What is an X-Frame-Options header?
Tells the browser whether the page may be rendered inside a frame/iframe, a defence against clickjacking.
X-Frame-Options is a longstanding, simple defence against clickjacking - it tells the browser whether a website's page is allowed to be embedded inside an iframe on another site at all, and if attackers can't frame your login or payment page, they can't trick visitors into clicking on it through an invisible overlay. Content-Security-Policy's frame-ancestors directive is the modern, more flexible replacement, but many sites still send both for broader browser compatibility.
Common use case
A banking site sets X-Frame-Options: DENY on its login page, so an attacker can't embed it invisibly inside a malicious page and trick a visitor into clicking through a fake overlay.
Example
X-Frame-Options: SAMEORIGINHistory
Introduced informally by Microsoft in Internet Explorer 8 (2009), later documented as an informational RFC (RFC 7034, 2013) without ever becoming a full internet standard.
Deprecated / legacy status
Functionally superseded by Content-Security-Policy's frame-ancestors directive, which supports a more flexible allowlist rather than X-Frame-Options's rigid deny/same-origin/single-origin choices - many sites still send both for compatibility with older browsers that don't understand CSP.
Did you know?
It never went through the formal IETF standards process the way most HTTP headers did - it started as one browser vendor's pragmatic fix that every other browser vendor simply copied because it worked.