Disable direct IP access. Use wildcard certificates. Don't use guessable subdomains like www or mail.