Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
X-Request-ID
CF-Ray
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Buckets
Upgrade
Xkey
X-CDN
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Cache-Group
Access-Control-Max-Age
X-Pass-Why
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
X-Amz-Request-Id
Grace
X-Amz-Id-2
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
WPE-Backend
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Server-Timing
Allow
X-Ac
X-Rq
X-Node
X-Host
X-Server-Id
Content-Location
Feature-Policy
X-CST
X-Cnection
X-Response-Time
Report-To
X-Backend-Server
X-Cloud-Trace-Context
EagleEye-TraceId
Surrogate-Control
X-Application-Context
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Type
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
NEL
X-EdgeConnect-Origin-MEX-Latency
X-Instart-Request-ID
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
Pinterest-Generated-By
X-Mod-Pagespeed
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Px
X-Goog-Hash
X-Upstream-Env
X-Server-Name
Verso
X-HW
Accept-CH
X-Dispatcher
X-ORACLE-DMS-RID
MS-Author-Via
X-ESI
AR-ATIME
AR-CACHE
AR-PoweredBy
Arc-Version
X-Mobile-Rewrite
X-VARITI-CCR
PB-RID
PB-PID
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Server
X-Exp-Id
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-DataStream-Cache-Status
X-Cached
X-Version
Content-MD5
X-Powered-By-Plesk
Public-Key-Pins
Charset
X-TTL
X-Recruiting
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
X-Abt-Application-Version
X-Navigation-Version
X-D2id
X-TtlSet
X-Vname
X-PC
X-Ser
Ar-Sid
X-Amz-Server-Side-Encryption
X-Varnish-TTL
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Vcap-Request-Id
X-Forwarded-Proto
X-Trace
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-Server-ID
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
X-FTR-Cache-Status
X-Cdn
X-FTR-Expires
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
S
X-Amz-Rid
X-SharePointHealthScore
X-VCache
X-Fastly-Request-ID
DynaTrace
X-XRDS-Location
X-Debug
TCN
X-Hits
Arr-Disable-Session-Affinity
X-TEC-API-ORIGIN
X-Dw-Request-Base-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Shield-Request-Id
X-Akam-SW-Version
X-Upstream-Proxy
SPRequestDuration
Pinterest-Version
X-Pinterest-Rid
SPIisLatency
X-Oracle-Dms-Rid
Access-Control-Request-Method
X-Powered-CMS
X-T
X-FTR-Cache-Host
X-SERVER
X-Goog-Storage-Class
X-B3-TraceId
X-Id
X-Aspnet-Version
X-Acc-Meta-Resource-Type
Realpath
X-NF-Request-ID
Front-End-Https
Tracecode
X-MSEdge-Ref
X-Amzn-Trace-Id
Fastcgi-Cache
X-Content-Type
X-Dns-Prefetch-Control
X-Varnish-Age
X-N
Paypal-Debug-Id
X-Ttl
X-Upstream
X-Forwarded-For
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
MRF-Tech
Alternate-Protocol
X-Mrf-Item-Lastmod
X-RateLimit-Remaining
X-Frontend
X-Logged-In
X-HS-Content-Id
X-PressLabs-Stats
X-Content-Digest
X-HS-Hub-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
X-Cache-Key
X-Litespeed-Cache
X-Sol
X-Middleton-Display
Display
X-Hostname
X-Middleton-Response
Response
