Skip to content

HTTP security

security.txt checker

Fetch a site's /.well-known/security.txt and check that it tells someone who has found a vulnerability how to reach you, and that it is still current.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

security.txt (RFC 9116) is a plain text file at a fixed address that tells anyone who finds a security problem on your site how to report it. Without one, a report may go to a support queue that does not know what to do with it, or not be sent at all.

RFC 9116 requires at least one Contact and exactly one Expires. The expiry date exists so that a forgotten file stops being trusted: once it has passed, a researcher should assume the contacts may be out of date.

A missing file is a finding of informational severity; an incomplete or expired one is low. Neither is a weakness in the site itself. Both make it harder for someone to tell you about one.

How to fix common issues

No security.txt

Publish /.well-known/security.txt with at least a Contact and an Expires line, for example Contact: mailto:security@example.com and Expires: 2027-12-31T23:59:59Z.

More in the security.txt check reference

security.txt is incomplete or expired

Make sure the file has at least one Contact line and an Expires date in the future (RFC 9116), and set a reminder to update it.

More in the security.txt check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 requires a security.txt file. A published reporting contact is technical evidence for the broader control in ISO/IEC 27001:2022 Annex A 8.8 (management of technical vulnerabilities).

Behind the file, the organisation has to establish who reads the reporting address, how quickly reports are acknowledged and assessed, what is in scope, and who renews the file before it expires. The file shows where reports go, not what happens to them.

Scope and limitations

Related guides

Questions

What does a minimal security.txt look like?
Two lines: a Contact field, such as Contact: mailto:security@example.org, and an Expires date in RFC 3339 form, such as Expires: 2027-09-30T23:00:00Z. Serve it as plain text at /.well-known/security.txt over HTTPS.
How often should I update the Expires date?
RFC 9116 recommends an Expires date less than a year ahead. Review the file and renew the date before it passes.
Can Contact be a web form instead of an email address?
Yes. Contact takes a URI: mailto:, tel: or an https: address. A file can list several Contact lines, in order of preference.

Related security tools