Hi @EvertonSa2,
Looking into the screenshot you shared you are using AEM as a Cloud Service.
In AEM as a Cloud Service, security headers are injected via Adobe's edge CDN (even for publish URLs like https://publish-<env>.adobeaemcloud.com), not by the application code directly.
Also, you should test...