X-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-Srv
X-Accel-Expires
X-Webkit-CSP
X-Pad
Host
MicrosoftSharePointTeamServices
Server-Name
X-B3-Traceid
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Kinsta-Cache
Backend-Timing
X-Correlation-Id
X-Analytics
X-Content-Options
X-LB-Cache
X-Debug-Info
X-Revision
X-User-Agent
X-Rid
X-IPLB-Instance
X-Cache-2
X-Cache-Hit
X-Amzn-RequestId
X-AppVersion
X-Az
X-Activity-Id
X-Amz-Apigw-Id
X-B3-Sampled
FilterID
Accept-Charset
Surrogate-Key
X-Grace
Refresh
ServerID
X-Accel-Buffering
X-B
Powered-By-ChinaCache
X-CF-Powered-By
X-DIS-Request-ID
X-Page-Id
X-Whom
Server-Info
X-Request-Processing-Time
X-Request-Received
TP-L2-Cache
TP-Cache
X-FastCGI-Cache
MS-CV
Host-Header
X-PHP-Backend
X-Varnish-Backend
Cache-Status
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
X-Cached-By
X-TT
X-App-Environment
X-Akamai-Edgescape
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Action
Source
X-Amz-Replication-Status
X-Origin-Server
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-F-Cache
X-UA-Device-Type
X-Tumblr-User
X-Tumblr-Pixel-0
X-Platform-Server
X-Tumblr-Pixel
X-Cluster
X-Framework
X-Mobile
X-GUploader-UploadID
Access-Control-Allow-Method
X-Varnish-Grace
X-Content-Powered-By
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Type
X-Request-Guid
X-Instance
X-Drupal-Cache-Tags
X-FW-Hash
X-FB-Debug
PageSpeed
X-SS-Set-Cookie
X-RateLimit-Limit
X-Geo-Country
X-Zen-Fury
X-Forwarded-Host
X-Ezoic-Cdn
X-Shard
X-Handled-By
Edge-Cache-Tag
X-Magnolia-Registration
X-Node-Name
From-Origin
X-Cache-TTL
X-Varnish-Hostname
X-ATG-Version
X-Cache-Age
Cache-Tags
X-TA-CDN-Provider
X-App-Server
X-BCube-Filmed-By
DC
X-Varnish-Server
X-AOL-HN
Cleartype
X-Cache-Control
Fastly-Restarts
Healthy
Upgrade-Insecure-Requests
X-Cache-Rule
Payment
X-Region
Filters
X-Response-Served-From
X-RequestSource
X-WebKit-CSP-Report-Only
Server-Node
X-Signature
X-TX-ID
X-Generated-By
X-B-Cache
Country
X-Adobe-Loc
X-Adobe-Content
X-RTag
X-VG-WebCache
X-Tumblr-Pixel-1
Webserver
X-Tumblr-Pixel-2
X-Storage
X-UUID
Ms-Operation-Id
X-Redis-Cache
X-GeoIP
X-TT-TIMESTAMP
NGB
Actual-Object-TTL
Retry-After
X-FW-Dynamic
X-Jobs
Cache-Tv-Group
X-Drupal-Cache-Contexts
X-Varnish-Hits
X-Content-Age
X-XRDS-LOCATION
X-Cacheable-TTL
X-Locale
Powered
GEO-INFO
CACHE
ServedBy
X-Esi
Frame-Options
Liferay-Portal
X-Contextid
X-Oneagent-Js-Injection
HitType
X-WA-Info
X-Rendered-As
X-Seen-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-TTL-Remaining
X-Varnish-IP
X-Cache-NE
X-Via-JSL
X-ProcessESI
S-Cnection
X-RemovedCookies
Eomportal-Instance
X-Guploader-Uploadid
Viewport
X-Real-IP
X-BACKEND-TTL
X-Upgrade-Enabled
X-Cache-Server
X-Mode
X-Cache-Operation
X-Wix-Server-Artifact-Id
NtCoent-Length
X-Varnish-Cache-Hits
Xserver
X-Newrelic-App-Data
OT-Force-Account-Verify
X-Hl-Ver
Content-Style-Type
Content-Script-Type
X-Is-Bot
X-From
X-Detected-As
X-Cache-Var
X-Device-Type
X-Cache-Var-Map
Mn-Server-Ip
Meta-Geo
X-ES-SERVER
Cache-Hits
Cache-Key
Load-Balancing
X-Routing-Service
X-RN-RSRV
X-Path-Route
X-Proto
X-Proxied
X-Zipkin-Id
Machine
Datacenter
X-S
X-Time
TWC-Connection-Speed
We-Hiring
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
NGX
X-Akamai-Transformed
TWC-Privacy
X-AWS-Id
X-L-Path
X-Origin-Hint
X-LJ-Flow-ID
X-FB-TRIP-ID
X-Environment-Context
Mail-Subject
X-Tb
Vix-Hermes-Req-Id
X-Proxy
L5d-Success-Class
TWC-Device-Class
X-Cache-Enabled
Property-Id
X-Cache-Config
X-Backend-Name
X-FC-Vary-Parameters
X-Viewer-Country
X-VWS-Id
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
X-Hosted-By
X-VG-TLSProxy
X-Labrador-Cache-Channel
X-Loop
X-Format
Azure-InstanceId
X-MP-GENERATED-AT
Azure-SiteName
Azure-SlotName
Azure-Version
X-FW-Version
Azure-RegionName
X-RCS-CacheZone
Origin-Edge-Control
X-Access
X-Tumblr-Pixel-3
Origin-Cache-Control
X-Web-Node
X-Birta-Served
X-Akamai-Request-ID
X-Rocket-Nginx-Bypass
X-Birta-Cache-Post
X-NCache
X-TNCMS
DB-Nickname
X-Debug-Cache
S-Rt
Now
X-Section
X-Time-Microsecs
X-ServerID
X-Origin-Response-Time
X-CCM
X-EIG-Tracking-Id
X-OCL
X-NWS-LOG-UUID
X-ProxyCache-Status
X-BYPASS-REASON
X-Trace-Id
X-Via-Fastly
X-Via-CDN
X-Human
X-ProxyCache-Key
X-Vgn-Hpd-Reason
X-IP
X-JoinUs
X-Endurance-Cache-Level
X-PCL
Cache-Tag
X-Xfnlog-Site
X-Cache-Category-Id
Selected-FE
Uber-Trace-Id
X-Internal-Host
X-Site-Version
X-Timing-Wait
X-Varnish-Cacheable
X-Www-Served-By
X-Grey
X-Proxy-Build
X-Generated
Access-Control-Request-Headers
Decoy-Debug-Status
Decoy-Debug-TTL
X-R9-Blue-Green-Version
Decoy-Debug-Key
X-Status
X-GRACE
X-VC-Cache
Served-By
X-Dynatrace-Js-Agent
X-Cache-Remote
LB
X-Rule
X-UnsetCookies
X-UA
Release
X-EdgeConnect-Cache-Status
ViewerVersion
X-Wix-Request-Id
X-CDN-Cache
AsisCache
X-TIME
Nel
X-Cluster-Node
X-Origin-Host
Rt-Fastcgi-Cache
X-Sucuri-ID
X-APP-VERSION
X-App-Name
X-PERF
X-B3-Spanid
X-Ua
X-ApacheServer
X-Datadome
X-Request-Time
X-Source
X-Nginx-Cache
X-Agile-Age
X-Agile-Id
X-Agile
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hit
User-Agent
X-Origin
X-NewRelic-App-Data
X-OVcl-Cache
Cache-Name
X-OVcl
X-VCT
Warning
DSUID
SRV
X-App-Version
X-WPE-Loopback-Upstream-Addr
X-Edge-Location
X-Origin-CC
X-ElasticPress-Search
X-Origin-TTL
X-Server-Group
X-Request-UUID
X-NU-AKA-ACS-Version
X-B-Cookie
X-Region-Sid
Server-Cache-Control
X-Cache-ASPX
X-PAYTM-SRV-ID
X-Refresh
X-Sedo-Request-Id
X-Rojux
X-S-Cookie
X-ARC
X-Rewrite-Enabled
X-IN-APIGATEWAY
Thinkindot-CacheControl
X-Secret
X-ScT
X-BB-ID
X-Ocache
X-A-Ccd
X-A
Ajk
X-A-Dam
X-Platform
Www
X-Logtrace-Id
X-Mobile-URL
X-Matched-Rule
BehaviorPad-Version
UCS
Arc-Country
X-A-Dcw
X-Processor
Server-Surrogate-Control
Thinkindot-Control
Cross-Origin-Window-Policy
Thinkindot-CacheControl-Type
Ec-Rule-Version
X-Aed
X-Cache-Grace
X-A-Wwc
X-A-Dgt
X-Accel-Expires-Debug
X-Pubstack
Cache-Prefix
X-Application
Fly-Request-Id
X-DPWN-IS-SECURE
Node
X-Gannett-Site-Version
Meta-Geo-Continent
Hostname
X-Transaction
X-Var-Ttl
X-Twitter-Response-Tags
X-Destination
X-Developer
X-IN-WAF
Origin
On-Server
X-Instart-Isnd
X-Up
X-SRCache-Key
X-VG-WebServer
X-G
Lfy
X-Webstats-RespID
X-External-Request-Id
Xc-Version
X-F5-Cache
X-NodeID
X-Varnish-Authentication
