Prevent foreign embedding stops other websites from loading your redirected hostnames inside a frame or iframe. That protects your visitors against clickjacking, where a malicious page overlays your content with invisible elements, and keeps your hostnames from being shown inside someone else's page.
What we send
With the setting enabled, redirect.pizza adds the following headers to the responses of your hostnames:
X-Frame-Options: DENY Content-Security-Policy: default-src 'self' X-XSS-Protection: 1; mode=block
You can check whether a hostname sends them with the redirect tester.
Enabling it
Enable prevent foreign embedding for all hostnames on the Settings page of your team:

Or override the team setting for a specific hostname:

This setting is about your hostnames being framed by others. It's unrelated to the frame redirect type, which frames your destination on your own hostname.