https://stackoverflow.com/questions/...e-on-my-domain
good explanation of the issues.
If you can send the SAMEORIGIN headers with a software other that the server software for specific pages -- that would work well.
added:
https://www.owasp.org/index.php/Clic...se_Cheat_Sheet
here are some more ideas