X-Debug-Log
X-Thinkindot-L3
X-Hp-Webp
X-CF-Lambda-Fn
X-CF-Lambda-Version
Request-Time
X-Generated-In
X-Cache-Miss-From
X-NX-Host
Fly-Cache
X-Cache-Info
Memcached
X-Debug-Cookies
X-Trv-Group
X-Date
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
MD5-Digest
X-D
X-Connection-Hash
Request-EU
X-Core-Value
Request-Country
Rendered-Blocks
User-Cache-Control
X-Cache-Backend
X-Varnish-Ttl
Cache
X-Nginx-Cache-Key
X-Micro-Cache
Server-Int
Server-Host
RNT-Time
Proxy-Connection
Pramga
Pagetype
X-No-Session
RNT-Machine
ServerName
X-Cache-Debug
X-Distributor
X-LAGOON
X-Epic-Correlation-Id
X-Distil-CS
X-Dispatcher-Server
X-Li-Fabric
X-Developers
X-Eu-Site
X-Key
X-Hash
X-Hnp-Log
X-Geo-Header
X-Gen-Mode
X-Irp-Debug
X-Info
X-Crawler
X-Li-Pop
X-Amzn-Remapped-Date
X-LI-Proto
X-Amzn-Remapped-Connection
X-LI-UUID
Web-Mar-Node
X-Location
X-Block-Status
X-C
X-Cdn-Srv
X-CGP
X-Cache-Id
X-Cache-Host
X-Cache-Bucket
X-Cache-Expires
True-Client-Country-4JS
Country-Code
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Backend
Apple-News-Services-Request-Url
Cache-Cookie-Set-Lfrom
CDCHOST
X-PHP-Host
X-Rebelmouse-Surrogate-Control
X-ServiceProvider
X-SN
X-Reboot
Apple-News-Services-Parsed-Url
X-Protected-By
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Sucuri-Cache
X-Policy
X-Request-URI
Apple-News-Services-Host
Apple-News-Services-Handled
FNAC-ModuleRouting
X-Qloud-Router
X-SIPLIST1
X-Edge-IP
X-Servername
HA-Ipaddr
Ha-Gx-Prefs
X-Sf
X-Rebelmouse-Cache-Control
X-Ah-Environment
Kp-EeAlive
X-Real-Ip
IsBot
Fastly-SIE
X-Origin-Date
X-RateLimit-Limit-Second
X-TT-LOGID
X-Swa-Ws
X-Origin-Expires
Fastly-SWR
X-Page-Type
X-RateLimit-Remaining-Second
X-FireWall-Port
Cteonnt-Length
X-Varnish-Beresp-Status
Pagespeed
X-Varnish-Beresp-Grace
X-Level-Front-Cache
X-Cms-Context
X-Core-Mission
X-Shopify-Stage
X-Skip-Cache
X-Device-Os
X-Wikidot-Static-Cache
X-User
X-Variation
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Generated-On
X-Thanos
X-TrackingId
X-GeoIP-Country-Code
X-GeoIP-City
X-Gateway-Cache-Key
X-Varnish-Url
X-ShopId
X-Amzn-Remapped-Content-Length
X-Sorting-Hat-ShopId
X-Fastly-Cache
X-Wikidot-Backend
X-Via-Edge
X-Via-SSL
X-Fetched-On
X-Sorting-Hat-PodId
N-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Content-Disposition
AKAMAI
Adler-Geo
X-Backend-Host
X-Auto-Login
X-ShardId
X-Alternate-Cache-Key
Fastly-Backend-Name
Fastly-Soc-X-Request-Id
Platform
HTTPS
Is-Eu
Magicmarker
Heartbleed
X-MSEdge-Flight
SD-X-WS
Fastly-SSL
X-MSEdge-Features
X-Backend-State
X-Amz-Meta-Cache-Control
X-Backend-Url
X-Server-IP
X-Cache-FS-Status
X-BBXSRF
X-Bip
X-S-Maxage
X-Cdn-Forward
X-NC
X-GZip
X-Server-Time
Gh-Request-Id
X-RateLimit-Reset
X-Owner
MIME-Version
X-Apm-Inst-Hash
X-Apm-App-Name
X-Sn-Servicetimems
X-Node-Id
X-Apm-Svc-Key
Server-ID
X-Cdn-Origin
V-Age
X-Varnish-Beresp-Ttl
X-CDN-Forward
X-FPC
X-Exp-Se
X-ND-Cache
Rt-Proxy-Cache
X-Org
REQUESTUUID
X-Geo
X-Served-From
VivaBuild
Powered-By
Viewtype
X-CUA
HostName
AR-SID
X-Gdpr
X-Load-Cache
X-B3-Parentspanid
X-Aicache-OS
X-Pjax-Url
Section-Io-Cache
Pragrma
X-Parent-Response-Time
