X-Frame-Options

HTTP response header

X-Frame-Options is an obsolete header to instruct the browser to allow rendering a page within a frame or iframe. The header is used to enable the Clickjacking protection.

Header usage statistics

X-Frame-Options response header information and usage statistics.
Websites using header X-Frame-Options10,416,169
Percentage of websites that use X-Frame-Options header12.89%
Total discovered header valuesMore than 10,000
Header uses directivesYes
Header values are unique or randomNo
Most popular in the country United States

X-Frame-Options directives (3 total)

  • allow-from
  • deny
  • sameorigin

X-Frame-Options Directives

X-Frame-Options directives value information and usage statistics
DirectiveShareWebsites countUnique Values
sameorigin81.73%8,512,8852
deny17.61%1,834,0641
allow-from<0.1%2,35028

Connected technologies

Technologies that utilize the header
Kajabi, category Ecommerce, total 18,377 websites
Contentful, category Content Management System, total 16,447 websites
Storyblok, category Content Management System, total 3,993 websites

X-Frame-Options header usage distribution by website rank



Geographical Distribution

Header usage distribution by websites across the globe.



Websites utilizing X-Frame-Options

List of websites that use X-Frame-Options header
DomainCountryRankContacts
www.facebook.com United States2
google.com United States3
www.google.com United States3
wordpress.org United States4
s.w.org United States5
youtube.com United States6
See full domain list

Common header values

List of top common X-Frame-Options header values
Header valueValue prevalence
SAMEORIGIN80.42%
DENY17.27%
ALLOWALL0.53%
SAMEORIGIN, SAMEORIGIN0.22%
GOFORIT0.15%
ALLOW0.10%
ALLOW-FROM https://my.bigcartel.com0.09%
allow-from https://engine.prosites.com/ https://engine.lifelearn.ca0.06%
SAMEORIGIN;0.05%
ALLOW-FROM https://greenhouse.cloversites.com0.04%
SAMEORIGIN,SAMEORIGIN0.03%
ALLOW-FROM https://app.kajabi.com https://app.vibely.io https://communities.kajabi.com0.03%
*0.03%
ALLOW-FROM *0.03%
ALLOW-FROM https://website.pixieset.com0.03%
SAMEORIGIN, SAMEORIGIN, SAMEORIGIN, SAMEORIGIN0.03%
ALLOW-FROM https://app.kajabi.com https://app.vibely.io https://communities.kajabi.com *.mykajabi.com0.02%
ALLOW-FROM https://www.lodgify.com/0.02%
Allow-From https://my.livechatinc.com/0.02%
ALLOW-FROM https://www.futurdigital.fr/widget0.02%