Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Request-ID
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Buckets
Upgrade
Xkey
X-CDN
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
Access-Control-Max-Age
X-Pass-Why
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
WPE-Backend
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
P3p
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
Server-Timing
Allow
X-Ac
X-Rq
X-Node
X-Host
X-Server-Id
Content-Location
Feature-Policy
X-CST
X-Cnection
X-Response-Time
Report-To
X-Backend-Server
X-Cloud-Trace-Context
EagleEye-TraceId
X-Application-Context
Surrogate-Control
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Url
X-Origin-Cache
X-Readtime
Request-Id
X-Rack-Cache
X-Type
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
X-Instart-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
NEL
X-Vhost
X-DynaTrace
X-Ruxit-JS-Agent
Pinterest-Generated-By
X-Mod-Pagespeed
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Px
X-Goog-Hash
X-Upstream-Env
Verso
X-Server-Name
X-HW
Accept-CH
X-Dispatcher
X-ESI
MS-Author-Via
AR-CACHE
X-VARITI-CCR
AR-ATIME
AR-PoweredBy
PB-RID
X-Mobile-Rewrite
PB-PID
Arc-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
X-DataStream-Cache-Status
X-ORACLE-DMS-RID
X-Cached
X-Version
X-Powered-By-Plesk
Public-Key-Pins
Content-MD5
Charset
X-Recruiting
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
Ar-Sid
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-TTL
X-PC
X-TtlSet
X-Vname
X-Ser
X-Amz-Server-Side-Encryption
X-Varnish-TTL
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Vcap-Request-Id
X-Forwarded-Proto
X-Trace
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-Server-ID
X-FTR-DC
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-Cdn
X-Goog-Stored-Content-Length
X-FTR-Expires
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Oracle-Dms-Rid
X-Amz-Meta-S3cmd-Attrs
S
X-Amz-Rid
X-SharePointHealthScore
DynaTrace
X-Fastly-Request-ID
X-VCache
X-Debug
TCN
X-Hits
Arr-Disable-Session-Affinity
X-Dw-Request-Base-Id
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Shield-Request-Id
SPIisLatency
SPRequestDuration
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Proxy
X-Akam-SW-Version
X-XRDS-Location
Access-Control-Request-Method
X-T
X-Powered-CMS
X-FTR-Cache-Host
X-SERVER
X-Goog-Storage-Class
X-Ttl
X-Id
X-Aspnet-Version
X-Acc-Meta-Resource-Type
Front-End-Https
Realpath
X-NF-Request-ID
Tracecode
X-MSEdge-Ref
X-Amzn-Trace-Id
Fastcgi-Cache
X-B3-TraceId
X-Dns-Prefetch-Control
X-Varnish-Age
X-Content-Type
X-N
X-Forwarded-For
Paypal-Debug-Id
X-Upstream
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Alternate-Protocol
X-B3-TraceId-Primal
X-Fastcgi-Cache
X-RateLimit-Remaining
X-Frontend
X-PressLabs-Stats
X-Logged-In
X-Content-Digest
X-HS-Hub-Id
X-HS-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
X-Cache-Key
X-Litespeed-Cache
X-Middleton-Display
Display
X-Srv
X-Sol
X-Hostname
X-Middleton-Response
X-B3-Traceid
Response
