Newsletter - September 2026

Newsletter - September 2026

September was about making Report URI easier to start with, easier to pay for and more useful before you've signed up at all. Here's everything we shipped.

Start a trial without a card πŸ’³

If you're subscribing to Report URI for the first time, you no longer need to enter a card to start your trial. Pick a plan, get the full product for 30 days, and decide at the end whether it's earned a place. If you don't add a card, the trial simply ends - there's no surprise charge. Start your trial here

Four new free tools 🧰

Our free tools grew by four this month:

  • DMARC record generator - checks a domain against the 2026 DMARC specification, shows which record actually governs a name (it often isn't the one at that name), and tells you whether your report destinations have agreed to receive anything.
  • SPF record checker - walks your whole include tree, counts the DNS lookups it costs, and flags what will break before you publish.
  • CAA record checker - shows which CAs can issue for a name, which can issue wildcards and where the policy really comes from, with a builder that won't accidentally lock you out.
  • SRI validator - paste your script and stylesheet tags and get a verdict for each one, plus a fixed tag to copy wherever an integrity attribute is wrong or missing.

The SRI hash generator got some love too: it now produces a single sha512 hash, and a link to a result can be shared.

Magento: a new home, and a beta to join πŸ›’

Magento stores have their own set of client-side problems, so they now have their own Magento page. We're also building a Magento module and are looking for 25 stores to help us test it. Beta stores get Report URI free until 31 December 2026, then 50% off the first year for taking part, whether the module works perfectly or you spend the beta telling us what's wrong with it. The details are on the beta page, or just email magento@report-uri.com.

Let someone else handle the billing 🧾

The person who uses Report URI often isn't the one who pays for it, and the one who needs the invoices is often neither. You can now create a shareable Billing Portal link from your billing page and send it to your finance team. They can update the card or download invoices without your password. Each link expires after 72 hours and you can revoke it at any time. Every use is recorded in your audit trail. The link carries full billing access, cancelling included, so only send it to someone you'd trust with that.

Putting a number on PCI DSS πŸ’·

Two new calculators for anyone making the case for client-side security internally. The PCI DSS fine calculator estimates the monthly fines card brands charge for staying out of compliance, no breach required. The data breach cost calculator compares the cost of a skimmer with no policy, with a report-only policy and with an enforced policy. Our PCI DSS hub now also covers SAQ A-EP and SAQ D.

More threat intelligence, published πŸ›°οΈ

We added nearly 600 indicators to our threat intelligence lists in September, and three new campaign write-ups to our threat intelligence research:

The new indicators also cover more Polygon EtherHiding ClickFix infrastructure, new Magecart skimmer domains and macOS stealer hosts. If any of them turn up in your reports, you'll see it flagged.

Getting reports from Safari 🧭

Safari only reads reporting groups from the newer Reporting-Endpoints header, not the original Report-To header. Our Setup page used to show only Report-To. If you set up from it, Safari hasn't been sending you deprecation, intervention, crash or NEL reports. The page now shows both headers. Setting both gives you the widest browser coverage, and browsers that understand both prefer Reporting-Endpoints.

Fixes in the account area 🧹

If Chrome closed every window when you exported reports or your audit trail, that's fixed. Exports now download normally on every report type. As always, if something in the dashboard irritates you, tell us; that's usually how these end up on the list.

Behind the scenes πŸ› οΈ

Reports waiting to be processed now take up about a quarter of the memory they used to, thanks to a new compression dictionary we built specifically for report data. That means more headroom on the busiest days, the start of each month especially. We also moved login state onto its own infrastructure, separate from the report pipeline, and did another round of hardening on our own defences. Nothing for you to do - just a sturdier Report URI underneath.

That's September - a trial you can start without a card, four more free tools, a Magento beta looking for stores and a lot more published threat intelligence. As always, if you have any ideas or feedback, please do let me know.

Read more