What a visitor of each site on this server receives. Checked with a request to the server itself, refreshed every 10 minutes.
Web server version in responsesnginx
PHP version in responseshidden
TRACE methoddisabled
Site
HSTS
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
CSP
example.com
shop.example.com
Report-Only
app.example.com
—
Amber marks headers worth adding, grey marks nice-to-have ones. CSP cannot be switched on with one line: the policy is built for a specific site, otherwise the site stops loading its own scripts, styles and fonts. Report-Only means the policy is in observe mode.
One command adds what is missing: a separate file in conf.d, reloaded only after nginx -t. A server block with its own add_header ignores the shared lines, so add them to that block as well.