Framing protection headers rise to 30% adoption
Analysis of the top 1 million domains shows framing protection headers grew from 14.4% to 29.7% adoption since 2023, with CSP frame-ancestors nearly quadrupling from 1.9% to 7.1%.
A three-year follow-up study examining security header adoption across the top 1 million domains reveals significant growth in protections against iframe-based phishing attacks. Overall coverage by either X-Frame-Options or CSP frame-ancestors headers has more than doubled from 14.4% in 2023 to 29.7% in 2026, with the most dramatic improvement seen in CSP frame-ancestors adoption, which grew from 1.9% to 7.1% of all domains.
These headers prevent attackers from embedding legitimate websites in iframes on malicious pages, a technique commonly used in overlay phishing where fake login prompts are displayed over framed legitimate sites. The X-Frame-Options header, while older and more limited, saw its SAMEORIGIN directive increase from 12.4% to 19.4% adoption. The more flexible CSP frame-ancestors directive, now considered the authoritative standard by modern browsers, showed the strongest growth trajectory across all sample sizes.
Despite these improvements, the majority of even the most popular domains still lack basic framing protection, leaving users vulnerable to credential-harvesting attacks. The top 1,000 domains actually showed decreased adoption, likely due to composition changes as traditional websites were replaced by CDN endpoints and API backends that don't serve traditional web content. The researcher notes that implementation requires only a single line of server configuration, suggesting substantial room remains for industry-wide improvement.
Source reporting: https://isc.sans.edu/diary/rss/33068
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free