Errors / Blocked by the browser
Refused to display '…' in a frame because it set 'X-Frame-Options' to 'sameorigin'.
The page tried to show another website inside it, and that website does not allow it.
An empty frame, or a small error page, where the content should be.
Why it happens
- The framed site sends
X-Frame-Options: SAMEORIGINorDENYto protect itself from being shown inside other sites. - Common with login pages, payment pages, and sites like Google or Facebook opened in an
<iframe>. - Also when a site's own subdomain frames it and the header says
SAMEORIGIN.
How to fix it
- If you own the framed site, replace the header with
Content-Security-Policy: frame-ancestorslisting the sites allowed to frame it. - If you do not, link to it or open it in a new window: it cannot be framed, by design.
- For embeds, use the provider's embed URL (YouTube's
/embed/, Google Maps' embed), which allows framing.
Whose problem it is
Usually another company's script or site, embedded in this one.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- frame-ancestors violationA website shown inside this page does not allow being shown on this site.
- ERR_BLOCKED_BY_RESPONSEThe other website's own answer told the browser not to let this page use it.