Load any URL in a sandboxed iframe to check whether it allows embedding or blocks it with a header.
Enter a URL and it loads in a sandboxed frame. If the page stays blank, the site is almost certainly refusing to be embedded with an `X-Frame-Options` header or a `frame-ancestors` directive in its Content Security Policy.
The frame is sandboxed to scripts, forms and same-origin, so an embedded page cannot navigate this one.