Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Xss-Protection
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Buckets
Upgrade
Xkey
X-CDN
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-Server-Powered-By
WPE-Backend
X-Robots-Tag
X-Nginx-Cache-Status
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
P3p
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Server-Timing
Allow
X-Ac
X-Rq
X-Node
X-Host
X-Server-Id
Content-Location
Feature-Policy
X-CST
X-Cnection
X-Response-Time
Report-To
X-Backend-Server
X-Cloud-Trace-Context
EagleEye-TraceId
Surrogate-Control
X-Application-Context
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Type
X-Country
X-FTR-Request-ID
X-Clacks-Overhead
X-Cache-Lookup
X-Country-Code
Rating
NEL
X-Instart-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Vhost
X-DynaTrace
Pinterest-Generated-By
X-Mod-Pagespeed
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Px
X-Upstream-Env
X-Goog-Hash
X-Server-Name
Verso
X-HW
Accept-CH
X-Dispatcher
X-ESI
MS-Author-Via
PB-RID
PB-PID
Arc-Version
AR-ATIME
X-Mobile-Rewrite
AR-CACHE
AR-PoweredBy
X-VARITI-CCR
X-MS-InvokeApp
X-GitHub-Request-Id
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Exp-Id
X-Kinja-Server
X-Cdn-Fetch
X-Use-Magma
X-DataStream-Cache-Status
X-ORACLE-DMS-RID
X-Cached
X-Version
X-Powered-By-Plesk
Content-MD5
Public-Key-Pins
Charset
X-TTL
X-Recruiting
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
Ar-Sid
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-Vname
X-TtlSet
X-PC
X-Amz-Server-Side-Encryption
X-Ser
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Varnish-TTL
X-Vcap-Request-Id
X-Trace
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
Nginx-Cache
X-Server-ID
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-Cdn
X-FTR-Expires
X-DynaTrace-JS-Agent
X-Oracle-Dms-Rid
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Amz-Meta-S3cmd-Attrs
X-Amz-Rid
X-SharePointHealthScore
S
X-Fastly-Request-ID
X-VCache
DynaTrace
X-XRDS-Location
TCN
X-Debug
X-Hits
Arr-Disable-Session-Affinity
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Dw-Request-Base-Id
X-Shield-Request-Id
X-Upstream-Proxy
Pinterest-Version
X-Pinterest-Rid
SPIisLatency
SPRequestDuration
X-Akam-SW-Version
X-Powered-CMS
Access-Control-Request-Method
X-T
X-SERVER
X-FTR-Cache-Host
X-Goog-Storage-Class
X-Id
X-Aspnet-Version
Realpath
Front-End-Https
X-NF-Request-ID
Tracecode
X-Acc-Meta-Resource-Type
X-Amzn-Trace-Id
X-MSEdge-Ref
X-B3-TraceId
Fastcgi-Cache
X-N
X-Dns-Prefetch-Control
X-Content-Type
X-Varnish-Age
Paypal-Debug-Id
X-Forwarded-For
X-Ttl
X-Upstream
Mrf-Cache-Status
MRF-Tech
Alternate-Protocol
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-PressLabs-Stats
X-Logged-In
X-RateLimit-Remaining
X-Content-Digest
X-Frontend
X-HS-Content-Id
X-HS-Hub-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
X-Litespeed-Cache
X-Cache-Key
X-Srv
Display
X-Fastcgi-Cache
X-Middleton-Display
X-Sol
X-Hostname
Response
X-Middleton-Response
AMP-Access-Control-Allow-Source-Origin
X-B3-Traceid
X-Pad