X-CSRF-TOKEN
X-Dc
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From
X-Server-By
X-Original-Request
X-Svr
X-Stale
X-Actual-URL
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-DC
X-Passed-To
Wxu-Next-Region
Wxu-Next-Hostname
Memory
X-Git-Hash
X-VServer
X-Croise-Owner
Wxu-Next-Commit
PICS-Label
X-HS-Cache-Config
Host-ID
CF-IPCountry
Time
X-Nc
Cdn-Request-Time
X-Servedbyhost
X-Edge-Server
Cdn-Host
X-CACHE-KEY
X-Wa
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
Resin-Trace
Fastcgi-Useragent
X-Oss-Object-Type
X-Unique-ID
X-Oss-Storage-Class
X-Oss-Server-Time
X-Host-Name
ProcessTime
X-Release
X-Tb-Optimization-Total-Bytes-Saved
SID
X-Microcachable
Mime-Version
X-Cache-HT
X-Newrelic-Synthetics
X-Optimization
X-From-Cache
X-WebServer
X-TH-Server
X-Daa-Tunnel
X-Lb-Id
X-V
X-Req
X-Phone
X-Varnish-Beresp-TTL
Cf-Ipcountry
Cdn
X-Upstream-HT
X-Upstream-CT
Odigeo-Trace-Id
X-Instart-Info
X-Atg-Version
CF-Cached-On
Backend-Name
X-Fastly-Backend-Reqs
XServer
X-HTML-Minification-Powered-By
Proxy-Firewall
X-APP
X-ID
Processtime
X-WR-MODIFICATION
X-Fstrz
X-Worker
X-LB-ID
X-Ratelimit-Remaining
X-Backend-TTL
X-Vcl-Version
X-B3-SpanId
X-Ratelimit-Limit
189phosttRef
352pxline
225prxHost
219prxHost
355prline
409pxxline
X-Server-W
Xxline
X-Response-By
286prxHost
178proxuri
188prxHost
X-CLOUD-TRACE-CONTEXT
X-CACHE-AGE
GMS-Ver
X-Nananana
X-IPS-LoggedIn
X-Check-Cacheable
Public-Key-Pins-Report-Only
Version
X-Zone
X-Vcache
X-NGINX-Cache
WZWS-RAY
X-WA
Fastcgi-X-Cache-Version
Esi-Enabled
X-UPSTREAM-Address
X-VCL-Version
X-Ratelimit-Reset
X-URL
X-Akamai-Request-ID2
GW-Server
Pics-Label
GeoIP-Latitude
X-Amz-Meta-Surrogate-Control
X-CSRF-Token
GeoIP-Country-Code
GeoIP-City
X-HS-Status
X-ServedByHost
X-AssetVersion
Accept-Language
X-GEO
SN
X-Hyper-Cache
X-Contensis-Viewer-Groups
DataCenter
Geoip-Latitude
GeoIp-Country-Code
X-We-Are-Hiring
Countrycode
X-UE-Client-Country
X-Clientip
X-FORWARDED-FOR
Lb
X-Fastly-Country-Code
X-SRV
Mobile-Detection-Method
X-SERVER-NAME
X-Dynatrace
X-ZONE
X-RequestId
X-BE
X-Request-Start
SS
X-Via-Ucdn
X-Vtex-Processado-Em
X-Render-Time
X-Request-Handler-Origin-Region
X-Vtex-Remote-Cache
Geoip-City
X-Be
X-Microsite
WP-Super-Cache
X-Cdn-Cache
Ohc-File-Size
X-CS
X-Via-NSCOPI
X-Urbn-Context-Path
X-Cache-Ttl
X-LiteSpeed-Cache-Control
X-Urbn-Site-Id
X-Reqid
Locale
URI
CDN
X-NWS-UUID-VERIFY
X-PJAX-URL
X-GDPR
X-GZIP
X-Unique-Id
X-PF-Uncompressing
X-HS-Combine-CSS
FSS-Proxy
X-Gen-Id
X-ABtesting
FSS-Cache
X-Hello
X-Flog
Amp-Access-Control-Allow-Source-Origin
X-HostName
Dynatrace
FastCGI-Cache
Cneonction
X-Fastly-Cache-Hits
IBM-Web2-Location
Serverid
X-Fpc
Dnion-Transfer-Encoding
RequestUuid
X-Pf-Uncompressing
X-Generation-Time
X-Html-Edge-Cache
X-Request-Url
X-LiteSpeed-Tag
Accept-Ch
Server-Id
Ohc-Cache-HIT
X-Test
A
X-Store
Requestid
X-Akamai-SSL-Client-Sid
X-NGENIX-Cache
X-Dw-Trace-Id
X-Compress-Hint
X-Cluster-Name
X-Bug-Bounty
X-EC-Lua
X-Cdn-Request-ID
X-Port
X-Serial
X-HTML-Edge-Cache
Frontcache
NnCoection
Is-Session-Tracking
Get-Access-Time
X-UCC
X-ServerName
Ohc-Response-Time