October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
clickjacking

X-Frame-Options Test: Check Clickjacking Protection Header

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To test clickjacking protection, inspect the HTTP response headers for the page you want to protect. Look for X-Frame-Options and the Content Security Policy (CSP) frame-ancestors directive; do not rely on page source or a <meta> tag. DENY blocks framing, while SAMEORIGIN permits only same-origin ancestors. A missing X-Frame-Options header is not automatically a vulnerability because an enforced CSP frame-ancestors policy may provide the control instead.

What the X-Frame-Options test actually checks

X-Frame-Options is an HTTP response header that tells a browser whether a document may be rendered inside a <frame>, <iframe>, <embed> or <object>. Framing restrictions are a principal defense against clickjacking, where an attacker places your page beneath an interface the victim can see and click.

The test answers one narrow question: what policy did this particular HTTP response send? It does not prove that every route, subdomain, deployment environment, redirect target or browser behaves identically. Check the pages that handle sensitive actions, not just the home page.

Interpret the header values

Response value Meaning Practical assessment
X-Frame-Options: DENY The document should not be rendered in any frame, including a same-origin frame. Use when the page never needs embedding.
X-Frame-Options: SAMEORIGIN Embedding is allowed only when the relevant ancestor frames have the same origin as the document. Suitable for applications that embed their own pages.
X-Frame-Options: ALLOW-FROM https://example.com An obsolete directive that modern browsers may ignore. Do not use it as a current allowlist mechanism; use CSP frame-ancestors.
No X-Frame-Options header No XFO policy was observed in that response. Inspect CSP frame-ancestors before concluding that framing is unrestricted.

Header names are case-insensitive, but the value and whether the header is actually present in the final response matter. A response from a CDN, reverse proxy, authentication gateway or error handler can differ from the application response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to check X-Frame-Options with cURL

Inspect a normal GET response

A GET request is usually more representative than a HEAD request because some servers generate different headers for HEAD. This command prints response headers while discarding the body:

curl -sS -D - -o /dev/null https://example.com/

Search the output for lines beginning with X-Frame-Options: and Content-Security-Policy:. Header matching is case-insensitive. If the response contains CSP, inspect its value for frame-ancestors, for example:

Content-Security-Policy: default-src 'self'; frame-ancestors 'none'

Follow redirects and retain every response

Login redirects, canonical-host redirects and HTTP-to-HTTPS upgrades can hide which response you are evaluating. Use:

curl -sS -L -D headers.txt -o /dev/null https://example.com/

Open headers.txt and separate each response at its status line (such as HTTP/2 301 or HTTP/2 200). The final document response is normally the one that controls the rendered page, but an intermediate response can still reveal a configuration problem. If you need to see the redirect chain interactively, add -v:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -sS -L -v -o /dev/null https://example.com/

Check a route that requires authentication

Public and authenticated pages often pass through different middleware. Supply an appropriate cookie or authorization header only in a controlled environment, and never paste production credentials into shared logs:

curl -sS -D - -o /dev/null 
  -H 'Authorization: Bearer YOUR_TOKEN' 
  https://example.com/account/settings

Compare the result with the unauthenticated response. A login page, 403 response or 500 error may be generated by another layer and may not carry the same policy as the application page.

Check the header in browser developer tools

  1. Open the exact URL in a current browser.
  2. Open Developer Tools and select the Network panel.
  3. Reload the page with the Network panel open.
  4. Select the document request, usually shown as type document or Doc.
  5. In Headers, expand Response Headers.
  6. Read x-frame-options and content-security-policy. Use the response associated with the page itself, not an image, script or stylesheet.

Repeat the check after a redirect and on important routes. DevTools shows what your browser received; it does not tell you whether another geographic edge, protocol, user agent or cache variant sends a different response.

Verify that the policy is in an HTTP response, not HTML

This is invalid as a framing defense:

<meta http-equiv="X-Frame-Options" content="DENY">

Browsers do not enforce X-Frame-Options when it is supplied through a meta element. The directive must be an HTTP response header. Likewise, viewing an HTML source file or a server configuration file alone cannot establish what a user actually receives; inspect the wire response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test the real framing behavior

Header inspection is the reliable first check, but a controlled iframe test can expose routing or browser-specific surprises. Host this temporary page on a different origin from the target and replace the URL:

<!doctype html>
<title>Frame test</title>
<iframe src="https://example.com/" width="800" height="600"></iframe>

With DENY, the target should refuse to render in the iframe. With SAMEORIGIN, a page hosted on another origin should be refused, while a page hosted on the same origin may load. A refusal can appear as a blank frame or a browser console message; do not treat the visual appearance alone as proof of the exact directive. Capture the response headers as evidence.

X-Frame-Options versus CSP frame-ancestors

Policy flexibility

X-Frame-Options has two useful modern choices: block all framing with DENY, or allow same-origin framing with SAMEORIGIN. CSP frame-ancestors can name specific parent origins, so it is the appropriate control when a site must allow selected partners rather than every same-origin page.

