security.txt Checker
RFC 9116 security.txt vulnerability-disclosure contact file.
This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain.
Based on: RFC 9116 — A File Format to Aid in Security Vulnerability Disclosure (security.txt)
About this validation
Checks for an RFC 9116 security.txt vulnerability-disclosure contact file.
- Protocol / standard:
- Rules reviewed:
- Sep 6, 2026
SEOTechTests methodology: Data source: a live request to /.well-known/security.txt performed by SEOTechTests. Standard: RFC 9116 defines the file's location and required fields.
Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.
FAQ
What is security.txt?
A standardized text file at a well-known URL that tells security researchers how to responsibly report a vulnerability they find on the site -- a contact address, PGP key, and often a disclosure policy.
Why does SEOTechTests check for it?
Its presence at the standardized RFC 9116 location makes vulnerability reporting straightforward for a researcher, rather than requiring guesswork or a public bug bounty platform.
Is a missing security.txt file itself a vulnerability?
No. It's an operational convenience for reporting, not a technical control -- its absence doesn't create a security weakness, it just makes responsible disclosure to the site owner less discoverable.
What does PASS mean for this check?
A file was found at the standard location with the fields RFC 9116 requires (at minimum a Contact field) -- it doesn't verify the contact information actually works or is monitored.