Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-AspNet-Version
X-Xss-Protection
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Request-ID
X-Cacheable
Content-Security-Policy-Report-Only
X-Cache-Status
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Template
X-Language
Status
X-Iinfo
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
X-Backend
X-Cache-Group
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
P3p
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Pingback
X-Server
X-Via
X-Proxy-Cache
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
WPE-Backend
X-Varnish-Cache
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
X-Page-Speed
EagleId
X-UA-Device
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-WebKit-CSP
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
Ali-Swift-Global-Savetime
Allow
Server-Timing
X-Ac
X-Rq
X-Node
X-Host
X-CST
Content-Location
Feature-Policy
X-Cnection
X-Response-Time
X-Server-Id
Report-To
X-Type
X-Backend-Server
X-Cloud-Trace-Context
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Iejgwucgyu
X-ORACLE-DMS-ECID
X-Url
X-Readtime
X-Origin-Cache
Request-Id
X-Rack-Cache
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
NEL
X-Instart-Request-ID
X-Vhost
X-DynaTrace
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Pinterest-Generated-By
X-Origin-Upstream-Status
X-DataDome
X-Px
Edge-Control
X-Upstream-Env
X-Goog-Hash
Verso
X-Server-Name
X-ESI
Accept-CH
X-HW
X-Dispatcher
MS-Author-Via
X-VARITI-CCR
AR-ATIME
AR-CACHE
AR-PoweredBy
X-GitHub-Request-Id
X-DataStream-Cache-Status
PB-PID
X-MS-InvokeApp
X-Mobile-Rewrite
PB-RID
Arc-Version
X-ORACLE-DMS-RID
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Cached
X-Version
Charset
Content-MD5
X-Powered-By-Plesk
Public-Key-Pins
X-Recruiting
X-Server-ID
X-Dns-Prefetch-Control
Service-Worker-Allowed
AR-Request-ID
Accept-CH-Lifetime
RTSS
Ar-Sid
X-Abt-Application-Version
X-D2id
X-Navigation-Version
X-Vname
X-PC
X-TtlSet
X-Ser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-TTL
X-Varnish-TTL
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
X-Trace
X-Forwarded-Proto
X-Client-IP
SPRequestGuid
X-DynaTrace-JS-Agent
Nginx-Cache
X-FTR-Balancer
X-FTR-Realm
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-DC
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-FTR-Expires
X-Amz-Rid
X-VCache
X-Fastly-Request-ID
X-SharePointHealthScore
S
X-Amz-Meta-S3cmd-Attrs
X-Debug
X-Oracle-Dms-Rid
TCN
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-Hits
DynaTrace
X-TEC-API-ORIGIN
X-Dw-Request-Base-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-XRDS-Location
