Analyze HTTP response headers for security best practices
Or use: curl -I https://example.com
Strict-Transport-Security: max-age=31536000; includeSubDomainsX-Content-Type-Options: nosniffX-Frame-Options: DENY or SAMEORIGINReferrer-Policy: strict-origin-when-cross-origin