SafeFrame is a managed API-enabled cross-origin iframe, leveraging the browser same-origin policy, to provide a security boundary between publisher page content and ad creative code. While it protects your site and users through robust sandboxing, it involves certain trade-offs, such as an increase in latency, the restriction of some high-impact ad formats that need to change the appearance or behavior of your site, and the possible impairment of certain third-party measurement and viewability scripts.
On this page:
- What is SafeFrame?
- How SafeFrame protects you and your users
- New SafeFrame controls in Demand Channel settings
- Benefits of disabling SafeFrame (using same-origin iframes)
- Risks of disabling SafeFrame
- Making an informed decision
What is SafeFrame?
SafeFrame is an IAB standardthat provides an API-enabled, sandboxed iframe designed to render ad creatives securely. It acts as a security barrier, isolating the ad creative from the publisher's page content.
In Google Ad Manager, SafeFrame is active by default for many ad types when using Google Publisher Tags (GPT). This default setting ensures that most programmatic demand executes within a protected environment without requiring manual configuration. Google Ad Manager is unique for enabling SafeFrame by default, as other supply side solutions do not.
How SafeFrame protects you and your users
The primary purpose of SafeFrame is to minimize the risks associated with third-party code execution. It offers several key protections:
- Prevents DOM access: It stops malicious code within ads from accessing or altering your website, preventing unauthorized changes to your site (such as defacement or functionality changes).
- Stops forced redirects: SafeFrame is a critical defense against unauthorized redirects, ensuring users remain on your page unless they intentionally click an ad.
- Protects sensitive data: The sandbox prevents ads from accessing sensitive information stored on your page, such as cookies and form data.
- Maintains layout stability: By containing the ad within specific boundaries, SafeFrame prevents creatives from breaking your page layout.
New SafeFrame controls in Demand Channel settings
Google Ad Manager has introduced new controls within Demand Channel settings to provide more granular management of SafeFrame. These controls allow you to align your SafeFrame preferences across different demand sources, including:
- Authorized Buyers
- Open Bidding
- Google demand
The newly introduced Safeframe control will allow you to turn Safeframe off for the above demand channels. The control also offers an optimized setting that is enabled by default. When selected, Safeframe will be turned off if a meaningful portion of your Header Bidding traffic serves into a friendly iframe.
Demand Channel settings also offers the use of Override Groups as a way to apply the different settings from the demand channel to a subset of bidders, and are an effective way to manage bidder trust levels. For example, you can set up a group of bidders who you trust to serve creatives into a friendly iframe and disable Safeframe for them.
These updates allow you to consistently apply settings across your programmatic stack, similar to the controls often available for Header Bidding partners.
Benefits of disabling SafeFrame (using same-origin iframes)
While SafeFrame provides significant security, some publishers choose to disable it for specific use cases to achieve the following:
- Increased demand eligibility: High-impact formats like page takeovers, skins, or highly interactive units often require direct access to the page to function. Disabling SafeFrame can unlock access to this premium demand.
- Improved measurement: Certain third-party viewability and measurement scripts may provide more accurate or detailed data when they are not restricted by a sandbox.
- Latency reduction: In some scenarios, rendering ads in a same-origin iframe (without the SafeFrame sandboxing) can reduce technical overhead and latency, which often results in increased revenue.
- Operational consistency: If you already disable SafeFrame for Header Bidding, using these new controls allows you to maintain a uniform environment for Ad Exchange and Open Bidding.
Risks of disabling SafeFrame
Disabling SafeFrame removes the security sandbox, which introduces several significant risks:
- Security vulnerabilities: Without the sandbox provided by Safeframe, malicious creatives can attempt to execute forced redirects, steal user credentials, or modify your page content and layout. You should review how such unexpected access and possible leakage of your user’s data impacts your regulatory compliance.
- Malvertising exposure: You accept a higher risk of "bad ads" impacting your user experience and site reputation.
- Shifted responsibility: When SafeFrame is disabled, the responsibility to vet demand sources and monitor for malicious activity shifts more heavily to the publisher.
- Limited Google protection: Google’s ability to detect and block adverse events at the creative level is significantly limited when those creatives run outside of a SafeFrame.
Making an informed decision
Choosing whether to use SafeFrame involves balancing revenue opportunities with security risks. We recommend the following best practices:
- Evaluate partner trust: Publishers should consider disabling SafeFrame only for demand partners and bidders they trust, aligning this decision with existing SafeFrame configurations for those partners in header bidding.
- Review automated controls: Review your current settings for automated controls in Demand Channel Settings and decide how they align with your specific header bidding setup. The automated solution may offer operational consistency.
- Use granular controls and monitor quality: Utilize the new Demand Channel Settings to apply SafeFrame rules per bidder as necessary. Ensure you are using robust ad quality tools and monitoring services to catch potential security issues early if SafeFrame is disabled for any partner.
Take action: Review your current configurations and the new controls by navigating to Delivery, then Demand Channel settings of your Google Ad Manager account.