelic-App-Data
LB
X-Sucuri-ID
AsisCache
X-UnsetCookies
X-TIME
X-Cluster-Node
Rt-Fastcgi-Cache
Nel
Release
User-Agent
X-App-Name
X-APP-VERSION
X-ApacheServer
X-PERF
X-B3-Spanid
X-Datadome
X-Nginx-Cache
X-Agile-Age
Pagespeed
X-Agile
X-Agile-Id
X-Source
X-Request-Time
Cache-Name
X-Ua
X-Ocache
Hostname
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Origin
X-Hit
X-OVcl-Cache
Warning
X-Sucuri-Cache
X-Pubstack
X-App-Version
X-Edge-Location
X-Origin-CC
X-OVcl
X-Origin-TTL
X-ElasticPress-Search
X-Debug-Cache-Store
X-NX-Host
X-Debug-Cache-Fetch
X-Logtrace-Id
X-Debug-Cookies
X-NodeID
X-NU-AKA-ACS-Version
X-Matched-Rule
X-Application
X-Mobile-URL
Fly-Cache
X-Generated-In
Cross-Origin-Window-Policy
Ec-Rule-Version
X-Hp-Webp
X-Developers
X-Gannett-Site-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-External-Request-Id
X-G
X-Cache-Grace
X-Aed
X-BB-ID
X-B-Cookie
Ajk
X-ARC
X-Destination
X-Developer
X-Cache-Expires
X-DPWN-IS-SECURE
Fly-Request-Id
X-Debug-Log
Xc-Version
Rendered-Blocks
Thinkindot-CacheControl-Type
Request-Country
Request-EU
Request-Time
Thinkindot-Control
X-Server-Group
X-ScT
X-Secret
UCS
X-Date
BehaviorPad-Version
X-SRCache-Key
X-Twitter-Response-Tags
X-Connection-Hash
X-Up
X-Var-Ttl
X-Core-Value
X-D
X-Trv-Group
Thinkindot-CacheControl
X-Thinkindot-L3
X-Transaction
X-VG-WebServer
X-Accel-Expires-Debug
X-S-Cookie
Meta-Geo-Continent
X-Platform
X-Processor
X-A-Dam
N-Cache
MD5-Digest
Cache-Prefix
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-PAYTM-SRV-ID
Node
X-A-Ccd
X-Protected-By
Arc-Country
X-Request-UUID
X-Rewrite-Enabled
X-Region-Sid
X-Debug-Cache-Expiry
X-A
On-Server
Origin
X-Rojux
Www
X-VCT
X-Varnish-Ttl
X-Varnish-Beresp-Grace
X-Edge-IP
X-Cache-Backend
X-Varnish-Beresp-Status
True-Client-Country-4JS
User-Cache-Control
Web-Mar-Node
X-CGP
SRV
Server-Int
Server-Surrogate-Control
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-C
X-Cache-ASPX
X-Cache-Debug
X-Block-Status
X-Cache-Id
X-Cms-Context
X-Webstats-RespID
X-Cache-Host
X-LI-UUID
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Refresh
X-RateLimit-Limit-Second
X-Qloud-Router
X-PHP-Host
X-Page-Type
X-Policy
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Request-URI
X-Via-SSL
X-Swa-Ws
X-SN
X-TT-LOGID
X-Varnish-Url
X-Varnish-Authentication
X-SIPLIST1
X-Sf
X-Sedo-Request-Id
X-Servername
X-Via-Edge
X-ServiceProvider
Memcached
X-Origin-Expires
X-IN-APIGATEWAY
X-Hnp-Log
X-IN-WAF
X-Info
X-Instart-Isnd
X-Geo-Header
X-Gen-Mode
X-Distil-CS
X-Device-Os
X-Distributor
X-Epic-Correlation-Id
X-Eu-Site
X-Irp-Debug
X-Key
X-Nginx-Cache-Key
Server-Cache-Control
X-No-Session
X-Origin-Date
X-Cache-Info
X-Location
X-F5-Cache
X-LAGOON
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Crawler
X-Cache-Miss-From
Fastly-SIE
Fastly-Backend-Name
Country-Code
X-Real-Ip
Fastly-Soc-X-Request-Id
Fastly-SWR
IsBot
Heartbleed
HA-Ipaddr
Ha-Gx-Prefs
Content-Disposition
X-WPE-Loopback-Upstream-Addr
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
X-Ah-Environment
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDCHOST
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Backend
Magicmarker
Cache-Cookie-Set-Idcheck
Proxy-Connection
RNT-Machine
Pramga
RNT-Time
X-Cdn-Forward
X-FireWall-Port
X-Core-Mission
X-Wikidot-Static-Cache
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
SD-X-WS
X-Fetched-On
Adler-Geo
X-Generated-On
X-S-Maxage
X-Dispatcher-Server
X-Variation
Lfy
X-Micro-Cache
Server-Host
X-Level-Front-Cache
X-MSEdge-Features
X-MSEdge-Flight
X-Node-Id
X-Fastly-Cache
X-Cache-Bucket
X-Planisys-CDN-Cache
X-GeoIP-Country-Code
X-GeoIP-City
X-Hash
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-User
X-Server-IP
X-Wikidot-Backend
X-Backend-State
X-Backend-Host
X-Thanos
X-Backend-Url
X-BBXSRF
X-ShopId
X-Shopify-Stage
X-Bip
Pagetype
