Inspect the response you actually use
Security headers can reduce specific browser risks. Their usefulness depends on correct configuration and application behaviour. A header checklist is not a complete security audit, and presence alone does not prove that a policy is effective.
For your own website, request headers with:
curl -I --max-time 15 https://your-domain.example/Replace the example domain. On Windows PowerShell, use curl.exe to explicitly invoke curl on systems where curl is a shell alias.
Watch redirects and methods
The first response might be a redirect. Add -L if you want to follow it, and distinguish each response block from the final destination. A HEAD request can behave differently from GET. If HEAD is unsupported, inspect a GET response while discarding the body:
curl -sS -D - -o /dev/null --max-time 15 https://your-domain.example/On Windows, use NUL instead of /dev/null. Do not attach session cookies or tokens to a command you will publish.
Review important fields
Look for Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options and Referrer-Policy. Also inspect cache controls on private or authenticated responses. Each serves a different purpose: script-source restrictions, HTTPS persistence, MIME interpretation and referrer disclosure are not interchangeable.
A CSP allowing every source or extensive unsafe behaviour can be weak despite its presence. HSTS should be deployed only when the covered hosts are ready for HTTPS; an unreviewed includeSubDomains or preload decision can break access.
Verify with the browser
Use developer tools to inspect the main document response and any console policy violations. Test actual navigation, forms and required scripts after a change. A report-only CSP helps observe violations but does not enforce blocking.
Common mistakes
Reading a redirect's headers as the final page's policy produces the wrong conclusion. Cloudflare or another proxy can add or modify headers, so the public response matters. Do not remove security controls simply to silence an error without identifying the blocked dependency.
Keep the outcome specific
Record URL, response status, method and the relevant policy values. Recommend a change for a concrete risk, then test the application. Do not give a site a perfect security score solely because several header names appear.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.