Generate HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, and an optional CSP — as Nginx or Apache config, checked against real syntax rules for both.
Every header combination here has been checked against the real Nginx and Apache binaries during development, including a genuinely easy-to-miss gotcha: Nginx's add_header doesn't inherit from a parent block into a nested location block that defines its own add_header lines — you have to repeat them. The CSP section is deliberately the most cautious part of this tool, built from direct experience: a CSP that works fine on a simple page can silently break ads, fonts, or any third-party script the moment you deploy it, so it ships off by default and the presets are intentionally conservative. See How to use ProxyForge for a walkthrough of every setting and where the output goes.
Pick Nginx or Apache, then toggle the headers you want — HSTS, frame protection, MIME sniffing, referrer policy, permissions.
Optionally enable a CSP preset — read the warning first, since this is the one header that can genuinely break things if misconfigured.
Copy the result into your existing server block — this is a snippet to add alongside your config, not a replacement for it.
Once headers are live, check them for real:
Some links above are affiliate links — signing up through them may earn this site a small commission at no extra cost to you. See the privacy policy for details.