Skip to content

HTTP security configuration

What is security.txt?

Whether the site publishes /.well-known/security.txt, and whether it has the Contact and Expires lines RFC 9116 requires, with an expiry still in the future.

Part of the External Security Check. Free during the preview.

What it checks

Whether the site publishes /.well-known/security.txt, and whether it has the Contact and Expires lines RFC 9116 requires, with an expiry still in the future.

A pass means: A valid security.txt tells researchers how to report problems.

Possible findings

No security.txt

Severity: InformationConfidence: ConfirmedKind: Recommended hardening

What we found

No security.txt file was found at /.well-known/security.txt.

Why it matters

security.txt tells researchers who find a problem how to report it to you, rather than leaving them to guess or give up.

How to fix it

Publish /.well-known/security.txt with at least a Contact and an Expires line, for example Contact: mailto:security@example.com and Expires: 2027-12-31T23:59:59Z.

security.txt is incomplete or expired

Severity: LowConfidence: ConfirmedKind: Recommended hardening

What we found

A security.txt file exists but is missing a required field or has expired.

Why it matters

Researchers may ignore an expired or incomplete file, or be unable to reach you.

How to fix it

Make sure the file has at least one Contact line and an Expires date in the future (RFC 9116), and set a reminder to update it.

References