X-Frame-Options / Clickjacking Checker
Check if X-Frame-Options and CSP frame-ancestors block framing.
Paste response headers
Clickjacking analysis
- warnCSP is present but has no frame-ancestors directive.
- goodX-Frame-Options: SAMEORIGIN
Recommended headers
About the X-Frame-Options / Clickjacking Checker
Paste response headers to evaluate whether X-Frame-Options and CSP frame-ancestors actually block your page from being embedded in an iframe, detect conflicts between the two, and get recommended headers.
Examples
No protection
Content-Type: text/htmlOutput
Framing is NOT blockedKeyboard shortcuts
- Copy the main outputCtrl / ⌘ + Shift + C
- Download the resultCtrl / ⌘ + S
- Share this toolCtrl / ⌘ + Shift + S
- Reset the inputsAlt + R
- Open the tool search paletteCtrl / ⌘ + K
Related tools
CORS Config Generator
Security
Generate CORS headers/config for Nginx, Apache, Express, or Workers.
CSP Builder
Security
Build a Content-Security-Policy header from per-directive sources.
Permissions-Policy Header Generator
Security
Build a Permissions-Policy header controlling camera, geolocation and more.
Referrer Policy Generator
Security
Pick a Referrer-Policy value and get header/meta/server snippets.
Robots.txt Security Checker
Security
Scan robots.txt for accidental disclosure of sensitive paths.
Security Headers Auditor
Security
Grade HTTP response headers against security best practices.
Frequently asked questions
Version 1.0.0 · Updated 2026-08-10 · Runs entirely in your browser