Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Request-ID
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Buckets
Upgrade
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
X-CDN
Keep-Alive
Access-Control-Expose-Headers
X-Backend
Access-Control-Max-Age
X-Cache-Group
X-Pass-Why
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Server
X-Pingback
X-Via
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
WPE-Backend
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
P3p
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
Server-Timing
Allow
X-Ac
X-Rq
X-Node
X-Host
X-Server-Id
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
X-CST
Report-To
X-Backend-Server
X-Cloud-Trace-Context
EagleEye-TraceId
Surrogate-Control
X-Application-Context
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Url
X-Origin-Cache
X-Readtime
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Type
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
NEL
X-Instart-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
Pinterest-Generated-By
X-DataDome
X-Mod-Pagespeed
X-Origin-Upstream-Status
Edge-Control
X-Px
X-Goog-Hash
X-HW
X-Server-Name
Verso
Accept-CH
X-Upstream-Env
X-Dispatcher
X-ESI
X-Cdn
MS-Author-Via
AR-PoweredBy
AR-ATIME
AR-CACHE
X-VARITI-CCR
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-ORACLE-DMS-RID
X-DataStream-Cache-Status
X-Cached
Public-Key-Pins
X-Powered-By-Plesk
X-Version
Content-MD5
X-Dns-Prefetch-Control
Charset
Service-Worker-Allowed
X-Recruiting
AR-Request-ID
RTSS
Accept-CH-Lifetime
Ar-Sid
X-Abt-Application-Version
X-D2id
X-TTL
X-Navigation-Version
X-Amz-Server-Side-Encryption
X-Vname
X-PC
X-TtlSet
X-Ser
X-Varnish-TTL
X-Vcap-Request-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-Proto
X-Client-IP
X-Trace
SPRequestGuid
Nginx-Cache
X-DynaTrace-JS-Agent
X-Server-ID
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Expires
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Oracle-Dms-Rid
X-Amz-Rid
X-Amz-Meta-S3cmd-Attrs
DynaTrace
S
X-VCache
X-SharePointHealthScore
X-Fastly-Request-ID
X-XRDS-Location
X-Debug
TCN
X-Hits
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Dw-Request-Base-Id
Arr-Disable-Session-Affinity
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Proxy
X-Shield-Request-Id
X-Akam-SW-Version
SPIisLatency
SPRequestDuration
Access-Control-Request-Method
X-Powered-CMS
X-T
X-FTR-Cache-Host
X-Goog-Storage-Class
X-Id
X-Ttl
Realpath
X-Aspnet-Version
X-Acc-Meta-Resource-Type
X-NF-Request-ID
Tracecode
X-MSEdge-Ref
Front-End-Https
X-Amzn-Trace-Id
X-Webkit-CSP
X-B3-TraceId
X-N
Fastcgi-Cache
X-Varnish-Age
X-Content-Type
X-Forwarded-For
Paypal-Debug-Id
X-Upstream
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
Alternate-Protocol
X-Frontend
X-PressLabs-Stats
X-Content-Digest
X-Logged-In
X-HS-Content-Id
X-HS-Hub-Id
X-RateLimit-Remaining
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-Litespeed-Cache
X-Middleton-Display
X-Sol
Response
X-Middleton-Response
Display
X-Cache-Key
X-Fastcgi-Cache
X-Hostname
X-Srv
X-B3-Traceid
X-Pad
