security.txt tells security researchers how to report a vulnerability in your site. Enter a domain to find the file at /.well-known/security.txt, check the required Contact and Expires fields against RFC 9116 and see which optional fields are set.
Table of Contents
Required fields
Contact gives one or more ways to reach you as a URI: mailto:security@example.com, an https:// form or a tel: number. Expires is a single date in ISO 8601 format, for example 2027-01-01T00:00:00Z, which should be less than a year ahead so stale files are not trusted forever.
The file belongs at https://your-domain/.well-known/security.txt and is served as text/plain. A copy at /security.txt is allowed as a fallback.
Optional fields
Policy links to your disclosure policy, Acknowledgments to a thank-you page, Encryption to a PGP key, Preferred-Languages lists the languages you read and Canonical states the file’s own URL. The whole file may be signed with PGP so researchers can verify it.
Keeping Expires current
A file that expired is treated as untrustworthy. Some control panels, including DirectAdmin, can publish security.txt with a rolling Expires date; otherwise put a yearly reminder in your calendar or update the date with a small cron job.
security.txt Checker at a glance



Official documentation: RFC 9116 (security.txt), securitytxt.org.
Related guides: Harden Shared cPanel Server: Secure CageFS and ModSecurity Setup · cPanel Root Escalation Incident Response: Critical First 24 Hours · Server hacked: incident response runbook for Linux and cPanel.
Frequently asked questions
Does security.txt make my site more secure?
Not directly. It makes it easy for people who find a problem to tell you before others exploit it, which shortens the time a vulnerability stays open.
Which address should I use for Contact?
A role mailbox such as security@ that more than one person reads, or a web form. Avoid a personal address that may leave with an employee.
Why is my Expires date flagged?
It is in the past, missing, appears more than once or is more than a year ahead. RFC 9116 asks for exactly one Expires field and recommends less than a year.