Every header contains the hash of the previous block. That hash covers the previous header, which itself contains the hash of the block before, and so on back to the genesis block of 3 January 2009.
Pull one thread
Suppose someone changes one transaction in a block from last year. Its Merkle root changes, so its header changes, so its hash changes. The next block, which recorded the old hash, no longer points to it. To make the chain whole again, every following block would need a new valid proof of work.
That is why depth is safety. An old block is buried under all the work done since, and redoing that work while the rest of the network keeps adding blocks is out of reach of anyone who does not control most of the hashing power.
▶ SEE IT IN THE MACHINEOn the BLOCKCHAIN rail, each block slides into a slot the previous block opens: the tenon is the previous hash.