TaxCheckIt

HMRC fraud prevention headers — definition

Fraud prevention headers are device and connection details that HMRC requires all Making Tax Digital (MTD) software to send with every API request. They help HMRC detect fraudulent submissions. You'll see a privacy notice when connecting, as software must tell you this data is collected.

Reviewed 18 August 2026 · Software guidance, not tax advice.

In one paragraph

Fraud prevention headers are pieces of information — such as device ID, IP address, timezone and screen size — that HMRC requires all MTD software to send with every API request. They help HMRC detect fraudulent submissions. Software must tell users this data is collected, which is why you see a notice when connecting HMRC.

What is collected

HMRC specifies a set of headers, known as Gov-Client-* headers, that your software sends automatically. These include:

  • Device ID (a unique identifier for your device)
  • IP address
  • Timezone
  • Screen size
  • Operating system and browser version

Your software collects these details when you use it, and sends them with each request to HMRC.

Why HMRC requires it

Sending fraud prevention headers is a legal requirement for MTD software. HMRC uses the data to build a profile of normal activity and spot anomalies that might indicate fraud. For example, if a submission comes from an unexpected location or device, it may be flagged for review.

Because this is personal data, your software must show you a privacy notice before you connect to HMRC. This explains what's collected and why. You can't opt out of sending these headers if you want to use MTD software — it's part of the legal framework.

Related terms

Frequently asked questions

Can I opt out?
No. Fraud prevention headers are a legal requirement for MTD software. You can't opt out if you want to use software to meet your MTD obligations.
What are Gov-Client-* headers?
They are a set of standardised headers that HMRC requires software to send. They include device ID, IP address, timezone, screen size, and other technical details.
Why do I see a privacy notice when connecting?
Because your software must tell you that it's collecting and sending these details to HMRC. The notice explains what's collected and why.
Is this the same as cookies?
No. Cookies are small files stored in your browser. Fraud prevention headers are sent with each API request and don't involve cookies.