X-Webkit-CSP
X-Accel-Expires
Host
MicrosoftSharePointTeamServices
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
Server-Name
X-Analytics
Backend-Timing
X-Content-Options
X-Correlation-Id
X-Revision
X-User-Agent
X-Kinsta-Cache
X-Cache-2
X-Rid
X-IPLB-Instance
X-LB-Cache
X-Debug-Info
X-Cache-Hit
X-B3-Sampled
Surrogate-Key
X-Activity-Id
X-Az
X-Amzn-RequestId
X-AppVersion
X-Amz-Apigw-Id
FilterID
Refresh
X-Accel-Buffering
ServerID
X-Grace
Accept-Charset
Powered-By-ChinaCache
X-B
X-CF-Powered-By
X-DIS-Request-ID
X-Page-Id
X-Whom
X-Request-Processing-Time
X-Request-Received
Server-Info
TP-Cache
X-FastCGI-Cache
TP-L2-Cache
Host-Header
MS-CV
X-PHP-Backend
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-Kong-Upstream-Latency
X-TT
VIX-Pulpo-Upstream-Status
X-Akamai-Edgescape
X-Kong-Proxy-Latency
Cache-Status
X-Amz-Replication-Status
X-App-Environment
X-Cached-By
Source
X-Varnish-Backend
X-Cache-Action
X-Origin-Server
VIX-Pulpo-Node
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Framework
X-UA-Device-Type
X-Platform-Server
X-Varnish-Grace
X-Content-Powered-By
X-Mobile
X-FW-Serve
X-FW-Server
Access-Control-Allow-Method
X-FW-Hash
X-FW-Type
X-Cluster
X-Request-Guid
X-Instance
X-FW-Static
X-GUploader-UploadID
X-Drupal-Cache-Tags
X-F-Cache
X-SS-Set-Cookie
X-Zen-Fury
X-RateLimit-Limit
PageSpeed
X-FB-Debug
X-Forwarded-Host
X-Geo-Country
Edge-Cache-Tag
X-Ezoic-Cdn
X-Handled-By
X-Shard
X-Magnolia-Registration
X-Cache-TTL
X-Node-Name
From-Origin
X-Varnish-Hostname
X-ATG-Version
X-Cache-Age
X-TA-CDN-Provider
Cache-Tags
X-Varnish-Server
DC
X-BCube-Filmed-By
X-Cache-Control
Cleartype
X-App-Server
X-AOL-HN
Fastly-Restarts
Upgrade-Insecure-Requests
Healthy
X-Cache-Rule
Payment
X-RequestSource
Server-Node
X-WebKit-CSP-Report-Only
Filters
X-Response-Served-From
X-Region
Country
X-TX-ID
X-Generated-By
X-Redis-Cache
X-Tumblr-Pixel-1
NGB
X-VG-WebCache
X-Storage
X-Adobe-Loc
X-Adobe-Content
X-Tumblr-Pixel-2
X-TT-TIMESTAMP
X-Drupal-Cache-Contexts
Ms-Operation-Id
X-RTag
X-FW-Dynamic
X-Signature
Cache-Tv-Group
X-UUID
Actual-Object-TTL
Webserver
X-B-Cache
X-GeoIP
X-Locale
X-XRDS-LOCATION
Retry-After
X-Jobs
X-Cacheable-TTL
X-Content-Age
X-Varnish-Hits
CACHE
GEO-INFO
Powered
ServedBy
Frame-Options
X-Contextid
X-Oneagent-Js-Injection
Liferay-Portal
HitType
X-WA-Info
X-Rendered-As
X-Seen-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Real-IP
X-Varnish-IP
X-Cache-TTL-Remaining
X-ProcessESI
S-Cnection
X-Via-JSL
X-RemovedCookies
X-Guploader-Uploadid
X-Cache-NE
Viewport
Eomportal-Instance
X-Dynatrace-Js-Agent
X-BACKEND-TTL
X-Esi
X-Cache-Server
X-Upgrade-Enabled
X-Mode
X-Cache-Operation
X-Wix-Server-Artifact-Id
X-Varnish-Cache-Hits
X-Is-Bot
X-Hl-Ver
X-From
X-Path-Route
X-ES-SERVER
X-Proxied
X-Zipkin-Id
X-Routing-Service
X-RN-RSRV
X-Device-Type
X-Proto
X-Detected-As
Load-Balancing
Cache-Key
Cache-Hits
Content-Style-Type
Meta-Geo
Mn-Server-Ip
X-Cache-Var-Map
X-Cache-Var
X-Cache-Enabled
Content-Script-Type
Machine
X-Time
X-S
NtCoent-Length
TWC-Device-Class
X-Tb
X-Akamai-Transformed
X-Proxy
TWC-GeoIP-Country
