Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
CF-Ray
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Content-Security-Policy
X-Buckets
Upgrade
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
X-CDN
Keep-Alive
Access-Control-Expose-Headers
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Cache-Group
X-Pass-Why
X-Server
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Via
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Hacker
X-Varnish-Cache
X-Robots-Tag
X-Page-Speed
WPE-Backend
X-Server-Powered-By
X-Nginx-Cache-Status
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
P3p
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Device
X-OneAgent-JS-Injection
Server-Timing
Allow
X-Rq
X-Ac
X-Node
X-Host
X-Server-Id
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
Report-To
X-Cloud-Trace-Context
X-Backend-Server
EagleEye-TraceId
X-Application-Context
Surrogate-Control
X-CST
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Url
X-Origin-Cache
X-Readtime
X-Rack-Cache
X-FTR-Request-ID
X-Country
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
X-Instart-Request-ID
NEL
X-DataDome
X-Vhost
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
Pinterest-Generated-By
X-Cdn
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-Origin-Upstream-Status
Edge-Control
X-Type
X-Px
X-Goog-Hash
X-HW
Accept-CH
X-Dispatcher
Verso
X-Server-Name
X-ESI
MS-Author-Via
AR-ATIME
X-VARITI-CCR
AR-CACHE
AR-PoweredBy
PB-PID
Arc-Version
X-Mobile-Rewrite
PB-RID
X-GitHub-Request-Id
X-MS-InvokeApp
X-Cdn-Fetch
X-ORACLE-DMS-RID
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-DataStream-Cache-Status
Public-Key-Pins
X-Upstream-Env
X-Cached
X-Powered-By-Plesk
Content-MD5
X-Version
Service-Worker-Allowed
Accept-CH-Lifetime
AR-Request-ID
X-Recruiting
RTSS
X-D2id
X-Amz-Server-Side-Encryption
X-Navigation-Version
Charset
X-Abt-Application-Version
X-Vname
X-TtlSet
X-PC
X-Ser
Ar-Sid
X-Vcap-Request-Id
X-Varnish-TTL
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-TTL
X-Forwarded-Proto
X-Client-IP
X-Trace
Nginx-Cache
SPRequestGuid
X-DynaTrace-JS-Agent
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Backend
X-Server-ID
X-FTR-Expires
DynaTrace
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Oracle-Dms-Rid
X-Amz-Rid
X-VCache
X-Fastly-Request-ID
X-Amz-Meta-S3cmd-Attrs
S
X-Hits
X-Debug
TCN
X-SharePointHealthScore
Pinterest-Version
X-Upstream-Proxy
X-Pinterest-Rid
X-Ttl
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Dw-Request-Base-Id
X-Akam-SW-Version
X-Shield-Request-Id
Arr-Disable-Session-Affinity
X-Powered-CMS
