The add-in should be able to run in iFrame to work in Outlook Web, so the X-Frame-Options header should not be included at all. ALLOW-FROM cannot be used because the number of domains in the list is more than 3, and this list is growing - there are many cases when different users access Office365 and outlook.com using custom domains.
source
share