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-Backend-Name
X-AWS-Id
X-FB-TRIP-ID
Mail-Subject
X-FC-Vary-Parameters
Access-Control-Request-Headers
OT-Force-Account-Verify
Property-Id
X-LJ-Flow-ID
Webcakes-App-Version
TWC-Privacy
Webcakes-Region
X-Origin-Hint
L5d-Success-Class
NGX
Webcakes-App-Name
X-VWS-Id
Vix-Hermes-Req-Id
X-VG-TLSProxy
We-Hiring
X-Viewer-Country
Datacenter
X-Cache-Config
X-Newrelic-App-Data
X-Labrador-Cache-Channel
X-MP-GENERATED-AT
X-L-Path
Azure-RegionName
Azure-Version
X-Format
X-FW-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
X-NCache
X-Hosted-By
X-Section
X-Tumblr-Pixel-3
Xserver
X-Time-Microsecs
X-Web-Node
X-Birta-Cache-Post
X-Birta-Served
X-Access
X-Rocket-Nginx-Bypass
X-Environment-Context
S-Rt
DB-Nickname
Now
X-Origin-Response-Time
X-Debug-Cache
X-RCS-CacheZone
X-Akamai-Request-ID
X-CCM
Selected-FE
Origin-Edge-Control
X-EIG-Tracking-Id
Origin-Cache-Control
X-IP
X-Endurance-Cache-Level
X-OCL
X-PCL
Cache-Tag
X-Timing-Wait
X-Proxy-Build
X-ServerID
X-Loop
X-Via-Fastly
X-Xfnlog-Site
X-TNCMS
X-Via-CDN
X-Human
X-Trace-Id
X-Site-Version
X-Vgn-Hpd-Reason
X-NWS-LOG-UUID
X-Varnish-Cacheable
X-ProxyCache-Status
X-Internal-Host
X-ProxyCache-Key
X-Www-Served-By
X-BYPASS-REASON
Decoy-Debug-Status
Decoy-Debug-TTL
Uber-Trace-Id
X-R9-Blue-Green-Version
X-Cache-Category-Id
X-Grey
Decoy-Debug-Key
X-VC-Cache
Served-By
X-JoinUs
X-UA
X-GRACE
X-Generated
LB
X-Status
X-Cache-Remote
X-Rule
X-UnsetCookies
Release
X-Wix-Request-Id
ViewerVersion
X-EdgeConnect-Cache-Status
X-CDN-Cache
AsisCache
X-TIME
Nel
X-Cluster-Node
X-Origin-Host
Rt-Fastcgi-Cache
X-Sucuri-ID
X-App-Name
X-APP-VERSION
X-PERF
X-Datadome
X-B3-Spanid
X-ApacheServer
X-NewRelic-App-Data
X-Request-Time
X-Source
X-Nginx-Cache
X-Agile-Id
X-Ua
X-Agile-Age
X-Agile
User-Agent
X-OVcl-Cache
Cache-Name
X-Origin
X-OVcl
X-Hit
X-VCT
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Edge-Location
Warning
X-App-Version
DSUID
SRV
X-ElasticPress-Search
X-Origin-TTL
X-WPE-Loopback-Upstream-Addr
X-Origin-CC
X-Request-UUID
X-Refresh
Fly-Cache
X-Region-Sid
X-Cache-Info
Ec-Rule-Version
Cross-Origin-Window-Policy
X-Connection-Hash
Arc-Country
X-Rewrite-Enabled
Ajk
X-Platform
X-Processor
X-Rojux
X-Pubstack
X-CF-Lambda-Version
X-CF-Lambda-Fn
Cache-Prefix
BehaviorPad-Version
X-S-Cookie
X-Cache-Miss-From
Memcached
UCS
X-Matched-Rule
Www
X-A
Thinkindot-Control
Thinkindot-CacheControl-Type
X-B-Cookie
X-Mobile-URL
Thinkindot-CacheControl
X-A-Ccd
X-A-Dam
X-Aed
X-ARC
X-Application
X-Logtrace-Id
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dgt
X-A-Wwc
Server-Surrogate-Control
Server-Cache-Control
MD5-Digest
Meta-Geo-Continent
X-NX-Host
Lfy
X-Cache-ASPX
X-PAYTM-SRV-ID
X-Cache-Grace
X-Cache-Expires
Node
X-NU-AKA-ACS-Version
Request-Country
Request-EU
Request-Time
Rendered-Blocks
X-BB-ID
X-NodeID
On-Server
Origin
Fly-Request-Id
X-Ocache
X-Debug-Log
X-Transaction
X-G
X-Destination
X-Twitter-Response-Tags
X-Debug-Cookies
X-Debug-Cache-Fetch
X-Gannett-Site-Version
X-Webstats-RespID
X-Debug-Cache-Store
X-Developer
Xc-Version