X-XRDS-Location
SPRequestDuration
SPIisLatency
X-FTR-Cache-Host
X-T
Access-Control-Request-Method
X-Goog-Storage-Class
X-Id
X-Webkit-CSP
Realpath
X-Aspnet-Version
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-NF-Request-ID
Tracecode
X-Amzn-Trace-Id
Front-End-Https
Fastcgi-Cache
X-N
X-Varnish-Age
X-Content-Type
X-Fastcgi-Cache
X-Upstream
X-Forwarded-For
X-B3-TraceId
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
Paypal-Debug-Id
X-B3-Traceid
X-Mrf-Item-Lastmod
Alternate-Protocol
X-Frontend
X-Logged-In
X-Content-Digest
X-HS-Content-Id
X-HS-Hub-Id
Display
X-Middleton-Display
Response
X-Sol
X-Middleton-Response
X-Pad
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
X-Litespeed-Cache
X-RateLimit-Remaining
X-Srv
X-Hostname
X-PressLabs-Stats
AMP-Access-Control-Allow-Source-Origin
X-Cache-Key
X-Accel-Expires
Host
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
MicrosoftSharePointTeamServices
X-Grace
ServerID
X-Correlation-Id
Server-Name
X-Analytics
Backend-Timing
X-B3-Sampled
X-Kinsta-Cache
X-User-Agent
X-AppVersion
Surrogate-Key
X-Az
X-Debug-Info
X-LB-Cache
X-IPLB-Instance
X-Revision
X-Activity-Id
X-Rid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Hit
X-Content-Options
FilterID
Accept-Charset
X-Ruxit-Js-Agent
X-Cache-2
Refresh
X-CF-Powered-By
Powered-By-ChinaCache
X-B
X-Request-Processing-Time
X-Request-Received
TP-Cache
TP-L2-Cache
X-Page-Id
MS-CV
X-Whom
X-DIS-Request-ID
Server-Info
X-Cached-By
Host-Header
Cache-Status
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
Source
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Akamai-Edgescape
X-Amz-Replication-Status
X-Origin-Server
X-App-Environment
X-Cache-Action
X-PHP-Backend
X-TT
X-Tumblr-Pixel-0
PageSpeed
X-Mobile
X-Platform-Server
X-Cluster
X-Tumblr-Pixel
X-Tumblr-User
X-Accel-Buffering
X-F-Cache
X-Framework
Access-Control-Allow-Method
X-FW-Server
X-FW-Type
X-Varnish-Grace
X-Content-Powered-By
X-FW-Static
X-FW-Hash
X-FW-Serve
X-Forwarded-Host
X-Drupal-Cache-Tags
X-Request-Guid
X-FB-Debug
X-Instance
X-Kong-Proxy-Latency
X-Ezoic-Cdn
X-UA-Device-Type
X-Kong-Upstream-Latency
X-Node-Name
X-Shard
X-Geo-Country
X-Oneagent-Js-Injection
Edge-Cache-Tag
X-RateLimit-Limit
X-TA-CDN-Provider
X-Zen-Fury
Fastly-Restarts
X-GUploader-UploadID
X-Handled-By
X-Cache-TTL
From-Origin
X-Varnish-Hostname
X-SS-Set-Cookie
X-Magnolia-Registration
Cache-Tags
X-Cache-Age
X-AOL-HN
X-BCube-Filmed-By
X-FastCGI-Cache
X-ATG-Version
X-XRDS-LOCATION
X-Cache-Control
X-Cache-Rule
Healthy
Upgrade-Insecure-Requests
X-Varnish-Server
Cleartype
Retry-After
X-App-Server
Server-Node
DC
Payment