X-Ttl
X-Upstream-Proxy
X-Pinterest-Rid
Pinterest-Version
SPIisLatency
SPRequestDuration
X-Akam-SW-Version
Access-Control-Request-Method
X-Goog-Storage-Class
X-FTR-Cache-Host
X-T
X-Powered-CMS
Front-End-Https
X-NF-Request-ID
X-SERVER
X-Acc-Meta-Resource-Type
Tracecode
Realpath
X-Id
X-Amzn-Trace-Id
X-MSEdge-Ref
X-B3-TraceId
X-Aspnet-Version
Fastcgi-Cache
X-N
X-Varnish-Age
Paypal-Debug-Id
X-Content-Type
X-Forwarded-For
X-Upstream
X-B3-TraceId-Primal
Alternate-Protocol
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-RateLimit-Remaining
X-Frontend
X-Logged-In
X-PressLabs-Stats
X-HS-Content-Id
X-Fastcgi-Cache
X-HS-Hub-Id
Fusion-Source
X-Content-Digest
Fusion-Template-Id
X-Sol
Fusion-Component-Id
Display
X-Middleton-Display
Fusion-Content-Id
Fusion-Content-Source
Response
X-Middleton-Response
AMP-Access-Control-Allow-Source-Origin
X-Hostname
X-Litespeed-Cache
X-Srv
X-B3-Traceid
X-Pad
X-Accel-Expires
X-Cache-Key
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Accel-Buffering
Server-Name
Host
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Analytics
X-User-Agent
Backend-Timing
X-Content-Options
X-Correlation-Id
X-Debug-Info
X-LB-Cache
X-Revision
X-Az
X-AppVersion
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Activity-Id
X-Rid
X-IPLB-Instance
Refresh
X-Cdn
Accept-Charset
FilterID
X-B3-Sampled
X-Cache-2
X-Cache-Hit
Surrogate-Key
Powered-By-ChinaCache
X-B
X-DIS-Request-ID
X-CF-Powered-By
X-Grace
ServerID
X-Ruxit-Js-Agent
X-Page-Id
X-Whom
Server-Info
TP-Cache
TP-L2-Cache
X-PHP-Backend
MS-CV
X-Request-Received
X-Request-Processing-Time
Host-Header
X-FastCGI-Cache
X-Cached-By
X-Content-Security-Policy-Report-Only
Cache-Status
Source
VIX-Pulpo-Node
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Backend
X-TT
X-Origin-Server
VIX-Pulpo-Upstream-Status
X-Amz-Replication-Status
X-Framework
X-UA-Device-Type
X-App-Environment
X-Cluster
X-Akamai-Edgescape
X-Cache-Action
X-Platform-Server
X-Webkit-CSP
Access-Control-Allow-Method
X-Mobile
X-Content-Powered-By
X-FW-Serve
X-Request-Guid
X-Tumblr-User
X-Tumblr-Pixel-0
X-Drupal-Cache-Tags
X-Tumblr-Pixel
X-Varnish-Grace
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Hash
X-F-Cache
X-Instance
X-Zen-Fury
X-FB-Debug
X-SS-Set-Cookie
X-RateLimit-Limit
X-Geo-Country
X-Shard
X-Ezoic-Cdn
X-Handled-By
X-GUploader-UploadID
X-Forwarded-Host
X-Cache-TTL
X-Magnolia-Registration
Edge-Cache-Tag
From-Origin
X-Node-Name
X-ATG-Version
PageSpeed
X-Cache-Age
X-Varnish-Hostname
X-App-Server
Cache-Tags
DC
X-Varnish-Server
Cleartype
X-BCube-Filmed-By
X-AOL-HN
CACHE
X-Cache-Control
X-XRDS-LOCATION
Payment
Healthy
Upgrade-Insecure-Requests