Content-Security-Policy: frame-ancestors 'none'

frame-ancestors 'none' is similar to X-Frame-Options: DENY. A more selective policy can list permitted sources, such as an exact scheme, host and optional port. The directive evaluates each ancestor, which matters when frames are nested.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When both headers are present

Modern browsers that support CSP frame-ancestors use that directive and ignore X-Frame-Options for the framing decision. Historical browser versions differed and could follow X-Frame-Options instead. If your audience includes legacy clients, document the intended fallback and test those clients explicitly rather than claiming universal precedence.

Enforced versus report-only CSP

A policy in Content-Security-Policy-Report-Only reports violations but does not block framing. For protection, verify that frame-ancestors appears in the enforced Content-Security-Policy response header.

A small automated check in Python

This script follows redirects, prints every response in the chain, and reports the final response’s relevant headers. Install the requests package first if necessary.

import requests

url = "https://example.com/"
response = requests.get(url, allow_redirects=True, timeout=30)

for item in response.history + [response]:
    print(f"{item.status_code} {item.url}")
    for name, value in item.headers.items():
        if name.lower() in {"x-frame-options", "content-security-policy", "content-security-policy-report-only"}:
            print(f"  {name}: {value}")

xfo = response.headers.get("X-Frame-Options")
csp = response.headers.get("Content-Security-Policy", "")
print("Final X-Frame-Options:", xfo or "(missing)")
print("Final frame-ancestors:", "frame-ancestors" in csp.lower())

The script reports presence, not whether your entire site is consistently configured. Extend it with a list of sensitive URLs and run it from the network locations and authentication states that matter to your deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A small automated check in Node.js

Node.js 18 and later include fetch. This example uses the default redirect-following behavior and prints the final response:

const url = 'https://example.com/';
const res = await fetch(url, { redirect: 'follow' });

console.log(res.status, res.url);
for (const [name, value] of res.headers) {
  const key = name.toLowerCase();
  if (key === 'x-frame-options' ||
      key === 'content-security-policy' ||
      key === 'content-security-policy-report-only') {
    console.log(`${name}: ${value}`);
  }
}

console.log('X-Frame-Options:', res.headers.get('x-frame-options') ?? '(missing)');
console.log('CSP:', res.headers.get('content-security-policy') ?? '(missing)');

If you need every redirect response in Node.js, request each Location yourself with redirect: 'manual' and record the headers before following it. This avoids mistaking a redirect response for the final document.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common test failures and fixes

The command shows no X-Frame-Options

Check the enforced CSP header for frame-ancestors. If it is absent too, determine whether the page is intentionally embeddable, whether a proxy stripped the header, or whether only another route sets it. Test the final response after redirects.

You tested with curl -I but the browser differs

Some servers vary HEAD and GET responses. Repeat the test with curl -D - -o /dev/null using GET, then compare status, cookies, user agent and redirect behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The page is framed despite an apparent protection header

Confirm that the header belongs to the framed document, not the outer page. Check for duplicate or malformed values, inspect the final response, and look for a CSP frame-ancestors policy that changes the effective decision. Test from the actual parent origin and examine the browser console.

ALLOW-FROM appears to work on one browser

That directive is obsolete and modern browsers may ignore it. Replace it with an enforced CSP frame-ancestors allowlist, retaining a deliberate fallback only if legacy-client requirements justify it.

The header appears in a configuration file but not in the response

A configuration file is not evidence of delivery. Check the public response through the same CDN, load balancer, authentication layer and protocol that users reach. Correct the layer that removes or overwrites the header.

A security scanner reports a missing header on an error page

Inspect the status and body. Error pages, login redirects and gateway responses may be generated separately. Decide whether those responses can be framed and configure the responsible layer consistently.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text

Reliability, scope and operational checks

  • Check more than the home page: include login, account, payment, administrative and other state-changing routes.
  • Check each deployment: staging, production, alternate hostnames and both HTTP and HTTPS redirect paths can differ.
  • Check cache variants: CDNs may cache an old policy or vary responses by cookie, user agent or geography.
  • Check nested ancestors: CSP frame-ancestors evaluates every ancestor, not only the immediate parent.
  • Do not overclaim: framing protection limits one attack class; it is not a complete application security assessment. SameSite cookies can add a partial mitigation, but they do not replace an explicit framing policy.

Or skip the browser setup

If you also need a clean visual capture of a page after checking its headers, ScreenshotNeo can render it through one API request. It does not replace header inspection—the response headers still need cURL, DevTools or code—but it avoids maintaining a browser for repeatable screenshots.

cURL (see the ScreenshotNeo API documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

What this test does not prove

A successful observation proves that one response sent a particular framing policy at one time. It does not establish that all pages, browser paths, origins, cookies or environments are protected, and it does not assess authorization, cross-site request forgery, script injection or other security controls. Treat X-Frame-Options and CSP frame-ancestors as focused clickjacking defenses within a broader review.

Frequently Asked Questions

Does X-Frame-Options affect a page opened normally in a browser tab?

No. The header governs whether the document may be embedded as a frame, embed or object; it does not prevent ordinary top-level navigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I use a wildcard in X-Frame-Options to allow several partner sites?

No current X-Frame-Options value provides a reliable multi-origin allowlist. Use an enforced CSP frame-ancestors policy with the specific permitted sources.

Should I remove X-Frame-Options when I deploy CSP?

Not automatically. Keep a deliberate fallback when legacy-browser support matters, and test the combination against the browsers your audience actually uses.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.