X-Response-Served-From
X-RequestSource
X-B-Cache
Country
X-Storage
X-TX-ID
X-Signature
X-Adobe-Loc
X-Adobe-Content
X-WebKit-CSP-Report-Only
X-RTag
X-Region
X-TT-TIMESTAMP
X-Tumblr-Pixel-1
X-Dns-Prefetch-Control
Ms-Operation-Id
X-Redis-Cache
Actual-Object-TTL
X-UUID
X-FW-Dynamic
Powered
Filters
X-GeoIP
X-Tumblr-Pixel-2
X-VG-WebCache
Cache-Tv-Group
X-Jobs
X-Drupal-Cache-Contexts
X-Generated-By
X-Varnish-Hits
X-Content-Age
X-Cacheable-TTL
Webserver
X-Locale
Frame-Options
CACHE
GEO-INFO
X-WA-Info
NGB
ServedBy
X-Guploader-Uploadid
X-Contextid
X-Cache-NE
X-Yottaa-Optimizations
Liferay-Portal
X-Yottaa-Metrics
HitType
X-Rendered-As
X-RemovedCookies
X-ProcessESI
X-BACKEND-TTL
Eomportal-Instance
X-Cache-Operation
X-Cache-TTL-Remaining
X-Varnish-IP
X-NWS-LOG-UUID
X-Upgrade-Enabled
Nel
X-Via-JSL
X-Mode
X-Esi
Viewport
X-Real-IP
X-Seen-By
S-Cnection
Xserver
NtCoent-Length
X-Varnish-Cache-Hits
Meta-Geo
X-Akamai-Transformed
X-Cache-Var
Machine
X-Routing-Service
X-Proto
X-Device-Type
X-ES-SERVER
Cache-Key
X-RN-RSRV
OT-Force-Account-Verify
Cache-Hits
X-From
X-Path-Route
X-Proxied
X-Cache-Enabled
LB
X-Cache-Var-Map
X-Detected-As
X-Is-Bot
X-Zipkin-Id
X-Hl-Ver
Mn-Server-Ip
Load-Balancing
X-Time
X-S
X-Hosted-By
L5d-Success-Class
Mail-Subject
X-FW-Version
Property-Id
NGX
X-L-Path
X-Cache-Config
X-R9-Blue-Green-Version
X-Rocket-Nginx-Bypass
X-Proxy
X-Origin-Hint
X-LJ-Flow-ID
X-NCache
X-FC-Vary-Parameters
X-FB-TRIP-ID
We-Hiring
Vix-Hermes-Req-Id
Webcakes-App-Name
Webcakes-App-Version
X-Environment-Context
Webcakes-Region
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
X-Backend-Name
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-AWS-Id
Access-Control-Request-Headers
X-VWS-Id
X-VG-TLSProxy
X-Time-Microsecs
X-Viewer-Country
X-Cache-Server
X-Tb
X-Labrador-Cache-Channel
S-Rt
X-Tumblr-Pixel-3
X-Loop
X-MP-GENERATED-AT
Azure-SiteName
Origin-Cache-Control
X-Format
Azure-Version
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Cache-Remote
X-RCS-CacheZone
X-Debug-Cache
X-Akamai-Request-ID
X-Section
X-Vgn-Hpd-Reason
X-ServerID
X-TNCMS
X-EIG-Tracking-Id
X-Web-Node
Origin-Edge-Control
X-Access
DB-Nickname
Now
X-Origin-Response-Time
X-Via-CDN
Selected-FE
X-BYPASS-REASON
X-CCM
Datacenter
X-Xfnlog-Site
X-Via-Fastly
X-Human
X-ProxyCache-Key
X-Proxy-Build
X-JoinUs
X-Trace-Id
X-ProxyCache-Status
X-PCL
X-Timing-Wait
X-OCL
X-IP
Cache-Tag
X-Grey
Content-Style-Type
X-Cache-Category-Id
X-Generated
Content-Script-Type
X-Internal-Host
Uber-Trace-Id
X-Www-Served-By
X-UnsetCookies
X-VC-Cache
X-UA
X-Dynatrace-Js-Agent
X-Endurance-Cache-Level
X-Varnish-Cacheable
X-Site-Version
X-Rule
Release
Decoy-Debug-Status
Decoy-Debug-Key
X-Status
Decoy-Debug-TTL
X-Birta-Cache-Post
Served-By
X-Birta-Served
X-EdgeConnect-Cache-Status
X-APP-VERSION
X-TIME
X-CDN-Cache
X-Newrelic-App-Data
X-B3-Spanid
X-GRACE
X-Request-Time
DSUID
X-Cluster-Node
X-OVcl
AsisCache
X-OVcl-Cache
X-Nginx-Cache
X-Origin
X-App-Name
Rt-Fastcgi-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NewRelic-App-Data
X-VCT
X-ApacheServer
X-PERF
X-Hit
Hostname
X-Source
SRV
X-Ua
X-Origin-Host
X-Sucuri-ID
X-Agile-Age
X-Agile-Id
X-Agile
ViewerVersion
X-Wix-Request-Id
Cache-Name
X-Pubstack
Cteonnt-Length
X-ElasticPress-Search
X-Wix-Server-Artifact-Id
X-Cache-Host
X-Origin-TTL
X-SERVER
X-Origin-CC
Thinkindot-Control
Thinkindot-CacheControl-Type
UCS
X-A
X-VG-WebServer
X-Webstats-RespID
X-Accel-Expires-Debug
X-Aed
X-Var-Ttl
X-Up
X-Twitter-Response-Tags
X-A-Wwc
X-A-Dgt
X-A-Ccd
X-A-Dam
X-A-Dcw
X-Varnish-Authentication
Origin
FNAC-ModuleRouting
Fly-Request-Id
Lfy
MD5-Digest
Memcached
Fly-Cache
Ec-Rule-Version
Arc-Country
BehaviorPad-Version
Cache-Prefix
Cross-Origin-Window-Policy
Meta-Geo-Continent
Node
Request-Time
Server-Cache-Control
Server-Host
Server-Surrogate-Control
Request-EU
Xc-Version
On-Server
X-Trv-Group
Rendered-Blocks
Request-Country
Thinkindot-CacheControl
X-Server-Group
X-Cache-Info
X-G
X-F5-Cache
X-External-Request-Id
X-DPWN-IS-SECURE
X-Gannett-Site-Version
X-Generated-In
X-Instart-Isnd
X-Logtrace-Id
X-IN-WAF
X-IN-APIGATEWAY
X-Hp-Webp
X-Cache-Miss-From
X-Developer
Ajk
X-Core-Value
X-D
X-Debug-Cache-Fetch
X-Date
X-Connection-Hash
X-Debug-Cache-Store
X-Destination
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Debug-Log
X-Debug-Cookies
X-Matched-Rule
X-Mobile-URL
X-ScT
X-Secret
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-Sedo-Request-Id
X-Debug-Cache-Expiry
X-SRCache-Key
X-Thinkindot-L3
X-ServiceProvider
X-Application
X-ARC
X-Request-UUID
X-Region-Sid
X-NU-AKA-ACS-Version
X-NX-Host
X-NodeID
X-Cache-Expires
X-Cache-Grace
X-PAYTM-SRV-ID
X-Platform
X-Reboot
X-Refresh
X-B-Cookie
X-Processor
X-Cache-ASPX
X-Transaction
Www
X-WPE-Loopback-Upstream-Addr
X-Varnish-Ttl
User-Cache-Control
X-Device-Os
X-Dispatcher-Server
X-Developers
X-Crawler
X-Cdn-Srv
X-CGP
X-Distil-CS
X-Gen-Mode
X-Hash
X-Fetched-On
X-Eu-Site
X-Distributor
X-Epic-Correlation-Id
X-Cache-Id
X-Cache-Bucket
V-Age
Web-Mar-Node
X-Amzn-Remapped-Connection
True-Client-Country-4JS
ServerName
RNT-Time
Server-Int
X-Amzn-Remapped-Content-Length
X-Amzn-Remapped-Date
X-Cache-Backend
X-Hnp-Log
X-Block-Status
X-Apm-Svc-Key
X-Apm-App-Name
X-Apm-Inst-Hash
X-Cache-Debug
X-Irp-Debug
Cache
