Please note that it seems on HTTPS pages sometimes the X-Frame-Options header is not sent when only the headers are requested although it is there. So always perform both checks.

Checking:

Result

Header X-Frame-Options found.
The header is set to SAMEORIGIN. You are on a different domain and therefore this page can NOT be included.
The url is redirected to https://www.toastmastersclubs.org/welcome/?m5bc (http status: 200)!

Show the full header

Header for: https://Neurodiverse.ToastmastersClubs.Org
HTTP/1.1 307 Temporary Redirect
Date: Tue, 29 Sep 2026 00:26:45 GMT
Server: Apache/2.4.68 (Amazon Linux) OpenSSL/3.5.8 mod_fcgid/2.3.9
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=(), fullscreen=(self)
Pragma: no-cache
Location: https://www.toastmastersclubs.org/welcome/?m5BC
Cache-Control: max-age=2592000
Expires: Thu, 29 Oct 2026 00:26:45 GMT
Vary: User-Agent
Content-Type: text/plain; charset=UTF-8

HTTP/1.1 200 OK
Date: Tue, 29 Sep 2026 00:26:46 GMT
Server: gunicorn
Permissions-Policy: camera=(), microphone=(), geolocation=(), fullscreen=(self)
Content-Type: text/html; charset=utf-8
X-Frame-Options: DENY
Vary: Cookie,User-Agent
Content-Length: 35616
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Cross-Origin-Opener-Policy: same-origin
Set-Cookie: csrftoken=VTYIrGM2etxOT9lU8TM904yVy3tJzOlO; expires=Tue, 28 Sep 2027 00:26:46 GMT; Max-Age=31449600; Path=/; SameSite=Lax



Check if a frame killer script is one the remote page. If you see the iframe below it works. If you click and you see the other page full screen a frame killer script does run and you cannot include the page.

Checked 44866 urls so far.