Crown Street, Wollongong, 2500
Load Site in an iframe
In a different case, you may want to enable your site to be embedded in an iframe (for example, to create a template page with your site). Allowing a site to be loaded within an iframe within another site may allow unscrupulous actors to leverage your site and brand to fool users into clicking the wrong link or providing data to third-party sources. If you want the webpage to be loaded in an iframe, just activate this option.
The ability to load your site in an iframe on another site is disabled by default. We do not recommend altering the default unless it is required for your specific site. Sites built before April 5, 2020, may be shown in an iframe.
To allow the ability to load the webpage in an iframe, do the following:
- Click Settings on the left side, then Site SSL.
- Toggle the Allow site to be loaded in an iframe checkbox.
Security Settings
To inform browsers that the site should not be loaded inside an iframe, the following security settings have been implemented:
- x-frame-options: SAMEORIGIN
- content-security-policy: frame-ancestors 'self'
The original version is x-frame-options, while content-security-policy is a newer setting that is not yet completely supported by all browsers. These instruct browsers not to load the site within an iframe.
These settings are enabled by default in order to apply the best security standards right out of the box. Allowing sites to load without an iframe by default is a small step toward preventing
ClickJacking. Clickjacking occurs when a malicious user opens the site within a frame while attempting to entice visitors to pass personal information that can be intercepted or collected.

Love My Online Marketing has 10+ Years of working alongside businesses and helping them grow. Discuss your options for online success from website Design and Development through to Google Marketing.
Do you want more traffic and business leads?
Love My Online Marketing is determined to make a business grow. Our only question is, will it be yours?