HSTS - Browser HTTPS Only  
                 Download List of All Websites using HSTS - Browser HTTPS Only  
                 
                The HTTP Strict-Transport-Security response header (often abbreviated as HSTS) lets a web site tell browsers that it should only be accessed using HTTPS, instead of using HTTP for 15552000 seconds
             
               
                         
                
                
               
                X-Frame-Options Header
                 Download List of All Websites using X-Frame-Options Header
                 
                The X-Frame-Options HTTP response header can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>. Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.
             
               
                         
                
                
               
                Vary Header Accept-Encoding
                 Download List of All Websites using Vary Header Accept-Encoding
                 
                The Accept-Encoding request HTTP header advertises which content encoding, usually a compression algorithm, the client is able to understand. Using content negotiation, the server selects one of the proposals, uses it and informs the client of its choice with the Content-Encoding response header.
             
               
                
                
               Tags:
               
           
               
           
               
           
              
               
                         
                
                
               
                Block Content Sniffing
                 Download List of All Websites using Block Content Sniffing
                 
                The X-Content-Type-Options response HTTP header is a marker used by the server to indicate that the MIME types advertised in the Content-Type headers should not be changed and be followed. This allows to opt-out of MIME type sniffing, or, in other words, it is a way to say that the webmasters knew what they were doing.
             
               
                
                
               Tags: