Headrule
Guide · Updated September 2026

A page refuses to load in an iframe? Remove X-Frame-Options and frame-ancestors in Chrome.

Short answer. Two response headers can stop a page from loading inside an iframe: X-Frame-Options and the frame-ancestors part of Content-Security-Policy. Chrome obeys either one, so removing only X-Frame-Options is often not enough. Remove or replace both, for that one domain.

Every result on this page was checked on 2026-09-28 by an automated test that loads Headrule in Chromium 141 and makes real requests: test/guides.mjs.

Test and development only. These headers protect a site against clickjacking, and a Content-Security-Policy usually does more than control framing. Change them only for a domain you are building or testing against, and pause Headrule when you are done.

On this page: Check which header blocks you The rules Keep the rest of the CSP What we tested

Check which header blocks you

Open DevTools, go to the Network tab, click the framed document's request and look at the response headers. You are looking for X-Frame-Options: DENY or SAMEORIGIN, and for frame-ancestors inside Content-Security-Policy. The console also names the header that refused the frame.

The rules

If only X-Frame-Options is present, one rule is enough:

TypeActionHeaderValueURL filter
ResponseRemoveX-Frame-Options||app.example.test

If the CSP also has frame-ancestors, add a second rule:

TypeActionHeaderValueURL filter
ResponseRemoveX-Frame-Options||app.example.test
ResponseRemoveContent-Security-Policy||app.example.test

Keep the rest of the CSP

Removing the whole Content-Security-Policy also removes its other protections, such as script-src. Headrule cannot edit one directive inside a header, but Set replaces the whole value. Copy the original policy from DevTools, delete only the frame-ancestors part (or change it to the origin that embeds the page), and set that as the new value:

TypeActionHeaderValueURL filter
ResponseSetContent-Security-Policydefault-src 'self'; script-src 'self'; frame-ancestors http://localhost:3000||app.example.test

What we tested

SituationResult
Page sends X-Frame-Options: DENY and frame-ancestors 'none', no rulesRefused
Remove X-Frame-Options onlyStill refused (frame-ancestors applies)
Remove X-Frame-Options and Content-Security-PolicyLoads
Remove X-Frame-Options, Set a CSP whose frame-ancestors is the embedding originLoads
Same, but frame-ancestors names a different originRefused

Related guides

Try it on your own API

Free to install. Every rule on this page works in the free version.