Content-Security-Policy: default-src https: X-XSS-Protection: 1; mode=block # Block site from being framed with X-Frame-Options and CSP Content-Security-Policy: frame-ancestors 'none' X-Frame-Options: DENY