AMP-Access-Control-Allow-Source-Origin
X-Pad
X-Accel-Expires
X-Webkit-CSP
MicrosoftSharePointTeamServices
Host
Server-Name
X-Kinsta-Cache
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Analytics
Backend-Timing
X-Correlation-Id
X-Content-Options
X-LB-Cache
X-User-Agent
X-Debug-Info
X-Revision
X-Rid
X-IPLB-Instance
X-Cache-2
X-Amzn-RequestId
X-Activity-Id
X-Amz-Apigw-Id
X-Az
X-B3-Sampled
X-Cache-Hit
X-AppVersion
FilterID
Accept-Charset
Surrogate-Key
X-Grace
Refresh
X-Accel-Buffering
ServerID
X-Ruxit-Js-Agent
X-B
Powered-By-ChinaCache
X-CF-Powered-By
X-DIS-Request-ID
X-Page-Id
X-Whom
X-Request-Processing-Time
X-Request-Received
Server-Info
TP-Cache
TP-L2-Cache
Host-Header
MS-CV
X-PHP-Backend
X-Varnish-Backend
Cache-Status
X-Content-Security-Policy-Report-Only
X-Cached-By
Source
X-Kong-Proxy-Latency
VIX-Pulpo-Node
X-App-Environment
X-Akamai-Edgescape
X-Cache-Action
X-Amz-Replication-Status
X-Origin-Server
VIX-Pulpo-Upstream-Status
X-Kong-Upstream-Latency
X-TT
X-Framework
X-UA-Device-Type
X-Platform-Server
X-Cluster
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-F-Cache
X-Mobile
Access-Control-Allow-Method
X-Varnish-Grace
X-Content-Powered-By
X-FW-Static
X-Instance
X-Request-Guid
X-FW-Type
X-FW-Server
X-FW-Serve
X-Drupal-Cache-Tags
X-FW-Hash
X-FB-Debug
X-RateLimit-Limit
X-SS-Set-Cookie
X-FastCGI-Cache
X-Zen-Fury
PageSpeed
X-Geo-Country
X-Forwarded-Host
X-Oneagent-Js-Injection
X-Ezoic-Cdn
X-Cache-TTL
X-Handled-By
Edge-Cache-Tag
X-Magnolia-Registration
X-Shard
X-Node-Name
X-GUploader-UploadID
From-Origin
X-Varnish-Hostname
X-ATG-Version
X-Cache-Age
Cache-Tags
X-XRDS-LOCATION
X-TA-CDN-Provider
X-Varnish-Server
X-App-Server
X-BCube-Filmed-By
DC
Cleartype
X-Cache-Control
X-AOL-HN
Fastly-Restarts
Healthy
Upgrade-Insecure-Requests
X-Cache-Rule
Payment
X-Generated-By
X-Region
Server-Node
X-RequestSource
Filters
X-WebKit-CSP-Report-Only
X-Response-Served-From
X-Adobe-Loc
X-B-Cache
X-TX-ID
X-Adobe-Content
X-Signature
Country
CACHE
X-RTag
X-Tumblr-Pixel-2
Ms-Operation-Id
X-Storage
X-Tumblr-Pixel-1
X-GeoIP
X-UUID
NGB
X-VG-WebCache
Actual-Object-TTL
X-TT-TIMESTAMP
X-Redis-Cache
Webserver
X-Drupal-Cache-Contexts
X-Jobs
X-FW-Dynamic
Cache-Tv-Group
X-Varnish-Hits
X-Locale
Retry-After
X-Cacheable-TTL
X-Content-Age
Powered
GEO-INFO
ServedBy
Frame-Options
Liferay-Portal
X-Contextid
HitType
X-Guploader-Uploadid
X-WA-Info
X-Rendered-As
X-Seen-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Varnish-IP
X-Cache-TTL-Remaining
X-Via-JSL
X-Cache-NE
X-ProcessESI
S-Cnection
X-RemovedCookies
Eomportal-Instance
Nel
X-Upgrade-Enabled
X-Real-IP
Viewport
X-Esi
X-BACKEND-TTL
X-Cache-Server
X-Mode
X-Cache-Operation
Xserver
X-Wix-Server-Artifact-Id
X-Varnish-Cache-Hits
X-Cache-Var-Map
OT-Force-Account-Verify
X-Time
X-ES-SERVER
X-Is-Bot
X-Hl-Ver
X-Proxied
Mn-Server-Ip
X-RN-RSRV
X-Device-Type
X-Routing-Service
X-Zipkin-Id
X-Detected-As
Content-Style-Type
Meta-Geo
Machine
X-Cache-Var
X-Proto
Cache-Key
Cache-Hits
X-Cache-Enabled
X-From
Content-Script-Type
Load-Balancing
X-Path-Route
X-S
Datacenter