AMP-Access-Control-Allow-Source-Origin
X-Accel-Expires
Host
X-SERVER
MicrosoftSharePointTeamServices
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
Server-Name
X-Kinsta-Cache
Backend-Timing
X-Analytics
X-Correlation-Id
X-AppVersion
X-LB-Cache
X-User-Agent
X-Content-Options
X-Revision
X-Az
X-Activity-Id
X-Debug-Info
X-B3-Sampled
X-Rid
X-IPLB-Instance
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Hit
Surrogate-Key
FilterID
X-Cache-2
X-Grace
ServerID
Accept-Charset
Refresh
Powered-By-ChinaCache
X-B
X-CF-Powered-By
X-Accel-Buffering
X-Page-Id
X-DIS-Request-ID
X-Request-Received
X-Request-Processing-Time
X-Whom
Server-Info
MS-CV
TP-L2-Cache
TP-Cache
X-FastCGI-Cache
Host-Header
X-PHP-Backend
X-Varnish-Backend
X-Ruxit-Js-Agent
Cache-Status
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-TT
X-Cache-Action
X-App-Environment
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Akamai-Edgescape
Source
X-Amz-Replication-Status
X-Cached-By
X-F-Cache
X-Cluster
X-Framework
X-Tumblr-Pixel
X-Mobile
X-UA-Device-Type
X-Tumblr-Pixel-0
X-Tumblr-User
X-Content-Powered-By
X-GUploader-UploadID
X-Varnish-Grace
X-Platform-Server
Access-Control-Allow-Method
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Drupal-Cache-Tags
X-Instance
X-Request-Guid
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FB-Debug
PageSpeed
X-Forwarded-Host
X-Geo-Country
Edge-Cache-Tag
X-Zen-Fury
X-Cache-TTL
X-RateLimit-Limit
X-Node-Name
X-SS-Set-Cookie
X-Shard
X-TA-CDN-Provider
X-Ezoic-Cdn
X-Handled-By
X-Magnolia-Registration
From-Origin
X-Varnish-Hostname
X-ATG-Version
X-Cache-Age
Cache-Tags
Fastly-Restarts
X-BCube-Filmed-By
X-Varnish-Server
X-Cache-Control
X-AOL-HN
X-App-Server
DC
Cleartype
Healthy
X-Cache-Rule
Upgrade-Insecure-Requests
Payment
Server-Node
X-Signature
X-Region
X-Response-Served-From
Filters
X-RequestSource
X-B-Cache
X-WebKit-CSP-Report-Only
Country
X-TX-ID
X-Redis-Cache
X-Storage
Webserver
X-VG-WebCache
X-GeoIP
X-RTag
Retry-After
X-Tumblr-Pixel-2
X-Adobe-Loc
X-TT-TIMESTAMP
Ms-Operation-Id
X-Adobe-Content
X-Tumblr-Pixel-1
X-Generated-By
X-FW-Dynamic
X-Jobs
X-UUID
Actual-Object-TTL
Cache-Tv-Group
X-Drupal-Cache-Contexts
X-XRDS-LOCATION
X-Content-Age
X-Locale
X-Varnish-Hits
Powered
X-Cacheable-TTL
NGB
CACHE
GEO-INFO
ServedBy
Frame-Options
X-Contextid
X-Oneagent-Js-Injection
X-WA-Info
Liferay-Portal
HitType
X-Rendered-As
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Real-IP
X-Seen-By
X-Cache-TTL-Remaining
X-Varnish-IP
X-ProcessESI
Eomportal-Instance
X-RemovedCookies
X-Cache-NE
X-Guploader-Uploadid
S-Cnection
X-BACKEND-TTL
X-Esi
Viewport
X-Via-JSL
X-Upgrade-Enabled
X-Cache-Operation
X-Mode
X-Varnish-Cache-Hits
X-Cache-Server
X-Is-Bot
Load-Balancing
Mn-Server-Ip
X-Detected-As
X-Device-Type
X-Cache-Enabled
Cache-Key
X-Zipkin-Id
OT-Force-Account-Verify
Cache-Hits
X-ES-SERVER
X-Routing-Service
X-Path-Route
X-Proto
X-Proxied
Meta-Geo
X-Cache-Var
X-From
X-Cache-Var-Map
X-Hl-Ver
X-RN-RSRV
Machine
X-S
X-Time
Content-Script-Type
Content-Style-Type
X-Akamai-Transformed
X-Tb
TWC-Device-Class
Property-Id
X-Proxy