X-Request-URI
X-Servername
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Sf
X-SIPLIST1
X-Server-Time
X-Sn-Servicetimems
X-Cdn-Origin
X-Real-Ip
X-SN
X-Swa-Ws
X-Qloud-Router
X-Policy
X-Li-Pop
X-LI-Proto
X-Li-Fabric
X-LAGOON
RNT-Machine
X-Key
X-LI-UUID
X-Location
X-Page-Type
X-PHP-Host
X-Origin-Expires
X-Origin-Date
X-Micro-Cache
X-Nginx-Cache-Key
X-Info
Warning
Ha-Gx-Prefs
Gh-Request-Id
Fastly-SWR
HA-Ipaddr
IsBot
Pramga
Pagetype
Kp-EeAlive
Fastly-SIE
Country-Code
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Request-Url
Backend
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Proxy-Connection
CDCHOST
X-FireWall-Port
Pagespeed
X-Geo
X-App-Version
X-Via-SSL
X-Cms-Context
X-Core-Mission
Heartbleed
X-ShopId
X-Via-Edge
X-Cache-FS-Status
X-ShardId
X-Server-IP
X-Level-Front-Cache
X-Wikidot-Static-Cache
Content-Disposition
X-Wikidot-Backend
X-GeoIP-Country-Code
X-S-Maxage
X-Geo-Header
X-Skip-Cache
X-Thanos
X-Gateway-Cache-Key
X-Fastly-Cache
X-Sorting-Hat-ShopId
X-Exp-Se
Is-Eu
X-Gateway-Cache-Status
Adler-Geo
X-Sorting-Hat-PodId
X-Variation
X-User
X-Generated-On
X-Gateway-Skip-Cache
X-Shopify-Stage
X-GeoIP-City
SD-X-WS
X-No-Session
AKAMAI
Fastly-Soc-X-Request-Id
Platform
X-Auto-Login
X-MSEdge-Flight
X-Protected-By
X-Amz-Meta-Cache-Control
X-Varnish-Beresp-Status
X-Planisys-CDN-Cache
X-Varnish-Beresp-Grace
X-Planisys-CDN-Rules
X-Alternate-Cache-Key
X-Planisys-CDN-TTL
Fastly-SSL
X-MSEdge-Features
X-BBXSRF
X-C
X-ND-Cache
Rt-Proxy-Cache
X-Backend-Url
X-Bip
X-Backend-Host
X-Backend-State
X-GZip
HTTPS
X-Ocache
X-Owner
REQUESTUUID
X-RateLimit-Reset
X-Org
X-Served-From
X-BB-ID
X-B3-Parentspanid
X-Edge-Location
X-Proxy-Cache-Status
X-Proxy-Upstream
Server-ID
X-Sucuri-Cache
X-TrackingId
X-TT-LOGID
X-Git-Hash
User-Agent
X-Cdn-Forward
X-CDN-Forward
Magicmarker
X-Varnish-Url
Fastly-Backend-Name
X-FPC
N-Cache
X-Edge-IP
MIME-Version
X-NC
X-Host-Name
VivaBuild
Viewtype
AR-SID
Wxu-Next-Commit
X-Gdpr
X-Aicache-OS
Wxu-Next-Region
Wxu-Next-Hostname
X-Load-Cache
X-Dc
X-Varnish-Beresp-Ttl
X-Daa-Tunnel
X-Node-Id
X-Pjax-Url
X-Parent-Response-Time
X-Nc
X-CSRF-TOKEN
Powered-By
X-CUA
Time
Memory
X-Release
X-DC
Pragrma
CF-IPCountry
HostName
X-WebServer
X-TH-Server
PICS-Label
X-CACHE-KEY
Resin-Trace
X-HS-Cache-Config
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Phone
X-Returned-From-DLL
X-Wa
X-Svr
X-Passed-To-BeforeDispatch
X-Server-By
X-Servedbyhost
X-Returned-From-BeforeDispatch
X-Stale
X-Returned-From
X-Returned-From-PostProcessResponse
Mime-Version
X-Original-Request
X-Oss-Hash-Crc64ecma
Host-ID
X-Upstream-HT
X-Passed-To
X-Actual-URL
