Replicating Managed Transform HTTP Headers on Apache

I’m using Managed Transforms > HTTP response headers.

But I have DNS records that are :grey: for certain purposes. I want to replicate these headers for them on my origin. I’m on the Apache server. I know my question may not be strictly related to Cloudflare but there is probably someone here who has done this before. These are the headers I was able to form:

Header set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header set X-XSS-Protection "1; mode=block"
Header set X-Content-Type-Options nosniff
Header set X-Frame-Options SAMEORIGIN
Header set Referrer-Policy same-origin
  1. Apache creates 2 VirtualHosts for each domain, one with port 80 and the other with port 443). I want to know if any of these headers are forbidden in either 80 or 443 port vhosts. In other words, can and should I put them in both?
  2. Some people suggest adding the always condition to headers.
  3. Instead of using set, append can be used for some of the headers, like X-Frame-Options SAMEORIGIN.
  4. Is my syntax correct for the listed headers?

I need clarification on each of these things. I conducted a thorough search online without finding a good conversation on this topic.

2 posts were merged into an existing topic: Replicating Managed Transform HTTP Headers for :grey: Records on Apache