Iframe Header Checker
Inspect X-Frame-Options and CSP frame-ancestors for a public URL. Enter your parent origin to check whether its embedding policies allow it.
Checking response headers…
Fetching the public response. This can take a few seconds.
Response headers & redirects
Two headers decide who can embed a page
X-Frame-Options: DENY prevents framing. SAMEORIGIN permits it only when the ancestor pages share the target’s origin. The obsolete ALLOW-FROM value is not a reliable way to allow a partner.
Content-Security-Policy: frame-ancestors supports an explicit allowlist. An enforced frame-ancestors directive takes precedence over X-Frame-Options in modern browsers. If multiple CSP policies are returned, every policy must allow the parent.
What this check can tell you
The server requests a public page without your cookies or login, follows up to five redirects, and returns relevant headers from the final response. It checks the parent origin you enter, not a complete nested ancestor chain. Report-only CSP is shown for context and does not block framing.
Other returned headers, including Permissions-Policy, COEP, and COOP, are informational. They are not treated as a simple “embedding passed” score. Your page’s own CSP frame-src directive, browser privacy settings, and authentication still need testing in the browser.
Why can the result differ from my browser?
Sites can vary their response by location, user agent, cookies, or bot protection. An HTTP error response may have different headers from the intended page. A successful header check means only that the inspected policies allow it; use the live iframe tester and DevTools to confirm.