CORS checker
dossier_corsSend a CORS preflight (OPTIONS) to https:/// and return the access-control-* headers in the answer. Use to check whether a site accepts cross-origin requests from a given origin and method. One request, 5 s timeout. Returns JSON with a status field: {status:"ok", data, fetchedAt} on success, {status:"not_applicable", reason} when the thing is genuinely absent, {status:"timeout", ms}, or {status:"error", message} when it could not be determined. Treat not_applicable as a finding and error as unknown.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Public domain name, e.g. example.com. IP addresses, ports, paths and protocol prefixes are rejected. | |
| method | No | Access-Control-Request-Method to send, e.g. POST. Defaults to GET. | |
| origin | No | Origin header to send, e.g. https://app.example.com. Defaults to https://domainposture.com. |