X-Generated-By
Filters
X-WebKit-CSP-Report-Only
X-Region
X-Response-Served-From
X-RequestSource
Fastly-Restarts
X-Adobe-Content
Server-Node
X-Adobe-Loc
X-TX-ID
Cache-Tv-Group
X-Cache-Rule
Webserver
X-RTag
Country
X-Storage
X-TT-TIMESTAMP
X-VG-WebCache
X-UUID
X-GeoIP
X-Redis-Cache
Ms-Operation-Id
NGB
Retry-After
X-Jobs
X-Signature
X-FW-Dynamic
X-B-Cache
X-Drupal-Cache-Contexts
Actual-Object-TTL
X-Cacheable-TTL
X-Tumblr-Pixel-2
X-Content-Age
X-Tumblr-Pixel-1
X-Locale
X-Varnish-Hits
GEO-INFO
X-TA-CDN-Provider
ServedBy
Powered
Liferay-Portal
X-Contextid
Frame-Options
X-Seen-By
X-Wix-Server-Artifact-Id
HitType
X-Rendered-As
X-Oneagent-Js-Injection
X-Via-JSL
X-Cache-TTL-Remaining
X-Guploader-Uploadid
X-Varnish-IP
X-WA-Info
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Real-IP
X-BACKEND-TTL
S-Cnection
Viewport
X-RemovedCookies
X-ProcessESI
Eomportal-Instance
X-Upgrade-Enabled
X-Cache-NE
X-Cache-Server
NtCoent-Length
Content-Style-Type
Content-Script-Type
X-Mode
Xserver
Nel
X-Esi
Datacenter
X-GRACE
X-Cache-Config
X-Akamai-Transformed
X-From
X-Proto
X-Proxied
X-ES-SERVER
X-Detected-As
X-Routing-Service
X-RN-RSRV
X-Time
X-Cache-Var-Map
X-Varnish-Cache-Hits
X-Cache-Var
X-Device-Type
X-Path-Route
X-Hl-Ver
Machine
Meta-Geo
Mn-Server-Ip
X-Is-Bot
X-S
X-Zipkin-Id
Load-Balancing
Cache-Hits
Cache-Key
OT-Force-Account-Verify
TWC-Device-Class
Property-Id
TWC-Locale-Group
TWC-GeoIP-Country
X-Environment-Context
TWC-GeoIP-LatLong
X-Cache-Operation
Webcakes-Region
Access-Control-Request-Headers
L5d-Success-Class
Vix-Hermes-Req-Id
We-Hiring
X-Tb
Webcakes-App-Version
Webcakes-App-Name
Mail-Subject
X-AWS-Id
TWC-Privacy
X-FC-Vary-Parameters
X-Origin-Hint
X-LJ-Flow-ID
X-Viewer-Country
X-Cache-Enabled
TWC-Connection-Speed
X-Hosted-By
X-VWS-Id
X-VG-TLSProxy
X-L-Path
Azure-RegionName
Azure-SiteName
X-Origin-Response-Time
X-Proxy
X-Access
Azure-SlotName
Azure-InstanceId
X-Web-Node
Origin-Edge-Control
X-Labrador-Cache-Channel
S-Rt
Origin-Cache-Control
X-Loop
X-FB-TRIP-ID
X-Backend-Name
NGX
Azure-Version
X-Akamai-Request-ID
X-Debug-Cache
X-Section
X-FW-Version
X-Birta-Cache-Post
X-EIG-Tracking-Id
X-Format
X-TNCMS
X-Time-Microsecs
X-Endurance-Cache-Level
X-ServerID
X-Birta-Served
X-Proxy-Build
X-Timing-Wait
Now
X-NCache
X-ProxyCache-Key
X-Trace-Id
X-OCL
X-Via-CDN
Cache-Tag
X-IP
X-JoinUs
Selected-FE
X-Xfnlog-Site
X-Human
X-Varnish-Cacheable
X-CCM
X-ProxyCache-Status
X-BYPASS-REASON
X-Via-Fastly
X-PCL
DB-Nickname
X-Status
X-Cache-Category-Id
X-Rocket-Nginx-Bypass
X-Tumblr-Pixel-3
X-Vgn-Hpd-Reason
X-Grey
X-Www-Served-By
X-Site-Version
X-Generated
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