X-Oss-Object-Type
X-Upstream-CT
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
Section-Io-Cache
X-Croise-Owner
X-Instart-Info
X-VServer
X-Newrelic-Synthetics
Backend-Name
X-Edge-Server
X-Lb-Id
Cdn-Host
X-From-Cache
X-Tb-Optimization-Total-Bytes-Saved
Cdn-Request-Time
CF-Cached-On
X-Cache-HT
Cf-Ipcountry
Cdn
X-Varnish-Beresp-TTL
X-Optimization
ProcessTime
X-Worker
225prxHost
178proxuri
219prxHost
189phosttRef
188prxHost
Version
286prxHost
352pxline
X-Request-Handler-Origin-Region
Xxline
X-Server-W
SID
409pxxline
X-APP
X-Fastly-Backend-Reqs
X-Microsite
355prline
X-Unique-ID
X-Atg-Version
Processtime
X-Datadome
XServer
X-Microcachable
X-Req
X-Zone
X-Vcl-Version
X-ID
X-Akamai-Request-ID2
Proxy-Firewall
Accept-Language
X-Ratelimit-Remaining
X-LB-ID
Odigeo-Trace-Id
X-B3-SpanId
Esi-Enabled
X-V
X-Ratelimit-Limit
X-CLOUD-TRACE-CONTEXT
Fastcgi-Useragent
X-CACHE-AGE
X-Contensis-Viewer-Groups
X-AssetVersion
X-IPS-LoggedIn
X-HTML-Minification-Powered-By
X-VCL-Version
X-UPSTREAM-Address
SN
X-Backend-TTL
X-Fstrz
X-Vcache
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
X-WA
X-NGINX-Cache
X-Check-Cacheable
X-WR-MODIFICATION
X-Vtex-Remote-Cache
Pics-Label
X-URL
X-Vtex-Processado-Em
X-CSRF-Token
X-ServedByHost
X-RequestId
X-HS-Status
X-Response-By
X-Nananana
X-Ratelimit-Reset
GMS-Ver
Geoip-Latitude
X-ZONE
GeoIp-Country-Code
X-Via-NSCOPI
X-Be
X-Urbn-Site-Id
X-Reqid
Locale
X-Urbn-Context-Path
DataCenter
X-Hello
X-Flog
X-ABtesting
X-Hyper-Cache
X-NWS-UUID-VERIFY
Geoip-City
X-SERVER-NAME
X-Dynatrace
Dnion-Transfer-Encoding
X-Request-Start
Fastcgi-X-Cache-Version
IBM-Web2-Location
X-Fastly-Country-Code
X-Render-Time
X-Via-Ucdn
Public-Key-Pins-Report-Only
X-Cdn-Cache
WP-Super-Cache
CDN
X-Amz-Meta-Surrogate-Control
X-CS
X-GDPR
X-Generation-Time
X-Cache-Ttl
WZWS-RAY
GW-Server
X-LiteSpeed-Cache-Control
X-Unique-Id
X-NGENIX-Cache
Lb
Requestid
Countrycode
X-Cluster-Name
Mobile-Detection-Method
X-PJAX-URL
X-We-Are-Hiring
X-Clientip
X-UE-Client-Country
URI
Dynatrace
X-HostName
X-Presslabs-Stats
X-SRV
FastCGI-Cache
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
X-Pf-Uncompressing
SS
X-Fpc
X-Gen-Id
X-Compress-Hint
X-Cache-URL
X-HS-Combine-CSS
Cneonction
X-GEO
Ohc-File-Size
Serverid
X-BE
WebServer
A
Server-Id
X-Got-Non-Ke-Cookie
X-Varnish-Action
Who
GEO-REGION-INFO
X-Bug-Bounty
X-Store
X-LiteSpeed-Tag
X-Test
X-Akamai-SSL-Client-Sid
Https
X-Dw-Trace-Id
RequestId
X-Serial
Frontcache
X-HTML-Edge-Cache
X-Html-Edge-Cache
X-Request-Url
X-Fastly-Cache-Hits
RequestUuid
X-GZIP
FSS-Proxy
X-ServerName
X-EC-Lua
NnCoection
FSS-Cache
X-Cdn-Request-ID
X-PF-Uncompressing