Security Headers Generator

Generate HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, and an optional CSP — as Nginx or Apache config, checked against real syntax rules for both.

About this tool

Every header combination here has been checked against the real Nginx and Apache binaries during development, including a genuinely easy-to-miss gotcha: Nginx's add_header doesn't inherit from a parent block into a nested location block that defines its own add_header lines — you have to repeat them. The CSP section is deliberately the most cautious part of this tool, built from direct experience: a CSP that works fine on a simple page can silently break ads, fonts, or any third-party script the moment you deploy it, so it ships off by default and the presets are intentionally conservative. See How to use ProxyForge for a walkthrough of every setting and where the output goes.

How it works

STEP 1

Pick Nginx or Apache, then toggle the headers you want — HSTS, frame protection, MIME sniffing, referrer policy, permissions.

STEP 2

Optionally enable a CSP preset — read the warning first, since this is the one header that can genuinely break things if misconfigured.

STEP 3

Copy the result into your existing server block — this is a snippet to add alongside your config, not a replacement for it.

Forces browsers to always use HTTPS for this domain.
Adds the flag required to submit your domain at hstspreload.org for browsers' built-in preload lists (it also requires includeSubDomains, so that's switched on automatically). Hard to fully undo once accepted — only enable this if you're certain every subdomain will always be HTTPS.

Prevents clickjacking by controlling whether your pages can be embedded in an iframe.
Stops browsers from guessing file types in a way attackers can exploit.
Controls how much of your URL gets sent to other sites when someone clicks a link away from your page.
Disables browser features your site almost certainly doesn't use — reduces attack surface from any third-party script that gets injected.

nginx-headers.conf ✓ Verified: Nginx 1.27.x

Need to validate your full setup?

Once headers are live, check them for real:

SSL.com EV, OV, and wildcard certificates with manual domain validation. Get started
UptimeRobot Free uptime monitoring — get alerted if a config change takes your site down. Get started
Vultr Simple cloud servers with a wide range of data center locations. Get started

Some links above are affiliate links — signing up through them may earn this site a small commission at no extra cost to you. See the privacy policy for details.