X-Var-Ttl
X-DPWN-IS-SECURE
X-Thinkindot-L3
X-Hp-Webp
X-External-Request-Id
X-IN-WAF
X-Up
X-Edge-IP
X-F5-Cache
Hostname
X-Debug-Cache-Expiry
X-Trv-Group
X-D
X-Sedo-Request-Id
X-Secret
X-Instart-Isnd
X-Server-Group
X-ScT
X-IN-APIGATEWAY
X-Core-Value
X-Generated-In
X-Varnish-Authentication
X-Date
X-VG-WebServer
X-SRCache-Key
X-Varnish-Ttl
Cache
User-Cache-Control
X-Cache-Backend
X-Geo-Header
X-Gen-Mode
X-Cache-Bucket
True-Client-Country-4JS
X-SN
X-ServiceProvider
IsBot
Kp-EeAlive
X-Reboot
X-Block-Status
X-C
Pagetype
ServerName
Proxy-Connection
Pramga
Server-Int
Web-Mar-Node
RNT-Machine
Server-Host
X-Swa-Ws
X-Nginx-Cache-Key
FNAC-ModuleRouting
X-Key
X-LAGOON
RNT-Time
X-Irp-Debug
X-Info
X-No-Session
X-Micro-Cache
Fastly-SIE
X-Protected-By
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Sucuri-Cache
X-Ah-Environment
X-Policy
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Sf
X-Servername
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Crawler
X-Request-URI
X-Amzn-Remapped-Connection
X-RateLimit-Remaining-Second
X-Location
X-Qloud-Router
X-Amzn-Remapped-Date
X-RateLimit-Limit-Second
HA-Ipaddr
X-CGP
X-Distil-CS
X-PHP-Host
X-Dispatcher-Server
X-Device-Os
X-Cache-Id
Fastly-SWR
Ha-Gx-Prefs
X-Eu-Site
X-Page-Type
X-TT-LOGID
Cache-Cookie-Set-From
X-Hnp-Log
CDCHOST
Cache-Cookie-Set-Lfrom
X-SIPLIST1
Cache-Cookie-Set-Idcheck
X-Cdn-Srv
X-Developers
Cteonnt-Length
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Pagespeed
X-Hash
X-Generated-On
X-Epic-Correlation-Id
X-Cache-Host
X-Distributor
X-Level-Front-Cache
X-LI-Proto
X-Cms-Context
X-Li-Pop
X-Li-Fabric
X-Cache-Debug
X-Bip
X-Backend-State
X-Backend-Host
X-Backend-Url
X-BBXSRF
X-LI-UUID
X-Fastly-Cache
X-Auto-Login
Country-Code
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Skip-Cache
Fastly-Backend-Name
Fastly-SSL
Fastly-Soc-X-Request-Id
Backend
AKAMAI
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Amzn-Remapped-Content-Length
X-Via-SSL
X-Server-IP
Adler-Geo
X-Via-Edge
X-Varnish-Url
Content-Disposition
Platform
X-Thanos
X-MSEdge-Flight
X-Variation
X-MSEdge-Features
X-TrackingId
X-User
N-Cache
X-Origin-Date
Heartbleed
X-Origin-Expires
HTTPS
Magicmarker
Is-Eu
X-Cdn-Forward
X-GZip
X-NC
X-FireWall-Port
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Gateway-Skip-Cache
Gh-Request-Id
X-RateLimit-Reset
X-Fetched-On
X-Gateway-Cache-Key
X-GeoIP-City
X-Gateway-Cache-Status
X-GeoIP-Country-Code
X-ShardId
X-Core-Mission
X-Server-Time
X-S-Maxage
X-Cache-FS-Status
X-Alternate-Cache-Key
SD-X-WS
X-Amz-Meta-Cache-Control
X-ShopId
X-Shopify-Stage
X-Real-Ip
MIME-Version
X-Sn-Servicetimems
X-Cdn-Origin
X-Owner
X-Apm-Svc-Key
X-Node-Id
X-Apm-App-Name
X-Apm-Inst-Hash
X-CDN-Forward
V-Age
X-Org
Server-ID
X-ND-Cache
REQUESTUUID
Rt-Proxy-Cache
X-FPC
X-Geo
X-Varnish-Beresp-Ttl
X-Pjax-Url
X-Exp-Se
X-Served-From
Viewtype
Powered-By
VivaBuild
X-CUA
X-Gdpr
HostName
X-Aicache-OS
X-Load-Cache
X-B3-Parentspanid
Pragrma
Section-Io-Cache
X-Parent-Response-Time
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Original-Request
X-Dc
X-Passed-To