X-NWS-LOG-UUID
Uber-Trace-Id
ViewerVersion
X-MP-GENERATED-AT
X-Wix-Request-Id
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Internal-Host
X-VC-Cache
Served-By
X-CDN-Cache
X-EdgeConnect-Cache-Status
X-Newrelic-App-Data
X-Rule
X-Dynatrace-Js-Agent
X-UA
X-Cache-Remote
X-NewRelic-App-Data
LB
AsisCache
Release
X-Origin-Host
X-UnsetCookies
X-Sucuri-ID
X-Cluster-Node
Rt-Fastcgi-Cache
X-TIME
X-App-Name
Pagespeed
X-ApacheServer
X-PERF
User-Agent
X-Source
X-APP-VERSION
X-Nginx-Cache
X-Agile-Id
X-Agile-Age
X-Agile
X-Request-Time
X-B3-Spanid
X-Ua
X-Datadome
Hostname
Cache-Name
X-App-Version
X-Edge-Location
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OVcl-Cache
X-Hit
X-Origin
X-OVcl
X-VCT
X-Pubstack
Warning
X-Edge-IP
X-Origin-TTL
X-Origin-CC
Fly-Request-Id
X-NodeID
Ec-Rule-Version
Fly-Cache
Arc-Country
X-NX-Host
Node
Meta-Geo-Continent
MD5-Digest
X-Generated-In
X-NU-AKA-ACS-Version
X-Gannett-Site-Version
X-IN-WAF
X-IN-APIGATEWAY
Cache-Prefix
Ajk
X-Sucuri-Cache
BehaviorPad-Version
X-Ocache
Cross-Origin-Window-Policy
X-Hp-Webp
X-Instart-Isnd
X-Logtrace-Id
X-Mobile-URL
X-Developer
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Date
X-D
X-Debug-Cache-Store
X-Aed
X-A-Wwc
X-Accel-Expires-Debug
X-Debug-Cookies
X-Application
X-ARC
X-CF-Lambda-Fn
X-Cache-ASPX
X-Cache-Expires
X-Cache-Grace
X-CF-Lambda-Version
X-BB-ID
X-B-Cookie
X-Core-Value
X-Connection-Hash
X-A-Dgt
X-A-Dcw
Request-EU
Request-Time
X-DPWN-IS-SECURE
Server-Cache-Control
Request-Country
Rendered-Blocks
Origin
X-G
X-External-Request-Id
Server-Surrogate-Control
Thinkindot-CacheControl
Www
X-A
X-A-Ccd
X-A-Dam
X-Debug-Log
X-Destination
Thinkindot-CacheControl-Type
Thinkindot-Control
UCS
On-Server
X-Matched-Rule
X-SRCache-Key
X-Protected-By
Xc-Version
X-Rewrite-Enabled
X-Server-Group
X-Processor
X-ScT
X-Varnish-Beresp-Status
X-Request-UUID
X-Rojux
X-Region-Sid
X-Secret
X-Varnish-Beresp-Grace
X-Platform
X-S-Cookie
X-Varnish-Authentication
X-Thinkindot-L3
X-Twitter-Response-Tags
X-Up
X-Var-Ttl
X-Transaction
X-Trv-Group
X-VG-WebServer
X-PAYTM-SRV-ID
User-Cache-Control
X-Cache-Backend
X-ElasticPress-Search
Proxy-Connection
X-Servername
Pramga
Pagetype
X-Eu-Site
Lfy
Memcached
Kp-EeAlive
IsBot
X-Gen-Mode
Magicmarker
X-ServiceProvider
X-CGP
N-Cache
X-Sedo-Request-Id
X-Crawler
Web-Mar-Node
X-Swa-Ws
X-Developers
True-Client-Country-4JS
X-Amzn-Remapped-Date
X-WPE-Loopback-Upstream-Addr
X-Varnish-Url
X-Amzn-Remapped-Connection
X-Cdn-Forward
X-TT-LOGID
X-SN
X-Device-Os
X-Distributor
RNT-Time
RNT-Machine
X-Epic-Correlation-Id
X-SIPLIST1
Server-Host
SRV
X-Dispatcher-Server
Server-Int
X-Distil-CS
X-Sf
X-Block-Status
X-LAGOON
X-Key
