field Registered
Verified 2026-09-18 · registry updated 2026-08-28

CSP Report-Only

CSP-Report-Only lets a site observe policy violations without blocking the affected resource.

Use report-only mode to discover dependencies before enforcement. Treat reports as untrusted input and move to an enforcing policy after reviewing real traffic.

httpsecuritycspmonitoring

Reference (http)

Content-Security-Policy-Report-Only: default-src 'self'; report-to csp-endpoint

Use report-only mode to discover dependencies before enforcement. Treat reports as untrusted input and move to an enforcing policy after reviewing real traffic.

Common mistakes

  • Assuming report-only protects the page or accepting violation reports without limiting their size and content.

IANA registry: http-fields/field-names

Registry reference: Content Security Policy Level 3

Permalink: https://merginit.com/reference/http/csp-report-only