Nginx sets response headers with add_header. Here is a copy-paste server block for HSTS, X-Frame-Options, nosniff and more — plus the inheritance trap that silently drops your headers inside a location block.
Apache sets headers with mod_headers. Here is a copy-paste config for HSTS, X-Frame-Options, nosniff and more — and why you want Header always set rather than Header set.
Proxied through Cloudflare? Add HSTS, X-Frame-Options, Referrer-Policy and more at the edge with Managed Transforms and Transform Rules — no origin changes required.
The security headers that actually matter, what each one does, and copy-paste values to get you started. No fluff, just the headers you need.