What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To test clickjacking protection, inspect the HTTP response headers for the page you want to protect. Look for X-Frame-Options and the Content Security Policy (CSP) frame-ancestors directive; do not rely on page source or a <meta> tag. DENY blocks framing, while SAMEORIGIN permits only same-origin ancestors. A missing X-Frame-Options header is not automatically a vulnerability because an enforced CSP frame-ancestors policy may provide the control instead.
What the X-Frame-Options test actually checks
X-Frame-Options is an HTTP response header that tells a browser whether a document may be rendered inside a <frame>, <iframe>, <embed> or <object>. Framing restrictions are a principal defense against clickjacking, where an attacker places your page beneath an interface the victim can see and click.
The test answers one narrow question: what policy did this particular HTTP response send? It does not prove that every route, subdomain, deployment environment, redirect target or browser behaves identically. Check the pages that handle sensitive actions, not just the home page.
Interpret the header values
| Response value | Meaning | Practical assessment |
|---|---|---|
X-Frame-Options: DENY |
The document should not be rendered in any frame, including a same-origin frame. | Use when the page never needs embedding. |
X-Frame-Options: SAMEORIGIN |
Embedding is allowed only when the relevant ancestor frames have the same origin as the document. | Suitable for applications that embed their own pages. |
X-Frame-Options: ALLOW-FROM https://example.com |
An obsolete directive that modern browsers may ignore. | Do not use it as a current allowlist mechanism; use CSP frame-ancestors. |
| No X-Frame-Options header | No XFO policy was observed in that response. | Inspect CSP frame-ancestors before concluding that framing is unrestricted. |
Header names are case-insensitive, but the value and whether the header is actually present in the final response matter. A response from a CDN, reverse proxy, authentication gateway or error handler can differ from the application response.
#1 Best Overall
How to check X-Frame-Options with cURL
Inspect a normal GET response
A GET request is usually more representative than a HEAD request because some servers generate different headers for HEAD. This command prints response headers while discarding the body:
curl -sS -D - -o /dev/null https://example.com/
Search the output for lines beginning with X-Frame-Options: and Content-Security-Policy:. Header matching is case-insensitive. If the response contains CSP, inspect its value for frame-ancestors, for example:
Content-Security-Policy: default-src 'self'; frame-ancestors 'none'
Follow redirects and retain every response
Login redirects, canonical-host redirects and HTTP-to-HTTPS upgrades can hide which response you are evaluating. Use:
curl -sS -L -D headers.txt -o /dev/null https://example.com/
Open headers.txt and separate each response at its status line (such as HTTP/2 301 or HTTP/2 200). The final document response is normally the one that controls the rendered page, but an intermediate response can still reveal a configuration problem. If you need to see the redirect chain interactively, add -v:
Free tools Windows power users keep installed
One-click scans. No signup required.
curl -sS -L -v -o /dev/null https://example.com/
Check a route that requires authentication
Public and authenticated pages often pass through different middleware. Supply an appropriate cookie or authorization header only in a controlled environment, and never paste production credentials into shared logs:
curl -sS -D - -o /dev/null
-H 'Authorization: Bearer YOUR_TOKEN'
https://example.com/account/settings
Compare the result with the unauthenticated response. A login page, 403 response or 500 error may be generated by another layer and may not carry the same policy as the application page.
Check the header in browser developer tools
- Open the exact URL in a current browser.
- Open Developer Tools and select the Network panel.
- Reload the page with the Network panel open.
- Select the document request, usually shown as type document or Doc.
- In Headers, expand Response Headers.
- Read
x-frame-optionsandcontent-security-policy. Use the response associated with the page itself, not an image, script or stylesheet.
Repeat the check after a redirect and on important routes. DevTools shows what your browser received; it does not tell you whether another geographic edge, protocol, user agent or cache variant sends a different response.
Verify that the policy is in an HTTP response, not HTML
This is invalid as a framing defense:
<meta http-equiv="X-Frame-Options" content="DENY">
Browsers do not enforce X-Frame-Options when it is supplied through a meta element. The directive must be an HTTP response header. Likewise, viewing an HTML source file or a server configuration file alone cannot establish what a user actually receives; inspect the wire response.
Test the real framing behavior
Header inspection is the reliable first check, but a controlled iframe test can expose routing or browser-specific surprises. Host this temporary page on a different origin from the target and replace the URL:
<!doctype html>
<title>Frame test</title>
<iframe src="https://example.com/" width="800" height="600"></iframe>
With DENY, the target should refuse to render in the iframe. With SAMEORIGIN, a page hosted on another origin should be refused, while a page hosted on the same origin may load. A refusal can appear as a blank frame or a browser console message; do not treat the visual appearance alone as proof of the exact directive. Capture the response headers as evidence.
X-Frame-Options versus CSP frame-ancestors
Policy flexibility
X-Frame-Options has two useful modern choices: block all framing with DENY, or allow same-origin framing with SAMEORIGIN. CSP frame-ancestors can name specific parent origins, so it is the appropriate control when a site must allow selected partners rather than every same-origin page.
Content-Security-Policy: frame-ancestors 'none'
frame-ancestors 'none' is similar to X-Frame-Options: DENY. A more selective policy can list permitted sources, such as an exact scheme, host and optional port. The directive evaluates each ancestor, which matters when frames are nested.