X-Cache-Debug
X-Proxy-Upstream
X-Li-Pop
X-Li-Fabric
X-Qloud-Router
X-Irp-Debug
Apple-News-Services-Request-Url
Heartbleed
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-LI-Proto
X-LI-UUID
X-Nginx-Cache-Key
X-Cache-Host
X-No-Session
X-Page-Type
X-Origin-Date
X-Origin-Expires
X-Webstats-RespID
X-Cache-Miss-From
X-Policy
X-Proxy-Cache-Status
X-F5-Cache
X-PHP-Host
X-Cache-Id
Backend
X-RateLimit-Limit-Second
Fastly-SIE
X-Hnp-Log
Fastly-Backend-Name
X-Request-URI
X-RateLimit-Remaining-Second
X-Hash
Fastly-SWR
Ha-Gx-Prefs
HA-Ipaddr
X-Geo-Header
X-C
X-Cache-Info
X-Refresh
Country-Code
X-Rebelmouse-Cache-Control
Cache-Cookie-Set-Lfrom
X-Reboot
CDCHOST
X-Rebelmouse-Surrogate-Control
X-Info
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Varnish-Ttl
DSUID
X-FireWall-Port
X-Cache-Bucket
X-Wikidot-Backend
X-Via-Edge
X-Wikidot-Static-Cache
X-Via-SSL
X-Core-Mission
X-Gateway-Cache-Status
X-GeoIP-City
X-Generated-On
X-Gateway-Skip-Cache
X-S-Maxage
X-GeoIP-Country-Code
X-Level-Front-Cache
X-MSEdge-Flight
X-MSEdge-Features
X-Micro-Cache
X-Location
X-Gateway-Cache-Key
X-Server-IP
X-Sorting-Hat-ShopId
X-Thanos
X-TrackingId
X-User
X-Sorting-Hat-PodId
X-Skip-Cache
X-Fetched-On
X-ShardId
X-ShopId
X-Shopify-Stage
X-Variation
X-Cms-Context
AKAMAI
X-Real-Ip
Adler-Geo
X-Cache-FS-Status
X-Amz-Meta-Cache-Control
Content-Disposition
Fastly-Soc-X-Request-Id
Is-Eu
Platform
HTTPS
SD-X-WS
Fastly-SSL
X-CACHE-KEY
X-Alternate-Cache-Key
X-BBXSRF
X-Bip
X-Amzn-Remapped-Content-Length
X-Ah-Environment
X-Backend-State
Cteonnt-Length
X-Owner
X-Fastly-Cache
X-Planisys-CDN-Cache
X-Cdn-Srv
ServerName
X-Planisys-CDN-Rules
X-Backend-Url
X-Server-Time
FNAC-ModuleRouting
X-Planisys-CDN-TTL
X-Node-Id
X-Auto-Login
X-Backend-Host
X-Varnish-Beresp-Ttl
X-GZip
X-RateLimit-Reset
Server-ID
X-Org
Section-Io-Cache
Gh-Request-Id
X-CUA
Powered-By
X-Nc
X-CDN-Forward
X-Apm-Svc-Key
X-Pjax-Url
VivaBuild
X-Sn-Servicetimems
X-Cdn-Origin
X-Load-Cache
Pragrma
X-FPC
V-Age
REQUESTUUID
X-Apm-App-Name
Viewtype
X-Apm-Inst-Hash
MIME-Version
Cache
X-NC
X-Dc
X-Passed-To-BeforeDispatch
X-Returned-From
X-Passed-To
X-Returned-From-BeforeDispatch
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Geo
X-ND-Cache
X-Original-Request
X-Returned-From-DLL
X-Stale
X-Svr
X-Returned-From-PostProcessResponse
X-Parent-Response-Time
X-Exp-Se
X-Actual-URL
Fastcgi-Useragent
Rt-Proxy-Cache
X-Server-By
X-Aicache-OS
X-VServer
Host-ID
X-Gdpr
X-HS-Cache-Config
X-Served-From
X-Croise-Owner
X-Ua-Device
HostName
X-CSRF-TOKEN
X-Unique-ID
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-B3-Parentspanid
PICS-Label
Time
Memory
X-Microcachable
Mime-Version
X-DC
