RFC 7034: HTTP Header Field X-Frame-Options
In plain English — editorial summary, not part of the RFC
To improve the protection of web applications against clickjacking, this document describes the X-Frame-Options HTTP header field, which declares a policy, communicated from the server to the client browser, regarding whether the browser may display the transmitted content in frames that are part of other web pages.
Document record
- Document ID
- RFC7034
- Published
- October 2013
- Authors
- D. Ross; T. Gondrom
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- app
- Pages
- 14
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 5988Web LinkingObsoleted
October 2010
- RFC 7070An Architecture for Reputation ReportingCurrent
November 2013
- RFC 7071A Media Type for Reputation InterchangeCurrent
November 2013
- RFC 7072A Reputation Query ProtocolCurrent
November 2013
- RFC 7073A Reputation Response Set for Email IdentifiersCurrent
November 2013
- RFC 7095jCard: The JSON Format for vCardCurrent
January 2014
- RFC 6953Protocol to Access White-Space (PAWS) Databases: Use Cases and RequirementsCurrent
May 2013
- RFC 7158The JavaScript Object Notation (JSON) Data Interchange FormatObsoleted
March 2014
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?