X-Amzn-Remapped-Content-Length
HTTPS
Is-Eu
Kp-EeAlive
X-Alternate-Cache-Key
X-Amz-Meta-Cache-Control
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-TrackingId
X-Skip-Cache
X-Cache-FS-Status
Platform
X-ShardId
Fastly-SSL
X-GZip
X-Owner
X-Auto-Login
Cteonnt-Length
X-RateLimit-Reset
X-Server-Time
ServerName
FNAC-ModuleRouting
X-Cdn-Srv
X-CACHE-KEY
DSUID
Section-Io-Cache
X-Varnish-Beresp-Ttl
Powered-By
X-CUA
Server-ID
X-CDN-Forward
Gh-Request-Id
Pragrma
MIME-Version
X-Org
X-NC
X-Passed-To-BeforeDispatch
X-Parent-Response-Time
X-Returned-From-PostProcessResponse
X-Passed-To
X-Passed-To-DLL
X-Sn-Servicetimems
X-Actual-URL
X-Server-By
X-Original-Request
X-Passed-To-PostProcessResponse
X-Svr
X-Cdn-Origin
X-Aicache-OS
X-Returned-From-BeforeDispatch
X-Stale
V-Age
X-Apm-Inst-Hash
REQUESTUUID
X-Apm-App-Name
X-Nc
Fastcgi-Useragent
X-FPC
X-Load-Cache
X-Returned-From-DLL
X-Returned-From
X-Apm-Svc-Key
VivaBuild
Viewtype
X-VServer
X-Pjax-Url
AR-SID
X-HS-Cache-Config
X-Geo
X-ND-Cache
X-Croise-Owner
Rt-Proxy-Cache
X-Exp-Se
Host-ID
X-Dc
Cdn-Request-Time
X-CSRF-TOKEN
X-Served-From
Cdn-Host
X-Ua-Device
X-Edge-Server
HostName
X-Gdpr
X-Unique-ID
Cache
PICS-Label
X-Microcachable
X-B3-Parentspanid
X-DC
X-Oss-Storage-Class
Time
X-Servedbyhost
Memory
X-Wa
X-Oss-Request-Id
X-Oss-Object-Type
SID
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Git-Hash
Resin-Trace
Wxu-Next-Commit
Mime-Version
Wxu-Next-Region
Wxu-Next-Hostname
ProcessTime
X-Newrelic-Synthetics
X-V
X-Req
X-Tb-Optimization-Total-Bytes-Saved
X-From-Cache
CF-IPCountry
X-Optimization
X-Cache-HT
Odigeo-Trace-Id
Cf-Ipcountry
X-HTML-Minification-Powered-By
X-Lb-Id
X-Release
XServer
X-Varnish-Beresp-TTL
X-WebServer
Cdn
X-Fstrz
X-Host-Name
X-Atg-Version
X-Phone
X-Response-By
X-TH-Server
Proxy-Firewall
X-ID
CF-Cached-On
Public-Key-Pins-Report-Only
X-Instart-Info
GMS-Ver
X-APP
X-LB-ID
Processtime
X-WR-MODIFICATION
X-Daa-Tunnel
X-Ratelimit-Remaining
Backend-Name
X-Upstream-CT
X-Ratelimit-Limit
X-Fastly-Backend-Reqs
WZWS-RAY
X-Vcl-Version
X-Upstream-HT
Fastcgi-X-Cache-Version
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
X-GEO
X-Nananana
X-Worker
X-Check-Cacheable
X-Zone
225prxHost
X-Vcache
286prxHost
352pxline
188prxHost
X-Amz-Meta-Surrogate-Control
178proxuri
X-NGINX-Cache
355prline
189phosttRef
219prxHost
X-Server-W
409pxxline
Xxline
X-COUNTRY
X-B3-SpanId
Countrycode
X-UE-Client-Country
X-WA
Mobile-Detection-Method
X-Ratelimit-Reset
X-We-Are-Hiring
X-HS-Status
X-Clientip
GW-Server
X-SRV
X-IPS-LoggedIn
X-URL
Lb
SS
X-CSRF-Token
Pics-Label
X-Backend-TTL
SN
X-Fastly-Country-Code
X-Hyper-Cache
X-ServedByHost
DataCenter
Version
Ohc-File-Size
X-VCL-Version
Geoip-Latitude
X-FORWARDED-FOR
X-SERVER-NAME
GeoIp-Country-Code
Esi-Enabled
X-GZIP
X-Dynatrace
FSS-Cache
FSS-Proxy
X-UPSTREAM-Address
URI
X-Request-Start
Geoip-City
X-AssetVersion
X-Render-Time
X-PF-Uncompressing
X-HS-Combine-CSS
X-BE
Serverid
X-Akamai-Request-ID2
X-GDPR
X-Contensis-Viewer-Groups
GeoIP-City
WP-Super-Cache
GeoIP-Country-Code
X-Via-Ucdn
X-CS
X-PJAX-URL
X-LiteSpeed-Cache-Control
GeoIP-Latitude
CDN
X-Unique-Id
X-Cache-Ttl
Accept-Language
X-NWS-UUID-VERIFY
X-Fpc
X-ZONE
X-Be
X-Cdn-Cache
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Gen-Id
Ohc-Cache-HIT
X-HostName
Amp-Access-Control-Allow-Source-Origin
Dynatrace
X-UCC
X-Pf-Uncompressing
X-RequestId
Cneonction
X-Fastly-Cache-Hits
X-Via-NSCOPI
RequestUuid
Locale
X-Hello
X-Reqid
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Html-Edge-Cache
X-Flog
X-ABtesting
X-Varnish-Action
X-LiteSpeed-Tag
A
Server-Id
Who
X-Request-Url
Accept-Ch
X-Store
X-Akamai-SSL-Client-Sid
X-Cache-URL
Is-Session-Tracking
Get-Access-Time
X-Port
IBM-Web2-Location
X-Cdn-Request-ID
X-EC-Lua
X-ServerName
X-HTML-Edge-Cache
NnCoection
Frontcache
X-Serial
Ohc-Response-Time