Security Headers

X-Frame-Options check

Stops other websites from loading yours inside an invisible frame to trick visitors into clicking things (clickjacking).

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We read the X-Frame-Options header, or a frame-ancestors rule in your CSP.

Why it matters to your business

Without it, a malicious page can overlay your login or payment form and capture clicks and typing from visitors who think they are on your site.

How to fix it

  1. Send X-Frame-Options: SAMEORIGIN, or Content-Security-Policy: frame-ancestors 'self'.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.