Header set X-Content-Type-Options "nosniff" Strict-Transport-Security: max-age= Strict-Transport-Security: max-age=; includeSubDomains Strict-Transport-Security: max-age=; includeSubDomains; preload