When both headers are present
Modern browsers that support CSP frame-ancestors use that directive and ignore X-Frame-Options for the framing decision. Historical browser versions differed and could follow X-Frame-Options instead. If your audience includes legacy clients, document the intended fallback and test those clients explicitly rather than claiming universal precedence.
Enforced versus report-only CSP
A policy in Content-Security-Policy-Report-Only reports violations but does not block framing. For protection, verify that frame-ancestors appears in the enforced Content-Security-Policy response header.
A small automated check in Python
This script follows redirects, prints every response in the chain, and reports the final response’s relevant headers. Install the requests package first if necessary.
import requests
url = "https://example.com/"
response = requests.get(url, allow_redirects=True, timeout=30)
for item in response.history + [response]:
print(f"{item.status_code} {item.url}")
for name, value in item.headers.items():
if name.lower() in {"x-frame-options", "content-security-policy", "content-security-policy-report-only"}:
print(f" {name}: {value}")
xfo = response.headers.get("X-Frame-Options")
csp = response.headers.get("Content-Security-Policy", "")
print("Final X-Frame-Options:", xfo or "(missing)")
print("Final frame-ancestors:", "frame-ancestors" in csp.lower())
The script reports presence, not whether your entire site is consistently configured. Extend it with a list of sensitive URLs and run it from the network locations and authentication states that matter to your deployment.
Recommended Free Tools
A small automated check in Node.js
Node.js 18 and later include fetch. This example uses the default redirect-following behavior and prints the final response:
const url = 'https://example.com/';
const res = await fetch(url, { redirect: 'follow' });
console.log(res.status, res.url);
for (const [name, value] of res.headers) {
const key = name.toLowerCase();
if (key === 'x-frame-options' ||
key === 'content-security-policy' ||
key === 'content-security-policy-report-only') {
console.log(`${name}: ${value}`);
}
}
console.log('X-Frame-Options:', res.headers.get('x-frame-options') ?? '(missing)');
console.log('CSP:', res.headers.get('content-security-policy') ?? '(missing)');
If you need every redirect response in Node.js, request each Location yourself with redirect: 'manual' and record the headers before following it. This avoids mistaking a redirect response for the final document.
Rank #4
Common test failures and fixes
The command shows no X-Frame-Options
Check the enforced CSP header for frame-ancestors. If it is absent too, determine whether the page is intentionally embeddable, whether a proxy stripped the header, or whether only another route sets it. Test the final response after redirects.
You tested with curl -I but the browser differs
Some servers vary HEAD and GET responses. Repeat the test with curl -D - -o /dev/null using GET, then compare status, cookies, user agent and redirect behavior.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The page is framed despite an apparent protection header
Confirm that the header belongs to the framed document, not the outer page. Check for duplicate or malformed values, inspect the final response, and look for a CSP frame-ancestors policy that changes the effective decision. Test from the actual parent origin and examine the browser console.
ALLOW-FROM appears to work on one browser
That directive is obsolete and modern browsers may ignore it. Replace it with an enforced CSP frame-ancestors allowlist, retaining a deliberate fallback only if legacy-client requirements justify it.
The header appears in a configuration file but not in the response
A configuration file is not evidence of delivery. Check the public response through the same CDN, load balancer, authentication layer and protocol that users reach. Correct the layer that removes or overwrites the header.
A security scanner reports a missing header on an error page
Inspect the status and body. Error pages, login redirects and gateway responses may be generated separately. Decide whether those responses can be framed and configure the responsible layer consistently.
Best Value
- Comes with secure packaging
- It can be a gift item
- Easy to read text
Reliability, scope and operational checks
- Check more than the home page: include login, account, payment, administrative and other state-changing routes.
- Check each deployment: staging, production, alternate hostnames and both HTTP and HTTPS redirect paths can differ.
- Check cache variants: CDNs may cache an old policy or vary responses by cookie, user agent or geography.
- Check nested ancestors: CSP
frame-ancestorsevaluates every ancestor, not only the immediate parent. - Do not overclaim: framing protection limits one attack class; it is not a complete application security assessment. SameSite cookies can add a partial mitigation, but they do not replace an explicit framing policy.
Or skip the browser setup
If you also need a clean visual capture of a page after checking its headers, ScreenshotNeo can render it through one API request. It does not replace header inspection—the response headers still need cURL, DevTools or code—but it avoids maintaining a browser for repeatable screenshots.
cURL (see the ScreenshotNeo API documentation):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
What this test does not prove
A successful observation proves that one response sent a particular framing policy at one time. It does not establish that all pages, browser paths, origins, cookies or environments are protected, and it does not assess authorization, cross-site request forgery, script injection or other security controls. Treat X-Frame-Options and CSP frame-ancestors as focused clickjacking defenses within a broader review.
Frequently Asked Questions
Does X-Frame-Options affect a page opened normally in a browser tab?
No. The header governs whether the document may be embedded as a frame, embed or object; it does not prevent ordinary top-level navigation.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsCan I use a wildcard in X-Frame-Options to allow several partner sites?
No current X-Frame-Options value provides a reliable multi-origin allowlist. Use an enforced CSP frame-ancestors policy with the specific permitted sources.
Should I remove X-Frame-Options when I deploy CSP?
Not automatically. Keep a deliberate fallback when legacy-browser support matters, and test the combination against the browsers your audience actually uses.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