X-Git-Hash
X-Wa
X-Servedbyhost
Resin-Trace
Wxu-Next-Commit
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
SID
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Wxu-Next-Hostname
Wxu-Next-Region
ProcessTime
X-Newrelic-Synthetics
X-V
X-From-Cache
X-Req
X-Tb-Optimization-Total-Bytes-Saved
CF-IPCountry
X-ID
X-Cache-HT
Cf-Ipcountry
X-Optimization
AR-SID
X-Release
Cdn
Odigeo-Trace-Id
X-Lb-Id
X-Host-Name
X-TH-Server
X-WebServer
X-HTML-Minification-Powered-By
X-Varnish-Beresp-TTL
CF-Cached-On
X-Fstrz
X-Phone
X-Daa-Tunnel
X-Atg-Version
Proxy-Firewall
XServer
Processtime
X-Instart-Info
X-APP
X-Response-By
X-Upstream-HT
X-Upstream-CT
Public-Key-Pins-Report-Only
X-WR-MODIFICATION
X-Vcl-Version
Backend-Name
GMS-Ver
X-LB-ID
X-Ratelimit-Remaining
X-Check-Cacheable
WZWS-RAY
X-Worker
X-Ratelimit-Limit
X-Fastly-Backend-Reqs
X-Zone
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
Fastcgi-X-Cache-Version
X-GEO
188prxHost
178proxuri
X-B3-SpanId
286prxHost
219prxHost
X-Server-W
225prxHost
409pxxline
189phosttRef
Xxline
352pxline
355prline
X-WA
X-NGINX-Cache
X-Backend-TTL
X-Amz-Meta-Surrogate-Control
X-Nananana
X-IPS-LoggedIn
X-Vcache
Version
X-ServedByHost
X-Clientip
Pics-Label
X-HS-Status
X-CSRF-Token
X-We-Are-Hiring
Countrycode
X-UE-Client-Country
GW-Server
X-Ratelimit-Reset
X-URL
Mobile-Detection-Method
Lb
SN
X-Fastly-Country-Code
X-UPSTREAM-Address
GeoIp-Country-Code
X-Hyper-Cache
Esi-Enabled
Geoip-Latitude
SS
WP-Super-Cache
DataCenter
Ohc-File-Size
X-VCL-Version
X-SERVER-NAME
X-Contensis-Viewer-Groups
Geoip-City
X-AssetVersion
X-Akamai-Request-ID2
X-Dynatrace
X-SRV
Accept-Language
X-GZIP
X-PF-Uncompressing
X-Be
FSS-Proxy
X-HS-Combine-CSS
X-Request-Start
GeoIP-City
GeoIP-Country-Code
URI
FSS-Cache
GeoIP-Latitude
X-Render-Time
X-Via-Ucdn
X-BE
Serverid
X-CS
X-GDPR
X-NWS-UUID-VERIFY
X-LiteSpeed-Cache-Control
X-Vtex-Remote-Cache
X-RequestId
X-Vtex-Processado-Em
X-Unique-Id
X-Via-NSCOPI
Ohc-Cache-HIT
X-Reqid
Locale
X-ZONE
X-Fpc
X-Gen-Id
X-PJAX-URL
X-Urbn-Site-Id
X-Urbn-Context-Path
CDN
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
X-HostName
FastCGI-Cache
Dynatrace
X-Hello
X-ABtesting
X-Flog
X-Request-Handler-Origin-Region
X-Microsite
X-Pf-Uncompressing
X-Html-Edge-Cache
RequestUuid
X-Fastly-Cache-Hits
X-UCC
Cneonction
X-Cdn-Cache
X-Cache-Ttl
X-LiteSpeed-Tag
X-Varnish-Action
Accept-Ch
Who
X-Store
A
X-Generation-Time
Server-Id
IBM-Web2-Location
X-Request-Url
Dnion-Transfer-Encoding
X-Akamai-SSL-Client-Sid
X-Cache-URL
X-Dw-Trace-Id
Get-Access-Time
X-ServerName
NnCoection
Frontcache
X-HTML-Edge-Cache
X-Serial
Ohc-Response-Time
X-Cdn-Request-ID
X-EC-Lua
Is-Session-Tracking
X-Port