Guide

How to Fix Exposed X-Frame-Options Header on Your Site

Updated October 2026

To fix an exposed X-Frame-Options header, ensure your site includes this header in its HTTP response to safeguard against clickjacking attacks. This guide helps you address a specific security header issue to improve website protection.

An exposed X-Frame-Options header may leave your website vulnerable to clickjacking attacks, where malicious sites embed your content. Understanding how to resolve this issue is crucial for safeguarding your business online.

This guide provides clear steps for addressing the exposed X-Frame-Options header on your website, from checking current configurations to confirming the fix.

Run my free security check about 10 seconds, no account needed

Step 1: Check Your HTTP Headers

Start by identifying if your website currently includes the X-Frame-Options header. Use a tool like the EB Security checker to perform this external scan.

The scan will review the HTTP responses your site serves. A missing or incorrectly configured X-Frame-Options header will be flagged for attention.

Step 2: Add the X-Frame-Options Header

After identifying the missing header, you need to ensure the X-Frame-Options header is included in all HTTP responses.

Configure your web server to include this header. For Apache, edit the .htaccess file; for Nginx, modify the configuration file to include 'add_header X-Frame-Options "SAMEORIGIN"'.

Step 3: Validate the Header Configuration

Once added, it’s important to validate that the X-Frame-Options header is correctly configured to protect your site.

Re-run the EB Security scan or use browser developer tools to confirm the header appears in all relevant HTTP responses.

Free, instant, no account

See your site's security grade in seconds.

Free, instant, and no account needed to see your grade.

Scan my site free

Plain-English A to E grade in about 10 seconds. No account needed to see it.

Common Issues and How to Fix Exposed X-Frame-Options Header

If your header isn't working, typical issues include server misconfigurations and conflicts with other headers.

Check for typos in the configuration file or conflicting headers that might override or nullify the X-Frame-Options header.

Why Fixing the X-Frame-Options Header Is Essential

Repairing an exposed X-Frame-Options header is crucial because it prevents clickjacking threats, ensuring your site's integrity.

For UK small businesses, protecting online assets helps maintain customer trust and meets basic security expectations.

To fix an exposed X-Frame-Options header, configure your server to send this header in every HTTP response. Run a free EB Security scan to check its status.

Common questions

What is an X-Frame-Options header?
An X-Frame-Options header controls the visibility of your site in iframes, preventing clickjacking attacks by restricting how others can frame your pages.
Why is my X-Frame-Options header exposed?
An X-Frame-Options header is exposed if it's missing or misconfigured, making your site vulnerable to clickjacking. Check your server settings to resolve this.
How often should I check my site for an exposed X-Frame-Options header?
It's advisable to check your site's headers anytime you make server changes or perform regular security audits, ensuring the X-Frame-Options header is present.
Can the EB Security tool fix the X-Frame-Options header for me?
The EB Security tool cannot implement fixes; it provides guidance on identifying issues. Configuration changes must be applied directly to your web server settings.
What does 'SAMEORIGIN' mean in X-Frame-Options?
'SAMEORIGIN' allows your pages to be framed only by pages from the same origin, enhancing security by preventing clickjacking from other domains.

Keep exploring

Add security headers

X-Frame-Options and clickjacking

Check security headers

Free, instant, no account

Check your website now, free.

A plain-English A to E grade in about 10 seconds, plus free monthly monitoring.

Scan my site free

Plain-English A to E grade in about 10 seconds. No account needed to see it.