Clickjacking test

Loads any URL in a frame and reports whether it can be framed.

Enter a URL and press Test.
How the result is determined + limits

Same-origin targets are verified directly (the frame's document is readable). For cross-origin targets the browser blocks all inspection, so a visible frame is the proof — the browser refuses to render pages that send X-Frame-Options: DENY / Content-Security-Policy: frame-ancestors 'none'. Bonus: when the target allows CORS, its anti-framing headers are read and shown above.