field Registered
Verified 2026-09-18 · registry updated 2026-08-28

X-Frame-Options

Controls whether a browser may render a response in a frame, iframe, embed, or object.

Prefer CSP frame-ancestors for modern applications, but use X-Frame-Options: DENY or SAMEORIGIN when legacy browser support requires it.

httpsecurityclickjackingheader

Reference (http)

X-Frame-Options: DENY

Prefer CSP frame-ancestors for modern applications, but use X-Frame-Options: DENY or SAMEORIGIN when legacy browser support requires it.

Common mistakes

  • Using ALLOW-FROM, which is obsolete and inconsistently supported, instead of CSP frame-ancestors.

IANA registry: http-fields/field-names

Registry reference: HTML

Permalink: https://merginit.com/reference/http/x-frame-options