It's possible that the request is in fact intentionally being disallowed by the user's web application and remote external service. Your email address will not be published. If the CORS configuration isn't setup correctly, the browser console will present an error like "Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at $somesite" indicating that the request was blocked due to violating the CORS security rules. The only way to determine what specifically went wrong is to look at the browser's console for details.

This might not necessarily be a set-up mistake, though. Part of the error text is a "reason" message that provides added insight into what went wrong. The iframe remains unchanged, with an absolute URL that points to … I came across an Outlook Web Access website that threw an error in Google Chrome that said " Blocked a frame with website name origin from accessing a cross-origin frame. If the iframe is "same origin" as the survey (both are on the same domain), it works. To understand the underlying issue with the CORS configuration, you need to find out which request is at fault and why. It's not related to cross-origin things, but important to know. The text of the error message will be something similar to the following: Note: For security reasons, specifics about what went wrong with a CORS request are not available to JavaScript code. The /echo2 and Razor Pages endpoints do not allow cross-origin requests because no default policy was specified. When an iframe comes from the same origin, and we may access its document, there's a pitfall. Cross-Origin Resource Sharing (CORS) is a standard that allows a server to relax the same-origin policy.

