Get in Touch About the Headers Checker

One inbox, read by a human. No ticket numbers, no chatbot in front of it.

What to Include in a Bug Report

Email [email protected] with enough detail to reproduce the problem.

For checker bugs

If the checker reports a header as missing that curl shows your server sending, grades a Content-Security-Policy in a way you think is wrong, or the generator produces a block your server refuses, send:

Grading rules you disagree with

The weights and the CSP deductions are opinions with reasons attached, written down on the headers guide. If a rule fires on a setup that is right for your case (a public CDN you pin with hashes, a report-only policy you keep on purpose), say so with an example; a rule that produces false positives more often than not gets softened to a note.

For everything else

Questions about how the grade is computed, corrections to the headers guide, or a note that something written here is out of date all go to the same address. Requests for scheduled re-checks, alerts, accounts, an embeddable badge or a penetration test will get a friendly no; the about page explains the boundaries. How submitted URLs are handled is covered in the privacy policy.

There is no form on this page on purpose: a form needs spam protection, and spam protection means loading a third-party script on a site that otherwise loads none.

Replies usually go out within a few days. If your message includes a URL for debugging, it gets read and then deleted, not kept as data.