How to read results
CORSProbe fetches a public URL from our servers (SSRF-filtered), optionally sending your chosen Origin, and explains Access-Control-* headers. Optional OPTIONS preflight is a separate request. This is educational — browser engines may still differ slightly.
Overall badge
- ok — Observed headers look consistent with the simulated Origin / preflight for educational purposes.
- review — Headers present with soft spots (e.g. missing Vary: Origin, wildcard notes, optional gaps).
- issues — Combinations that browsers would typically block (origin mismatch,
*with credentials, method/header not allowed).
Per-header status
- pass — Matches expected educational shape.
- warn — Worth a human look.
- fail — Likely browser-blocking mismatch for the simulation.
- unknown — Absent optional signal.
Sharing
Reports use opaque high-entropy IDs at /r/:id. There is no public list of reports.