CORS allowed
The response allows the configured cross-origin request.
Inspect cross-origin response headers, simulate preflight requests, detect unsafe configurations, and verify whether a browser request should be allowed.
The response allows the configured cross-origin request.
This checker performs the same steps a browser would: it first determines whether your request actually requires a CORS preflight (based on the method and requested headers, not just whether the checkbox is on), sends a real OPTIONS request when one is required, and then sends the real request itself, reading only the CORS-relevant response headers. The same SSRF protections used across our tools apply here too - private, loopback, link-local and cloud-metadata addresses are always rejected, and every redirect hop is re-validated before being followed. This tool never forwards your own cookies or authorization credentials to the target site - "Send credentials/cookies" only affects how the results are interpreted (whether a wildcard Access-Control-Allow-Origin would actually be usable by a credentialed browser request), not what our server sends.
No. The "Send credentials/cookies" option only changes how the CORS results are interpreted - it never causes our server to forward any of your browser's cookies or Authorization header to the target.
Per the CORS spec, "simple" requests (GET/HEAD/POST with only safelisted headers like Accept and Content-Language) never trigger a browser preflight, so simulating an OPTIONS call for one would be inaccurate - this tool only sends a real preflight when one would genuinely be required.
No. Hostnames that resolve to localhost, private IP ranges, link-local addresses or cloud metadata endpoints are rejected before any request is made, and each redirect hop is re-validated the same way.
Request bodies are capped at 64 KB to keep the check fast and prevent abuse - CORS testing doesn't need a large payload.
No. Only a small set of CORS-relevant response headers (Access-Control-Allow-Origin, -Methods, -Headers, -Credentials, -Expose-Headers, Max-Age, Vary) are read and returned - the response body is never downloaded or exposed.