X-AWS-Id
X-Hosted-By
X-L-Path
X-FC-Vary-Parameters
X-FB-TRIP-ID
X-Cache-Config
X-Environment-Context
X-LJ-Flow-ID
X-VWS-Id
X-Tb
X-Proxy
X-VG-TLSProxy
X-Viewer-Country
X-Origin-Hint
X-Backend-Name
Webcakes-Region
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
Property-Id
Mail-Subject
NGX
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
We-Hiring
Vix-Hermes-Req-Id
TWC-Privacy
Access-Control-Request-Headers
L5d-Success-Class
X-Akamai-Transformed
NtCoent-Length
X-Birta-Cache-Post
X-Birta-Served
X-Debug-Cache
X-Format
X-EIG-Tracking-Id
X-Akamai-Request-ID
Now
DB-Nickname
Origin-Cache-Control
Origin-Edge-Control
X-Access
S-Rt
X-FW-Version
X-Labrador-Cache-Channel
X-TNCMS
X-Time-Microsecs
X-Tumblr-Pixel-3
X-Web-Node
X-Rocket-Nginx-Bypass
X-ServerID
X-Section
X-MP-GENERATED-AT
X-Loop
X-Origin-Response-Time
X-Newrelic-App-Data
X-RCS-CacheZone
Azure-Version
X-NCache
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-SiteName
X-OCL
X-JoinUs
X-Human
X-NWS-LOG-UUID
X-BYPASS-REASON
X-CCM
X-PCL
X-IP
X-Proxy-Build
X-Via-CDN
X-Via-Fastly
X-Xfnlog-Site
X-Vgn-Hpd-Reason
X-Varnish-Cacheable
X-Trace-Id
Selected-FE
X-ProxyCache-Key
Cache-Tag
X-Timing-Wait
X-Endurance-Cache-Level
X-ProxyCache-Status
X-Internal-Host
X-Generated
Uber-Trace-Id
X-Www-Served-By
X-Site-Version
X-Grey
X-Cache-Category-Id
X-Status
Decoy-Debug-TTL
Served-By
X-R9-Blue-Green-Version
Decoy-Debug-Status
Decoy-Debug-Key
X-Dynatrace-Js-Agent
X-GRACE
X-VC-Cache
X-UA
LB
X-Rule
X-Cache-Remote
X-UnsetCookies
X-CDN-Cache
X-EdgeConnect-Cache-Status
Release
ViewerVersion
X-Wix-Request-Id
X-TIME
AsisCache
X-Origin-Host
X-Cluster-Node
X-Sucuri-ID
Rt-Fastcgi-Cache
X-APP-VERSION
X-App-Name
X-B3-Spanid
X-Datadome
X-PERF
X-ApacheServer
X-Nginx-Cache
X-Request-Time
X-Source
X-NewRelic-App-Data
X-Agile
X-Agile-Age
X-Agile-Id
Cache-Name
X-OVcl-Cache
X-OVcl
X-Goog-Meta-Goog-Reserved-File-Mtime
User-Agent
X-Hit
X-Ua
X-Origin
X-VCT
Hostname
X-Edge-Location
Warning
DSUID
SRV
X-App-Version
X-WPE-Loopback-Upstream-Addr
X-Origin-TTL
X-ElasticPress-Search
X-Origin-CC
X-Accel-Expires-Debug
Ec-Rule-Version
X-D
X-Core-Value
X-BB-ID
X-A-Wwc
BehaviorPad-Version
X-Instart-Isnd
X-Cache-Info
X-B-Cookie
X-Date
X-CF-Lambda-Version
Cross-Origin-Window-Policy
X-Connection-Hash
X-Application
X-ARC
X-CF-Lambda-Fn
Cache-Prefix
X-Aed
X-Debug-Cookies
X-F5-Cache
X-External-Request-Id
X-G
X-Developer
X-Gannett-Site-Version
Fly-Cache
X-Ocache
X-DPWN-IS-SECURE
X-Cache-Expires
X-A-Dgt
X-Cache-Grace
Fly-Request-Id
X-Generated-In
X-Debug-Log
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-IN-WAF
Ajk
X-Destination
X-Cache-ASPX
X-Hp-Webp
X-IN-APIGATEWAY
Arc-Country
X-Thinkindot-L3
X-Var-Ttl
On-Server
X-Edge-IP
Origin
X-Up
UCS
X-Pubstack
Www
X-Processor
Thinkindot-CacheControl
X-A
Request-EU
X-Varnish-Authentication
Node
X-Refresh
X-Region-Sid
X-S-Cookie
X-Rojux
X-ScT
X-Server-Group
X-Sedo-Request-Id
X-Secret
X-Rewrite-Enabled
X-Trv-Group
X-Request-UUID
Thinkindot-Control
X-Transaction
X-Twitter-Response-Tags
Request-Country
X-A-Ccd
