Increase for file uploads (e.g. 50M, 100M)
Sets server_tokens off
Generates an HTTP → HTTPS redirect block
Requires HTTPS — improves load times
Strict-Transport-Security header
31536000 = 1 year
Submit to browser preload lists — irreversible
nosniff — prevents MIME sniffing
Legacy XSS filter for older browsers
Restricts resource loading