Skip to content

Errors / Blocked by the browser

Refused to display '…' in a frame because it set 'X-Frame-Options' to 'sameorigin'.

The page tried to show another website inside it, and that website does not allow it.

An empty frame, or a small error page, where the content should be.

Why it happens

  • The framed site sends X-Frame-Options: SAMEORIGIN or DENY to protect itself from being shown inside other sites.
  • Common with login pages, payment pages, and sites like Google or Facebook opened in an <iframe>.
  • Also when a site's own subdomain frames it and the header says SAMEORIGIN.

How to fix it

  1. If you own the framed site, replace the header with Content-Security-Policy: frame-ancestors listing the sites allowed to frame it.
  2. If you do not, link to it or open it in a new window: it cannot be framed, by design.
  3. For embeds, use the provider's embed URL (YouTube's /embed/, Google Maps' embed), which allows framing.

Whose problem it is

Usually another company's script or site, embedded in this one.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.

Often seen with