Thinkindot-CacheControl-Type
Request-Time
X-NX-Host
X-NU-AKA-ACS-Version
X-NodeID
X-A-Dam
X-VG-WebServer
Xc-Version
Memcached
Rendered-Blocks
X-SRCache-Key
MD5-Digest
X-A-Dcw
X-Webstats-RespID
X-Matched-Rule
X-Logtrace-Id
X-Platform
X-Cache-Miss-From
Meta-Geo-Continent
Server-Surrogate-Control
X-Mobile-URL
Lfy
X-PAYTM-SRV-ID
Server-Cache-Control
User-Cache-Control
X-Cache-Backend
X-Varnish-Ttl
Server-Int
X-Cache-Debug
X-Cache-Bucket
Server-Host
ServerName
X-Cache-Host
X-Block-Status
X-Cache-Id
Web-Mar-Node
X-C
True-Client-Country-4JS
X-Amzn-Remapped-Connection
X-Origin-Date
X-Qloud-Router
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Proxy-Cache-Status
X-Protected-By
X-Origin-Expires
X-Page-Type
X-PHP-Host
X-Policy
X-Rebelmouse-Surrogate-Control
X-Request-URI
X-Varnish-Url
FNAC-ModuleRouting
X-Reboot
X-ServiceProvider
X-TT-LOGID
X-Swa-Ws
X-Servername
X-Sf
X-SIPLIST1
X-SN
X-No-Session
X-Nginx-Cache-Key
X-Epic-Correlation-Id
X-Distributor
X-Eu-Site
X-Gen-Mode
X-Geo-Header
X-Distil-CS
X-Dispatcher-Server
X-CGP
X-Crawler
X-Developers
X-Device-Os
X-Hash
X-Hnp-Log
X-LI-Proto
X-LI-UUID
X-Location
X-Micro-Cache
X-Li-Pop
X-Li-Fabric
X-Info
X-Irp-Debug
X-Key
X-LAGOON
X-Cdn-Srv
X-Amzn-Remapped-Date
Fastly-SIE
Fastly-Backend-Name
CDCHOST
Fastly-SWR
Ha-Gx-Prefs
Kp-EeAlive
IsBot
HA-Ipaddr
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Apple-News-Services-Handled
X-Real-Ip
X-Sucuri-Cache
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Cache-Cookie-Set-From
Backend
Apple-News-Services-Request-Url
X-Ah-Environment
Country-Code
Proxy-Connection
Pramga
Pagetype
RNT-Machine
RNT-Time
Pagespeed
X-FireWall-Port
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Cteonnt-Length
AKAMAI
X-Generated-On
X-GeoIP-City
X-GeoIP-Country-Code
N-Cache
X-Cms-Context
X-Via-SSL
Platform
X-Core-Mission
Adler-Geo
X-Amzn-Remapped-Content-Length
X-S-Maxage
X-Fetched-On
X-Planisys-CDN-Cache
SD-X-WS
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Fastly-Cache
X-TrackingId
X-Variation
X-Planisys-CDN-Rules
X-Level-Front-Cache
Content-Disposition
X-Planisys-CDN-TTL
X-Via-Edge
X-MSEdge-Flight
X-MSEdge-Features
X-Auto-Login
Heartbleed
X-Backend-State
X-Backend-Url
X-Wikidot-Static-Cache
X-BBXSRF
X-ShardId
X-ShopId
Is-Eu
X-Skip-Cache
Magicmarker
X-Shopify-Stage
HTTPS
X-Amz-Meta-Cache-Control
X-Alternate-Cache-Key
X-Bip
X-Backend-Host
X-Cache-FS-Status
Fastly-SSL
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-User
X-Server-IP
X-Thanos
Fastly-Soc-X-Request-Id
X-Wikidot-Backend
X-GZip
X-Cdn-Forward
Cache
X-Server-Time
X-Owner
Gh-Request-Id
X-RateLimit-Reset
X-Node-Id
V-Age
X-Apm-Svc-Key
X-Apm-Inst-Hash
X-Apm-App-Name
X-Sn-Servicetimems
Server-ID
X-NC
X-Cdn-Origin
X-CDN-Forward
X-Geo
X-ND-Cache
X-FPC
X-Org
MIME-Version
REQUESTUUID
Rt-Proxy-Cache
X-Exp-Se
X-Varnish-Beresp-Ttl
X-Pjax-Url
X-CUA
VivaBuild
X-Served-From
Viewtype
Powered-By
X-Gdpr
X-Dc
X-B3-Parentspanid
X-Load-Cache
X-Aicache-OS
Pragrma
Section-Io-Cache
X-Stale
X-Original-Request
X-Svr
X-Passed-To-DLL
X-Returned-From-BeforeDispatch
