</> Web Validators

security.txt Checker

RFC 9116 security.txt vulnerability-disclosure contact file.

This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain.

Based on: RFC 9116 — A File Format to Aid in Security Vulnerability Disclosure (security.txt)

About this validation

Checks for an RFC 9116 security.txt vulnerability-disclosure contact file.

Rules reviewed:
Sep 6, 2026

SEOTechTests methodology: Data source: a live request to /.well-known/security.txt performed by SEOTechTests. Standard: RFC 9116 defines the file's location and required fields.

Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.

FAQ

What is security.txt?

A standardized text file at a well-known URL that tells security researchers how to responsibly report a vulnerability they find on the site -- a contact address, PGP key, and often a disclosure policy.

Why does SEOTechTests check for it?

Its presence at the standardized RFC 9116 location makes vulnerability reporting straightforward for a researcher, rather than requiring guesswork or a public bug bounty platform.

Is a missing security.txt file itself a vulnerability?

No. It's an operational convenience for reporting, not a technical control -- its absence doesn't create a security weakness, it just makes responsible disclosure to the site owner less discoverable.

What does PASS mean for this check?

A file was found at the standard location with the fields RFC 9116 requires (at minimum a Contact field) -- it doesn't verify the contact information actually works or is monitored.