Free, no catch
Are your fraud prevention headers right?
HMRC publishes a validator for the headers your MTD software is legally required to send. It saw yours once, at production approval, on sandbox traffic. We will run your live setup against it and send you exactly what it says.
Nothing is attacked and nothing is exploited. This reads what your software already sends to HMRC and compares it against HMRC's own published specification.
Why this one is worth ten minutes
It is the law, not guidance
Header data is required by law for the VAT and Income Tax MTD APIs, under the Delivery of Tax Information through Software (Ancillary Metadata) Regulations 2019, in force since 1 April 2019.
The penalty is £3,000
HMRC introduced a £3,000 penalty for developers who fail to support the data transmission requirement.
Then they can cut you off
Where an application keeps submitting incorrect or missing data after discussions, HMRC states that providers may be fined and blocked from using HMRC APIs. For an MTD product, that is the whole business.
There is a six month grace period
HMRC allows six months to accommodate new and amended headers. After that, patterns of non compliance are monitored and can enter the sanctions process.
Sources: HMRC Developer Hub fraud prevention guidance and the Fraud Prevention Header Data Compliance and Sanctions Guidelines. Everything above is HMRC's own published position, not our interpretation of it.