X-FB-TRIP-ID
TWC-Connection-Speed
Access-Control-Request-Headers
X-FC-Vary-Parameters
NtCoent-Length
X-Hosted-By
L5d-Success-Class
X-Rocket-Nginx-Bypass
TWC-GeoIP-Country
Mail-Subject
NGX
X-VG-TLSProxy
X-Origin-Hint
Webcakes-Region
Webcakes-App-Name
X-LJ-Flow-ID
X-Cache-Config
X-Backend-Name
X-AWS-Id
We-Hiring
Webcakes-App-Version
TWC-Locale-Group
Vix-Hermes-Req-Id
TWC-Privacy
X-Viewer-Country
X-VWS-Id
TWC-GeoIP-LatLong
Azure-SlotName
X-Loop
Azure-SiteName
Azure-Version
Azure-InstanceId
Azure-RegionName
X-Labrador-Cache-Channel
X-EIG-Tracking-Id
S-Rt
X-Access
X-Debug-Cache
X-Akamai-Request-ID
X-MP-GENERATED-AT
X-Environment-Context
X-FW-Version
X-Format
Now
DB-Nickname
X-L-Path
X-Section
X-Web-Node
X-Vgn-Hpd-Reason
X-Tumblr-Pixel-3
X-NWS-LOG-UUID
X-TNCMS
Xserver
X-R9-Blue-Green-Version
Datacenter
X-Origin-Response-Time
X-RCS-CacheZone
X-NCache
X-Time-Microsecs
X-ServerID
Origin-Cache-Control
X-Timing-Wait
X-Via-CDN
X-Birta-Cache-Post
X-Birta-Served
X-CCM
X-Xfnlog-Site
X-Trace-Id
X-Via-Fastly
Selected-FE
Origin-Edge-Control
X-Proxy-Build
X-Human
X-PCL
X-IP
X-OCL
X-ProxyCache-Status
X-Internal-Host
Uber-Trace-Id
X-Endurance-Cache-Level
X-BYPASS-REASON
X-JoinUs
X-Www-Served-By
X-ProxyCache-Key
LB
X-Site-Version
X-Generated
Cache-Tag
X-Cache-Category-Id
X-Grey
X-Varnish-Cacheable
X-Cache-Remote
Decoy-Debug-Key
X-Dynatrace-Js-Agent
X-VC-Cache
X-Status
Decoy-Debug-Status
X-UA
Decoy-Debug-TTL
Served-By
X-GRACE
X-Rule
X-Newrelic-App-Data
X-UnsetCookies
X-EdgeConnect-Cache-Status
X-Wix-Server-Artifact-Id
Release
X-TIME
Nel
X-CDN-Cache
AsisCache
ViewerVersion
X-Cluster-Node
X-Wix-Request-Id
X-APP-VERSION
Rt-Fastcgi-Cache
X-B3-Spanid
X-Origin-Host
X-App-Name
X-Sucuri-ID
X-NewRelic-App-Data
X-PERF
X-Request-Time
X-ApacheServer
X-Source
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl-Cache
X-Nginx-Cache
X-OVcl
X-Hit
DSUID
X-VCT
X-Ua
X-Agile-Age
Cache-Name
Hostname
X-Agile-Id
X-Agile
SRV
X-App-Version
Warning
X-ElasticPress-Search
User-Agent
X-Origin-CC
X-Origin-TTL
X-A-Dcw
X-B-Cookie
X-A-Dam
X-Cache-ASPX
X-Cache-Expires
X-A
X-A-Ccd
X-A-Dgt
X-VG-WebServer
X-A-Wwc
X-Accel-Expires-Debug
X-Varnish-Authentication
X-Application
Www
X-ARC
X-Aed
Request-EU
Lfy
FNAC-ModuleRouting
MD5-Digest
Memcached
Meta-Geo-Continent
Fly-Request-Id
Fly-Cache
BehaviorPad-Version
Arc-Country
Cache-Prefix
Cross-Origin-Window-Policy
Ec-Rule-Version
Node
On-Server
Thinkindot-CacheControl
Server-Surrogate-Control
Thinkindot-CacheControl-Type
Xc-Version
X-Webstats-RespID
Server-Cache-Control
Request-Time
Origin
Rendered-Blocks
Request-Country
X-Var-Ttl
Thinkindot-Control
X-Transaction
X-Instart-Isnd
X-Logtrace-Id
X-IN-WAF
X-Date
X-IN-APIGATEWAY
X-Matched-Rule
X-Mobile-URL
X-NX-Host
X-PAYTM-SRV-ID
X-D
X-NU-AKA-ACS-Version
X-NodeID
X-Debug-Cache-Expiry
X-Hp-Webp
X-Debug-Cookies
X-DPWN-IS-SECURE
Ajk
X-Debug-Log
X-Destination
X-External-Request-Id
X-F5-Cache
X-Generated-In
X-Debug-Cache-Fetch
X-Gannett-Site-Version
X-G
X-Debug-Cache-Store
X-Platform
X-Processor
X-ServiceProvider
X-SRCache-Key
X-Server-Group
X-Sedo-Request-Id
