Get in Touch About the Headers Checker
One inbox, read by a human. No ticket numbers, no chatbot in front of it.
What to Include in a Bug Report
Email [email protected] with enough detail to reproduce the problem.
For checker bugs
If the checker reports a header as missing that curl shows your server sending, grades a Content-Security-Policy in a way you think is wrong, or the generator produces a block your server refuses, send:
- The URL you checked, or the generator settings and output format.
- What the report showed versus what you expected, ideally with the raw headers from curl -sD - -o /dev/null pasted in.
- For a rejected snippet, the exact error from Apache, nginx or Caddy.
Grading rules you disagree with
The weights and the CSP deductions are opinions with reasons attached, written down on the headers guide. If a rule fires on a setup that is right for your case (a public CDN you pin with hashes, a report-only policy you keep on purpose), say so with an example; a rule that produces false positives more often than not gets softened to a note.
For everything else
Questions about how the grade is computed, corrections to the headers guide, or a note that something written here is out of date all go to the same address. Requests for scheduled re-checks, alerts, accounts, an embeddable badge or a penetration test will get a friendly no; the about page explains the boundaries. How submitted URLs are handled is covered in the privacy policy.
There is no form on this page on purpose: a form needs spam protection, and spam protection means loading a third-party script on a site that otherwise loads none.
Replies usually go out within a few days. If your message includes a URL for debugging, it gets read and then deleted, not kept as data.