Skip to content

Free, no catch

Are your fraud prevention headers right?

HMRC publishes a validator for the headers your MTD software is legally required to send. It saw yours once, at production approval, on sandbox traffic. We will run your live setup against it and send you exactly what it says.

Nothing is attacked and nothing is exploited. This reads what your software already sends to HMRC and compares it against HMRC's own published specification.

Request the check

Four fields. No call required unless you want one.

We use this to run the check and reply. No mailing list, no sharing it on.

Why this one is worth ten minutes

It is the law, not guidance

Header data is required by law for the VAT and Income Tax MTD APIs, under the Delivery of Tax Information through Software (Ancillary Metadata) Regulations 2019, in force since 1 April 2019.

The penalty is £3,000

HMRC introduced a £3,000 penalty for developers who fail to support the data transmission requirement.

Then they can cut you off

Where an application keeps submitting incorrect or missing data after discussions, HMRC states that providers may be fined and blocked from using HMRC APIs. For an MTD product, that is the whole business.

There is a six month grace period

HMRC allows six months to accommodate new and amended headers. After that, patterns of non compliance are monitored and can enter the sanctions process.

Sources: HMRC Developer Hub fraud prevention guidance and the Fraud Prevention Header Data Compliance and Sanctions Guidelines. Everything above is HMRC's own published position, not our interpretation of it.