X-Secret
X-Thinkindot-L3
X-Developer
X-Trv-Group
X-Twitter-Response-Tags
X-Cache-Grace
X-Cache-Info
X-Cache-Miss-From
X-ScT
X-S-Cookie
X-CF-Lambda-Version
X-Reboot
X-Connection-Hash
X-Core-Value
X-Pubstack
X-Refresh
X-Region-Sid
X-CF-Lambda-Fn
X-Rojux
X-Rewrite-Enabled
X-Request-UUID
X-Up
UCS
X-Varnish-Ttl
X-Cache-Backend
User-Cache-Control
Pramga
X-Hnp-Log
X-Qloud-Router
X-Hash
X-Block-Status
X-RateLimit-Limit-Second
X-SIPLIST1
X-SN
Proxy-Connection
Cteonnt-Length
X-Origin-Expires
X-Eu-Site
X-Ocache
X-Cache-Id
X-Ah-Environment
X-Cache-Debug
RNT-Machine
X-Swa-Ws
X-Cache-Bucket
Pagetype
X-PHP-Host
X-Amzn-Remapped-Date
X-Rebelmouse-Cache-Control
Web-Mar-Node
X-RateLimit-Remaining-Second
X-Amzn-Remapped-Content-Length
X-Amzn-Remapped-Connection
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Origin-Date
X-Edge-Location
Cache
Server-Int
Kp-EeAlive
X-BB-ID
ServerName
X-Sf
True-Client-Country-4JS
X-Gen-Mode
X-Servername
RNT-Time
X-Nginx-Cache-Key
IsBot
X-Dispatcher-Server
X-Crawler
X-Location
Fastly-SIE
Fastly-SWR
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Backend
Cache-Cookie-Set-Idcheck
X-Developers
CDCHOST
Cache-Cookie-Set-From
X-Device-Os
Server-Host
Country-Code
Cache-Cookie-Set-Lfrom
Apple-News-Services-Handled
X-Micro-Cache
X-Proxy-Cache-Status
X-LAGOON
X-Cdn-Srv
X-Proxy-Upstream
X-Page-Type
X-Distil-CS
Ha-Gx-Prefs
HA-Ipaddr
X-Info
X-Irp-Debug
X-Key
X-CGP
X-Protected-By
X-Policy
X-Datadome
X-WPE-Loopback-Upstream-Addr
Pagespeed
X-Epic-Correlation-Id
X-Planisys-CDN-Cache
X-Alternate-Cache-Key
X-BBXSRF
X-Cms-Context
X-Bip
X-C
X-Distributor
X-Cache-Host
X-Core-Mission
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Backend-Host
X-Backend-State
X-Backend-Url
X-Auto-Login
X-GeoIP-City
X-Via-Edge
Heartbleed
X-Via-SSL
X-Sucuri-Cache
X-Wikidot-Backend
HTTPS
Is-Eu
X-User
X-MSEdge-Flight
X-Variation
X-MSEdge-Features
Fastly-SSL
Fastly-Soc-X-Request-Id
X-Level-Front-Cache
X-Li-Pop
AKAMAI
X-LI-Proto
X-Generated-On
X-Fetched-On
X-Wikidot-Static-Cache
X-Li-Fabric
Gh-Request-Id
Content-Disposition
X-TT-LOGID
X-TrackingId
X-LI-UUID
X-ShardId
X-Server-IP
X-S-Maxage
X-Fastly-Cache
Adler-Geo
X-ShopId
X-Geo-Header
X-Thanos
X-No-Session
X-Sorting-Hat-ShopId
Platform
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Skip-Cache
X-FireWall-Port
X-Edge-IP
X-GZip
X-Apm-Inst-Hash
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-GeoIP-Country-Code
X-Gateway-Cache-Key
X-Sn-Servicetimems
X-RateLimit-Reset
Magicmarker
N-Cache
SD-X-WS
X-Varnish-Beresp-Status
X-NC
X-Varnish-Url
X-Apm-App-Name
X-Cdn-Forward
Fastly-Backend-Name
X-Apm-Svc-Key
X-Varnish-Beresp-Grace
X-Cdn-Origin
X-Server-Time
X-Amz-Meta-Cache-Control
X-Cache-FS-Status
X-Real-Ip
MIME-Version
X-Geo
Rt-Proxy-Cache
X-Exp-Se
X-Owner
X-ND-Cache
REQUESTUUID
V-Age
X-CDN-Forward
X-Served-From
Server-ID
X-FPC
X-Org
X-Node-Id
X-B3-Parentspanid
X-Pjax-Url
X-Aicache-OS
VivaBuild
Viewtype
X-Gdpr
X-Dc
X-CUA
Powered-By
X-Load-Cache
X-Varnish-Beresp-Ttl
Wxu-Next-Hostname
X-Parent-Response-Time
Wxu-Next-Commit
HostName
X-Git-Hash
X-CSRF-TOKEN