X-Returned-From
HostName
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Passed-To-BeforeDispatch
X-Server-By
X-Passed-To-PostProcessResponse
X-Passed-To
X-Nc
X-Actual-URL
X-Parent-Response-Time
X-VServer
X-Croise-Owner
X-HS-Cache-Config
Host-ID
X-Git-Hash
X-CSRF-TOKEN
Wxu-Next-Region
PICS-Label
Wxu-Next-Hostname
Memory
Wxu-Next-Commit
Time
X-DC
X-CACHE-KEY
Resin-Trace
Cdn-Request-Time
X-Edge-Server
Cdn-Host
CF-IPCountry
Mime-Version
X-Servedbyhost
X-Wa
X-Unique-ID
Fastcgi-Useragent
X-Host-Name
X-Microcachable
X-Oss-Request-Id
X-Oss-Server-Time
X-Release
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
SID
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-HT
X-Newrelic-Synthetics
X-Optimization
ProcessTime
AR-SID
X-WebServer
X-Lb-Id
X-From-Cache
X-TH-Server
Cf-Ipcountry
X-Daa-Tunnel
X-Varnish-Beresp-TTL
X-Req
X-V
Cdn
X-Phone
Odigeo-Trace-Id
X-Upstream-HT
X-Upstream-CT
X-Instart-Info
X-Atg-Version
Processtime
XServer
Proxy-Firewall
X-HTML-Minification-Powered-By
X-APP
Backend-Name
X-Fastly-Backend-Reqs
CF-Cached-On
X-ID
X-Fstrz
X-Worker
X-Vcl-Version
X-WR-MODIFICATION
X-Ratelimit-Remaining
X-B3-SpanId
X-Backend-TTL
X-LB-ID
352pxline
X-Zone
X-Nananana
178proxuri
188prxHost
225prxHost
219prxHost
189phosttRef
355prline
409pxxline
Xxline
286prxHost
X-Response-By
X-Server-W
X-Ratelimit-Limit
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
GMS-Ver
X-IPS-LoggedIn
Version
Public-Key-Pins-Report-Only
X-Vcache
X-NGINX-Cache
X-WA
WZWS-RAY
Esi-Enabled
X-UPSTREAM-Address
X-CSRF-Token
X-ServedByHost
X-Ratelimit-Reset
Fastcgi-X-Cache-Version
X-URL
X-Akamai-Request-ID2
Accept-Language
X-VCL-Version
SN
GeoIp-Country-Code
X-Contensis-Viewer-Groups
X-AssetVersion
GW-Server
Geoip-Latitude
X-GEO
X-HS-Status
Pics-Label
X-Amz-Meta-Surrogate-Control
X-Hyper-Cache
DataCenter
GeoIP-Country-Code
X-SERVER-NAME
GeoIP-City
X-Fastly-Country-Code
Mobile-Detection-Method
Lb
GeoIP-Latitude
X-UE-Client-Country
Countrycode
X-We-Are-Hiring
X-Clientip
Geoip-City
X-Dynatrace
X-BE
X-Vtex-Processado-Em
X-Request-Handler-Origin-Region
X-Request-Start
X-Vtex-Remote-Cache
X-Microsite
SS
X-Via-Ucdn
X-Render-Time
X-Be
X-RequestId
WP-Super-Cache
Ohc-File-Size
X-Urbn-Context-Path
X-LiteSpeed-Cache-Control
X-Urbn-Site-Id
X-ZONE
Locale
X-Reqid
X-NWS-UUID-VERIFY
X-CS
URI
X-GDPR
X-Via-NSCOPI
X-Unique-Id
X-GZIP
X-Flog
X-Gen-Id
FSS-Cache
FSS-Proxy
X-PF-Uncompressing
X-Hello
X-PJAX-URL
X-ABtesting
X-Cdn-Cache
CDN
X-HS-Combine-CSS
Dynatrace
X-HostName
Amp-Access-Control-Allow-Source-Origin
X-SRV
FastCGI-Cache
X-FORWARDED-FOR
X-Generation-Time
IBM-Web2-Location
X-Fpc
Dnion-Transfer-Encoding
X-Fastly-Cache-Hits
Serverid
RequestUuid
Cneonction
X-Pf-Uncompressing
X-Cache-Ttl
X-Store
X-Request-Url
X-Html-Edge-Cache
Accept-Ch
A
Server-Id
X-Test
Ohc-Cache-HIT
X-LiteSpeed-Tag
X-Akamai-SSL-Client-Sid
Get-Access-Time
RequestId
Requestid
X-ServerName
X-Dw-Trace-Id
Is-Session-Tracking
X-Serial
Frontcache
X-EC-Lua
X-HTML-Edge-Cache
X-Port
NnCoection
X-UCC
X-Cdn-Request-ID
Ohc-Response-Time