Emergency server help: get in touch

security.txt Checker

Check a domain's security.txt against RFC 9116: the /.well-known/ location, the required Contact and Expires fields, Canonical, optional fields such as Policy and Encryption, and a PGP signature.

Status
Live
Last updated
October 3, 2026

security.txt tells security researchers how to report a vulnerability in your site. Enter a domain to find the file at /.well-known/security.txt, check the required Contact and Expires fields against RFC 9116 and see which optional fields are set.

Required fields

Contact gives one or more ways to reach you as a URI: mailto:security@example.com, an https:// form or a tel: number. Expires is a single date in ISO 8601 format, for example 2027-01-01T00:00:00Z, which should be less than a year ahead so stale files are not trusted forever.

The file belongs at https://your-domain/.well-known/security.txt and is served as text/plain. A copy at /security.txt is allowed as a fallback.

Optional fields

Policy links to your disclosure policy, Acknowledgments to a thank-you page, Encryption to a PGP key, Preferred-Languages lists the languages you read and Canonical states the file’s own URL. The whole file may be signed with PGP so researchers can verify it.

Keeping Expires current

A file that expired is treated as untrustworthy. Some control panels, including DirectAdmin, can publish security.txt with a rolling Expires date; otherwise put a yearly reminder in your calendar or update the date with a small cron job.

security.txt Checker at a glance

security.txt Checker summary card: security.txt tells security researchers how to report a vulnerability in your site.
In short: security.txt tells security researchers how to report a vulnerability in your site.
security.txt Checker sections: Required fields, Optional fields and Keeping Expires current
Covers: Required fields, Optional fields and Keeping Expires current.
security.txt Checker questions answered: Does security.txt make my site more secure? Which address should I use for Contact?
Answers: Does security.txt make my site more secure? Which address should I use for Contact?

Official documentation: RFC 9116 (security.txt), securitytxt.org.

Related guides: Harden Shared cPanel Server: Secure CageFS and ModSecurity Setup · cPanel Root Escalation Incident Response: Critical First 24 Hours · Server hacked: incident response runbook for Linux and cPanel.

Frequently asked questions

Does security.txt make my site more secure?

Not directly. It makes it easy for people who find a problem to tell you before others exploit it, which shortens the time a vulnerability stays open.

Which address should I use for Contact?

A role mailbox such as security@ that more than one person reads, or a web form. Avoid a personal address that may leave with an employee.

Why is my Expires date flagged?

It is in the past, missing, appears more than once or is more than a year ahead. RFC 9116 asks for exactly one Expires field and recommends less than a year.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.