Wxu-Next-Region
Pragrma
Section-Io-Cache
CF-IPCountry
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Passed-To
PICS-Label
Time
X-Returned-From-PostProcessResponse
X-Returned-From
X-Actual-URL
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Original-Request
X-Server-By
X-Stale
X-Svr
Memory
X-Nc
X-DC
X-Host-Name
X-Servedbyhost
X-CACHE-KEY
X-VServer
Host-ID
X-HS-Cache-Config
X-Croise-Owner
Resin-Trace
X-Wa
Cdn-Request-Time
Cdn-Host
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Release
X-Oss-Storage-Class
X-Edge-Server
X-TH-Server
X-Tb-Optimization-Total-Bytes-Saved
X-WebServer
Mime-Version
X-Varnish-Beresp-TTL
X-Optimization
X-Cache-HT
AR-SID
X-Daa-Tunnel
X-Unique-ID
X-Microcachable
X-From-Cache
ProcessTime
SID
X-Phone
X-Lb-Id
Fastcgi-Useragent
X-Newrelic-Synthetics
X-Upstream-CT
X-Upstream-HT
X-Instart-Info
XServer
Cf-Ipcountry
X-APP
Backend-Name
Cdn
X-Req
X-Atg-Version
X-V
CF-Cached-On
Proxy-Firewall
X-Fastly-Backend-Reqs
Processtime
X-Worker
Odigeo-Trace-Id
X-HTML-Minification-Powered-By
X-Server-W
X-ID
X-Ratelimit-Remaining
X-B3-SpanId
189phosttRef
219prxHost
225prxHost
178proxuri
286prxHost
Version
188prxHost
X-Zone
X-LB-ID
X-Vcl-Version
355prline
X-Backend-TTL
X-WR-MODIFICATION
Xxline
X-Ratelimit-Limit
352pxline
X-Fstrz
409pxxline
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
X-NGINX-Cache
X-Response-By
X-Check-Cacheable
X-IPS-LoggedIn
X-Nananana
X-Vcache
Esi-Enabled
X-Akamai-Request-ID2
GMS-Ver
X-VCL-Version
X-UPSTREAM-Address
Accept-Language
Public-Key-Pins-Report-Only
SN
X-WA
X-URL
X-Microsite
X-AssetVersion
X-Request-Handler-Origin-Region
X-Contensis-Viewer-Groups
X-Ratelimit-Reset
GeoIp-Country-Code
X-ServedByHost
Geoip-Latitude
X-CSRF-Token
X-Hyper-Cache
WZWS-RAY
Pics-Label
GeoIP-Latitude
GeoIP-Country-Code
GeoIP-City
X-HS-Status
Fastcgi-X-Cache-Version
DataCenter
X-Vtex-Processado-Em
X-Fastly-Country-Code
X-Vtex-Remote-Cache
X-Be
Geoip-City
GW-Server
X-Amz-Meta-Surrogate-Control
X-SERVER-NAME
X-ZONE
X-Dynatrace
X-Via-NSCOPI
Mobile-Detection-Method
X-Clientip
X-Request-Start
X-Urbn-Site-Id
X-Reqid
X-Urbn-Context-Path
X-Via-Ucdn
X-UE-Client-Country
X-We-Are-Hiring
Locale
Countrycode
X-RequestId
X-Render-Time
X-GEO
Lb
WP-Super-Cache
X-Cdn-Cache
X-CS
X-GDPR
X-LiteSpeed-Cache-Control
URI
X-BE
X-NWS-UUID-VERIFY
X-ABtesting
X-Flog
X-Hello
SS
CDN
X-Unique-Id
Ohc-File-Size
IBM-Web2-Location
Dnion-Transfer-Encoding
X-PJAX-URL
X-SRV
X-GZIP
X-HostName
X-FORWARDED-FOR
FastCGI-Cache
Dynatrace
Amp-Access-Control-Allow-Source-Origin
Serverid
X-HS-Combine-CSS
FSS-Proxy
X-PF-Uncompressing
X-Fpc
RequestUuid
FSS-Cache
Server-Id
X-Test
Cneonction
X-Gen-Id
X-Pf-Uncompressing
X-Generation-Time
X-Cache-Ttl
X-Bug-Bounty
X-Cluster-Name
X-Fastly-Cache-Hits
X-Html-Edge-Cache
Requestid
X-LiteSpeed-Tag
X-Store
A
Accept-Ch
X-Request-Url
X-Akamai-SSL-Client-Sid
X-NGENIX-Cache
X-Cdn-Request-ID
X-Serial
RequestId
X-Requestid
X-Cache-URL
X-Compress-Hint
Frontcache
Ohc-Response-Time
NnCoection
X-ServerName
X-EC-Lua
Is-Session-Tracking
Get-Access-Time
X-HTML-Edge-Cache
Ohc-Cache-HIT
X-Dw-Trace-Id