X-Returned-From
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Svr
X-Actual-URL
X-Returned-From-BeforeDispatch
X-Server-By
X-Stale
X-Passed-To-PostProcessResponse
X-DC
X-Git-Hash
X-VServer
PICS-Label
Host-ID
X-HS-Cache-Config
Wxu-Next-Commit
Time
X-Croise-Owner
X-CSRF-TOKEN
Wxu-Next-Hostname
Memory
Wxu-Next-Region
CF-IPCountry
X-Nc
X-CACHE-KEY
Cdn-Host
Cdn-Request-Time
X-Servedbyhost
X-Edge-Server
Fastcgi-Useragent
X-Unique-ID
Resin-Trace
X-Wa
X-Host-Name
X-Oss-Object-Type
X-Oss-Request-Id
X-Microcachable
X-Release
SID
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Tb-Optimization-Total-Bytes-Saved
X-Optimization
ProcessTime
X-Cache-HT
Mime-Version
X-Newrelic-Synthetics
AR-SID
X-Lb-Id
X-TH-Server
X-WebServer
X-From-Cache
XServer
X-Phone
X-Daa-Tunnel
X-V
X-Req
X-Varnish-Beresp-TTL
Cf-Ipcountry
X-Upstream-HT
X-Instart-Info
Cdn
X-Upstream-CT
Odigeo-Trace-Id
X-Atg-Version
CF-Cached-On
Processtime
Proxy-Firewall
X-HTML-Minification-Powered-By
Backend-Name
X-APP
X-Fastly-Backend-Reqs
X-WR-MODIFICATION
X-ID
X-Worker
X-Fstrz
X-Ratelimit-Remaining
X-Vcl-Version
X-Response-By
X-LB-ID
X-B3-SpanId
X-Backend-TTL
X-Ratelimit-Limit
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
X-Server-W
X-IPS-LoggedIn
Xxline
355prline
GMS-Ver
409pxxline
225prxHost
219prxHost
X-Check-Cacheable
352pxline
189phosttRef
X-Nananana
188prxHost
286prxHost
X-NGINX-Cache
178proxuri
X-Zone
Version
Public-Key-Pins-Report-Only
X-Vcache
WZWS-RAY
Esi-Enabled
X-VCL-Version
X-UPSTREAM-Address
Fastcgi-X-Cache-Version
X-URL
X-Ratelimit-Reset
X-WA
X-Contensis-Viewer-Groups
X-Akamai-Request-ID2
Geoip-Latitude
X-GEO
GW-Server
GeoIp-Country-Code
X-Hyper-Cache
X-CSRF-Token
X-Amz-Meta-Surrogate-Control
Pics-Label
X-ServedByHost
SN
X-HS-Status
Accept-Language
DataCenter
Geoip-City
X-AssetVersion
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
X-We-Are-Hiring
Countrycode
Lb
X-Fastly-Country-Code
X-SERVER-NAME
X-UE-Client-Country
X-Clientip
Mobile-Detection-Method
X-Dynatrace
X-ZONE
X-Vtex-Processado-Em
SS
X-Vtex-Remote-Cache
X-Request-Start
X-Request-Handler-Origin-Region
X-Render-Time
X-Be
X-Microsite
X-BE
X-Via-Ucdn
WP-Super-Cache
Ohc-File-Size
X-Reqid
X-GDPR
URI
X-CS
CDN
X-Via-NSCOPI
X-RequestId
X-Cdn-Cache
X-LiteSpeed-Cache-Control
X-NWS-UUID-VERIFY
X-GZIP
X-Unique-Id
FSS-Proxy
X-PJAX-URL
X-Gen-Id
X-ABtesting
X-Flog
X-Hello
Locale
X-Urbn-Context-Path
FSS-Cache
X-HS-Combine-CSS
X-Urbn-Site-Id
X-PF-Uncompressing
X-HostName
Dynatrace
Amp-Access-Control-Allow-Source-Origin
X-FORWARDED-FOR
FastCGI-Cache
X-SRV
Dnion-Transfer-Encoding
X-Pf-Uncompressing
X-Fpc
X-Generation-Time
X-Fastly-Cache-Hits
Serverid
Cneonction
RequestUuid
IBM-Web2-Location
X-Cache-Ttl
X-LiteSpeed-Tag
X-Request-Url
Server-Id
X-Test
Accept-Ch
Ohc-Cache-HIT
A
X-Html-Edge-Cache
X-Store
X-NGENIX-Cache
X-Akamai-SSL-Client-Sid
RequestId
Requestid
X-Compress-Hint
X-Dw-Trace-Id
X-Requestid
X-Port
Frontcache
Get-Access-Time
Is-Session-Tracking
Ohc-Response-Time
X-HTML-Edge-Cache
X-UCC
X-ServerName
NnCoection
X-Cdn-Request-ID
X-Serial
X-EC-Lua